[PATCH 1/2] Fix kexec forbidding kernels signed with keys in the secondary keyring to boot