ima: define '_ima' as a builtin 'trusted' keyring