verified boot: semantics of multiple required keys