The TPM validates the state of the software TCB, and the software TCB validates the state of the lower layer, and so on.
The TPM validates the state of the software TCB, and the software TCB validates the state of the lower layer, and so on.
This only works with the current TPM design if there is one “appropriate user”.
The real world contains Chrome, BitLocker, various VMs and containers, etc. The TPM does not properly accommodate this world.
It's even worse if you're self-hosting the signing, to the point that despite a ton of work put into making it safe and understood I wouldn't do it with the current design; a bare-state unlock is more predictable and reliable but I'll make sure to regularly exercise my backup key and header.
You can observe the kernel. It’s just extremely awkward because upgrading the kernel will change the kernel.
I thought application talks to the OS and the OS that check before it do the TPM thing.