KEYS: Separate the kernel signature checking keyring from module signing