Draft: Release signer
TPM certificate generated with:
openssl req -provider tpm2 -provider default -propquery '?provider=tpm2' \
-x509 -subj "/C=GB/CN=foo" -keyout testkey.pem \
-out testcert.pem
https://gitlab.archlinux.org/archlinux/testing-release-tpm-stuff/-/jobs/193362