Add support for an existing CompOS cert.

Modify odsign to verify an existing CompOS cert and add it to the
fs-verity keyring if ok or delete it if not.

The significant new behaviour is all behind an if (false), since
there's still a lot to do (like making it possible for a valid cert to
exist).

Otherwise, various refactorings and gratuitous tinkering.

Bug: 190166662
Bug: 188450218
Test: Presubmits
Test: Manual - push various differently-invalid certs & observe
Change-Id: I51021c95fa4670d5fd022783565b1e215962483b
5 files changed