* on first login of a user, measure its identity to some nvpcr
+* optionally spawn an swtpm instance if a system doesn't have a native tpm, do
+ it via the tpm generator
+
+* add a secret key logic to sd-stub, that uses early-boot efi variables for
+ storing, that can be used as fallback logic for tpm-less systems for disk
+ encryption, and swtpm state encryption.
+
* sd-lldp: pick up 802.3 maximum frame size/mtu, to be able to detect jumbo
frame capable networks