for the duration of boot, a PCR with the vTPM is extended with the root of this Merkle tree, and afterwards confirmed via the KMS prior to releasing the HPKE private essential. All subsequent reads from the root https://pr1bookmarks.com/story18385184/not-known-factual-statements-about-confidential-email