certs: Only allow certs signed by keys on the builtin keyring