NOTE: clevis-luks is the offical method of TPM LUKS unlocking on RHEL, but this method works fine on RHEL 9 and 10 and is far simpler (in my opinion).
- Install the TPM userspace utilities
yum install -y tpm2-tools tpm2-tss
- Dump the PCR values. Pick slots to bind the LUKS key unlocking to. Different values meet different threat models.