trust anchors: improvements around DNSKEY refusal
- also refuse revoked DNSKEY (explicitly configured as TA) - typo in message that confused the meaning - explicit message when DNSKEY is refused, even without --verbose - code rewrite, handle flags in a better way than "== 257"