kernel/system_certificate.S: use real contents instead of macro GLOBAL()