Pre-calculate and sign expected TPM2 PCR 11 values for booted unified kernel images
public key in the image $ openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits ... only be used in the initrd. $ openssl genpkey -algorithm RSA -pkeyopt rsa_keygen_bits