keygeneration: Add a script to sanity check versions for a keyset

Add a script that runs sanity checks on the versions in a keyset.
In particular, tests whether the actual key versions match those
in key.versions. Also runs consistency checks (for example: firmware
version should match kernel subkey version).

TEST=run on all of our keysets

Change-Id: I5b509ba33127364f6b63252ad167646eb7dce710
Reviewed-by: Mike Frysinger <>
Tested-by: Gaurav Shah <>
1 file changed