gscvd: add dedicated test keys

This patch extends create_new_keys.sh to generate two additional key
pairs to use for AP RO verification signing. Both new pairs are
RSA4096/SHA256.

The script was ran to generate a new set of keys and the produced AP
RO verification key pairs were copied into tests/devkeys.

BRANCH=none
BUG=b:141191727
TEST=re-signed guybrush AP firmware image following the process
     described in cmd_gscvd.c comments, created a Cr50 image
     incorporating the new root public key hash, updated the DUT AP
     and Cr50 firmware and observed successful AP RO validation.

Change-Id: I03cba1446fc5ffdfef662c5ce1ea3e61950477d4
Signed-off-by: Vadim Bendebury <vbendeb@google.com>
Reviewed-on: https://chromium-review.googlesource.com/c/chromiumos/platform/vboot_reference/+/3297447
Tested-by: Vadim Bendebury <vbendeb@chromium.org>
Reviewed-by: Mike Frysinger <vapier@chromium.org>
Commit-Queue: Vadim Bendebury <vbendeb@chromium.org>
7 files changed