sudo systemd-cryptenroll /dev/nvme1n1p1 --wipe-slot=2 sudo systemd-cryptenroll /dev/nvme1n1p1 --tpm2-device=auto --tpm2-pcrs=7 sudo reboot