login: Check TPM firmware update device policy

For enterprise-managed devices, TPM firmware updates require
permission by the administrator. Allow the update to be started if the
respective device policy is in place.

BUG=chromium:762030
TEST=unit test

Reviewed-on: https://chromium-review.googlesource.com/679655
Commit-Ready: Mattias Nissler <mnissler@chromium.org>
Tested-by: Mattias Nissler <mnissler@chromium.org>
Reviewed-by: Dan Erat <derat@chromium.org>

Change-Id: Icbbf43b18420be60303f919182369c63f0600674
Reviewed-on: https://chromium-review.googlesource.com/700674
Reviewed-by: Mattias Nissler <mnissler@chromium.org>
Tested-by: Mattias Nissler <mnissler@chromium.org>
3 files changed