yawangwang

Results 4 issues of yawangwang

This PR includes changes to populate the machinState proto with the verified SNP/TDX attestation data. The attestation verifier service will leverage the verified machineState to make claims around. # Breaking...

Adding `server.GRUB` to `server.verifyOpts` for verify cmd line. The intention is to align with what GAV (Google Attestation Verifier) does when doing attestation verification.

Per discussions from https://github.com/google/go-tpm-tools/pull/471#discussion_r1725944593, remove curve P224 as it is not supported by crypto/ecdh