You can use tpm2_policyauthorize and allow the PCR to change without having to manually unlock. This was not supported in TPM 1.2.
You can use it with Systemd.
https://github.com/tpm2-software/tpm2-tools/blob/master/man/...