Hi Daniel
The nerd answer is that you can use Automated DNSSEC Provisioning [1] to enable DNSSEC. This also sends an EPP poll message to your registrar to update locally cached state information about a domain name.
Yes, trying to understand, how I correctly get rid of my old RRSIG entries without shooting myself in the foot, I came across this whole new dnssec-policy and automatic publishing CDS records via Bind.
Not sure if I have yet fully understood the mechanics. But I have tentatively set it up now and I'll see, if this somehow, by the magic of the internet, caused my DS entries to get refreshed.