@duxsco yeah, I have doubts though that enrolling your own keys is something that can be made "just work" on general purpose PCs.
Yes, you can do it locally, if you know your hardware very well, or if you only care about VMs or so. But for the general population, I doubt self-enrolling is really an option. Too many problems given that hw extension cards provide signed firmware too.