{ config, lib, pkgs, ... }: { boot.initrd.luks.devices."root".crypttabExtraOpts = [ "tpm2-device=auto" "tpm2-measure-pcr=yes" ]; }