Merge changes from topic "max-boot-level-crypto"

* changes:
  Set earlyBootEnded before apex starts
  Expose AID_KEYSTORE