[PATCH] tpm: measure DTB in PCR1 instead of PCR0