package: don't leak signing key file fd

openssl BIO does not close the fd unless we explicitly tell it to
do so.
bio = BIO_new_fp(fdopen(fd, "r"), 0);
bio = BIO_new_fp(fdopen(fd, "r"), BIO_CLOSE);
ctx->signature.pkey = PEM_read_bio_PUBKEY(bio, NULL, NULL, NULL);
if (ctx->signature.pkey != NULL) {
if (fi->name[6] == 'R')
