something like pmos_encrypted_uuid=<UUID>, so we can detect earlier if we need to run unl0kr
pmos_encrypted_uuid=<UUID>