Container related improvements
make it possible to use fips-mode-setup --check without dracut
add .config symlinks so a crypto policy can be set with read-only
/etc by bind-mounting /usr/share/crypto-policies/<policy> to
/etc/crypto-policies/back-ends