enable aarch64 secure boot and enroll keys
This is done by replacing the python enroll script
with a short expect script which simply monitors for
"Shell>" and runs the key enroll.
The ugliest bit of this is building qemu command lines
for x86 and aarch64, but moving to this mechanism simplifies
future architectures which should only need the arch specific
bits tweaked. As a bit of a side effect the assumption is that
qemu is always run in TCG mode for purposes of enrolling keys
despite the architecture building the .noarch package.
Signed-off-by: Jeremy Linton <jeremy.linton@arm.com>