Hi there! At present on systems using initramfs-tools (such as Ubuntu) Clevis will wait for the password prompt to appear before getting to work attempting an unlock. This could possibly lead to confusion for an unwary end-user, thinking they need to enter a password when that may not necessarily be the case. It would be ideal if ASKPASS weren't displayed to the end user until needed (i.e. autounlock fails for whatever reason).
In my testing, this current behavior doesn't result in reduced functionality or anything - even if a user hurriedly types and submits an incorrect password, Clevis will be blissfully unaware and proceed as normal, unlocking if it is able. So this is mainly just a cosmetic/UX improvement.
This request is similar in spirit to #192 . Thanks for your time and consideration!