Merge "Key revocation check is permissive when device is unlocked" am: a9384cdc9b

Change-Id: I9e4cb8a722e6ae67882a6e37447dd924518eebc2