The plugin allows validating the tpm against a hash or a cert. It would be interesting if it supported checking both.