@Foxboron Personally I think we don't have at this point a working model for spec. It's essentially a proprietary spec because a single Microsoft employee controls it. For me that means that is solely Microsoft controlled spec which is not right.
Up until that is changed, I cannot e.g. accept patches that would add policies for trusted keys. Not saying it should be located in kernel tree but there should some kind of shared repository to discuss about it and propose updates.
In kernel we support only public and private fields essentially with parent auth value and that is what it stays up until there is "community edition" of the spec.
E.g., for me IMA it might be useful if one could apply policy sealed trusted key as the anchor of trust.