altfw: add the ability to disable rollback APIs

Adds a flag to VbSelectAndLoadKernelParams that will disable TPM
rollback APIs. This is necessary for altfw depthcharge because the real
depthcharge locks the rollback area of the TPM before handing off to
altfw, so any attempt to access these values will fail.

TEST=successfully booted depthcharge -> altfw -> ChromeOS

