Note that since you are using bind-9.6 you have to use a "trusted-keys" clause since it doesn't support "managed-keys" / RFC 5011. For the same reason bind-9.6 also does not support "dnssec-lookaside auto".

The ITAR only contains TLD trust anchors, not the root trust anchor nor any for lower zones. Also, the root trust anchor is distributed in a different format to the ITAR so anchors2keys doesn't work on it (hence my blog post).

I recommend ignoring the ITAR (it is due to be eliminated now the root has been signed). Use dnssec-lookaside if you want to validate zones that lack a chain of trust from the root.

