[UKI](https://uapi-group.org/specifications/specs/unified_kernel_image/) provides a way to specify the expected values for a TPM's PCR11 after loading the UKI, in a '.pcrpkey' section within the UKI. This is set up by the [ukify](https://www.freedesktop.org/software/systemd/man/latest/ukify.html#) tool which calls [systemd-measure](https://www.freedesktop.org/software/systemd/man/latest/systemd-measure.html). It would be useful for FIT to support a similar feature.