sign_official_build: Add support for a second miniOS key

For recovery images, if minios_kernel.v1.keyblock exists, sign
- MINIOS-A with minios_kernel.v1.keyblock
- MINIOS-B with minios_kernel.keyblock
Otherwise, sign both with minios_kernel.keyblock.

BRANCH=None
BUG=b:266502803
TEST=- Run replace_recovery_key.sh in devkeys directory to get test keys
- Run sign_official_build.sh on a nissa recovery image
- Set recovery_key.v1.vbpubk in GBB and run recovery. After recovery
  completes, check NBR still works.
- Repeat with recovery_key.vbpubk.

Change-Id: I2336e5261ef24114c5fee302ed95b4dfa1f67c11
Signed-off-by: Reka Norman <rekanorman@google.com>
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/vboot_reference/+/4452079
Tested-by: Reka Norman <rekanorman@chromium.org>
Commit-Queue: Reka Norman <rekanorman@chromium.org>
Reviewed-by: Julius Werner <jwerner@chromium.org>
1 file changed