http://forums.w5j6stm77zs6652pgsij4awcjeel3eco7kvipheu6mtr623eyyehj4yd.onion/t/ram-encryption-confidential-cloud/635
That TPM however might be proxied (MiTMd) through another machine and another TPM.
Potential solutions:
* TOFU: Ignoring this issue and trust on first use.
* local, physical provisioning: Customer provisions their own hardware locally to learn the TPM EK and then ships the hardware to the cloud provider.
* cloud provider should publish the TPM EK fingerprint upfront: Before provisioning a server, the cloud provider should be expected to reveal the TPM endorsement key fingerprint.