Enable IMA in skiroot

This adds basic support for the Integrity Measurement Subsystem to the
skiroot kernel.

The changes to skiroot_defconfig are the kernel config options to enable IMA
and the basic security subsystem.  The values were obtained by running a make
menuconfig, enabling IMA and the Nuvoton TPM driver, running a make defconfig,
then updating skiroot_defconfig with this result.

The changes to /etc/fstab ensure securityfs is mounted at boot.

Signed-off-by: Dave Heller <hellerda@us.ibm.com>
diff --git a/openpower/overlay/etc/fstab b/openpower/overlay/etc/fstab
index d373dc6..ece6d84 100644
--- a/openpower/overlay/etc/fstab
+++ b/openpower/overlay/etc/fstab
@@ -4,3 +4,4 @@
 devpts		/dev/pts	devpts	defaults,gid=5,mode=620	0	0
 tmpfs		/dev/shm	tmpfs	mode=0777	0	0
 sysfs		/sys		sysfs	defaults	0	0
+securityfs	/sys/kernel/security	securityfs	defaults	0	0