An XCCDF Rule
certs/signing_key.pem
/boot/config-*
CONFIG_MODULE_SIG_KEY
grep CONFIG_MODULE_SIG_KEY /boot/config-*