Merge "KeyMint VTS: catch empty cert chains" into sc-dev