
To be done:
 - add-secondary-key: make sure we really only have two keys
 - tpm-disable: implement
 - add/remove-secondary-pass: needs testing
 - LUKS over LVM is currently not working (we end up with the wrong
   partition UUID in grub.cfg, it seems).

What we want
 - kiwi options to create a LUKS volume w null cipher and empty password
 - do we really need to randomize the LUKS volume at image build time?
   resize and rekey happen waaay later and besides it makes the image
   hard to compress.
 - re-encrypt first, then resize
