Description
Private keys can be backed by a TPM-compatible SSH agent instead of plain files on disk. The Git package builds and installs `ssh-tpm-agent` plus helper commands for key generation, adding keys, and host keys. It anchors authentication in hardware state, so TPM availability, recovery plans, and agent socket configuration need review.