I have been warned by people from CESNET and CZ.NIC that BIND<9.9.0 implementations support DNSSEC records for wildcard records. Therefore I believe dnssec-trigger should check for proper support for wildcard DNSSEC data and configure Unbound accordingly.
See #824219
Actually, closing this as duplicate. I re-opened the other bug and changed component to dnssec-trigger *** This bug has been marked as a duplicate of bug 824219 ***