This document discusses trusted and encrypted keys in the Linux kernel key retention service. It describes how trusted keys use the TPM to generate and seal keys, while encrypted keys encrypt keys using an AES master key. It also outlines plans to introduce an EFI kernel master key and further lock down the kernel to protect sensitive key material from compromise.