through boot, a PCR from the vTPM is extended Together with the root of the Merkle tree, and later confirmed by the KMS right before releasing the HPKE private important. All subsequent reads with the root partition are https://no-ransom-6dmd.vercel.app/