[10:28] <cjwatson> cyphermox: yeah my gut feel would be hw-detect.  I agree about question policy though
[12:32] <xnox> hm, why do it on install?
[12:33] <xnox> taking TPM ownership, and adding it as a second luks slot seems like a better option, and then removing first slot.
[12:34] <xnox> note, my laptop has tpm, but i'm failing to take ownership of it or transfer any rsa secrets into it.