When using TSIG and doing an AXFR, two SOA records are created. I believe it is because that one of the TSIGs are being returned after the final SOA record in the AXFR response. I am using the same TSIG for multiple domains, this may also be part of the problem?
I can't reproduce this. When I ask powerdns to axfr a zone that is secured with TSIG, I end up with one SOA in the database.
Dig, as usual, shows two SOA records, which is normal. A second SOA ends the transfer.
Can you tell me more about your problem?
fixed in r2506