Tpm is for crypto and secure generation and storage of values for use in encryption generally. Secureboot is just firmware verification of loaded binaries from boot on out, they’re 2 different pieces and are not really relevant to each other, unless you’re like me and have a fully customized bootloader with keys in TPM and an EFI module with support for the TPM and unlocking your boot drive.
Cool story bro. And I am one of the 9 people that worked on the team at Intel to implement your modern EFI/UEFI.
I just don’t have the time or energy to sit here and explain the whole fucking stack to a bunch of people who mostly could care less. But, Secureboot, it’s a good thing, and the tools on linux get better every hour. Check out lanzaboote.
https://github.com/nix-community/lanzaboote