Without a TPM how can the EFI be trusted? You just have to replace it as well as the boot loader and kernel.
Without a TPM how can the EFI be trusted? You just have to replace it as well as the boot loader and kernel.