Careful, new systemd 252 may render your system unbootable. Some TPM -related service keeps trying to start indefinitely. This is on TPM 2 which supports SHA1 PCRs only + systemd-boot. Grub-controlled booting process with no Secure Boot on another machine worked fine.