Do not attempt to generate DNSSEC records when required keys are not present
Recently a customer who is responsible for a very large zone accidentally initiated resigning when no ZSK was present (they keep it off-line and only mount it when required.) The results were not good.
If BIND cannot properly perform a signing action because required keys are not present it should fail (loudly) without altering the zone.