[10:28] cyphermox: yeah my gut feel would be hw-detect. I agree about question policy though [12:32] hm, why do it on install? [12:33] taking TPM ownership, and adding it as a second luks slot seems like a better option, and then removing first slot. [12:34] note, my laptop has tpm, but i'm failing to take ownership of it or transfer any rsa secrets into it.