Signing with the TPM doesn't work super well, given that the TPM's inherent keys can't be used for signing as a privacy protection mechanism. You'd need to store an encrypted key in the image that could be used for signing purposes, but what stops an attacker from simply wiring up the TPM directly, generating a new key pair, and storing that instead? This is a legitimately difficult problem to solve well.