The use case for this is the need to strip out old DNSSEC material when transitioning a DNSSEC-signed zone between providers - specifically to be able to scrub DNSSEC records from a zone that is being slaved from an external master