5 points by carlana
I've been using Secure Boot to store the disk encryption keys on the server's TPM, which seems to be another option unless I'm missing something?