Document OS package decryption keys
Add documentation of OS package decryption keys to the Trust policy.
This is a follow up to MR Decrypt ospkg which introduced decryption of the downloaded OS package, and this change was suggested here: system-transparency/core/stboot!241 (comment 22055).