This reverts the remaining options from earlier commit 4a4699674f58e72604f8eb1f74f23f253d19b801 because actually I do not trust the TPM for my personal thread model enough and it doesn't support the GPG ciphers I want to use. (Instead I use an external USB token again.)
Kernel config files === Syntax: ${hostname}-config
Description