Keymint: Add support for CERTIFICATE_NOT_BEFORE/AFTER am: a5780e2e8e

Original change: https://android-review.googlesource.com/c/platform/system/keymaster/+/1566356

MUST ONLY BE SUBMITTED BY AUTOMERGER

Change-Id: I732ff35fa1bc292a07d9b1e80766e272b65b511a