> > > just disabling it for IMA or disabling it entirely based on whether > > IMA is configured? > > Since tpm2_pcr_extend() is unused if IMA is disabled, we don't really > need to condition on it, we could just remove the HMAC from extends. Ok, so defining a new Kconfig is unnecessary. Mimi