This allows us to get the OEM Public Key BootGuard hashes. Also add a new HSI test for leaked bootguard keys.