Reserve area for inserting a certificate without recompiling

configname: CONFIG_SYSTEM_EXTRA_CERTIFICATE

Linux Kernel Configuration
└─>Cryptographic API
└─>Certificates for signature checking
└─>Reserve area for inserting a certificate without recompiling
In linux kernel since version 4.1 (release Date: 2015-06-21)  
If set, space for an extra certificate will be reserved in the kernel
image. This allows introducing a trusted certificate to the default
system keyring without recompiling the kernel.