enforce kernel module software signature verification [module signing] / disallow kernel module loading by default