You are not logged in.
I use an old-fashioned separate kernel and initramfs and had no problems with the update. TPM LUKS unlocking still works. Because I don't use a UKI, ConditionSecurity=measure-os isn't satisfied and systemd-pcrextend, systemd-pcrosseparator, systemd-pcrphase-initrd, systemd-pcrphase, systemd-tpm2-setup-early, systemd-pcrnvdone, systemd-pcrproduct, systemd-tpm2-setup, systemd-pcrmachine, and systemd-pcrphase-sysinit are all skipped. `sudo systemd-analyze nvpcrs` shows that no NvPCRs were created.
You can opt out of these services by adding `systemd.tpm2_measured_os=0` to your kernel command line. Note this will change the values of (regular) PCRs along with skipping the NvPCRs. This was added to allow opting in to measurements on systems without hardware TPMs, not to opt out, but it is documented in `man systemd.unit` and `man kernel-command-line`.
Offline
adding `systemd.tpm2_measured_os=0` to your kernel command line.
This is what I was looking for, I use tpm to encrypt some credentials but i don't need the full systemd suite
Last edited by ugjka (2026-09-28 17:11:54)
Offline
adding `systemd.tpm2_measured_os=0` to your kernel command line.
Awesome, thank you. Exactly what I wanted as well.
Offline
Was reading the github issue, this seems the proper fix:
For me, the following settings worked to fix the errors:
OS: Arch Linux
Secure Boot: via sbctl
Initramfs/UKI Generator: `mkinitcpio` with UKI enabled
LUKS: yes, but without TPM unlock# /etc/kernel/uki.conf [UKI] SignInitrdPCRs=yes [PCRSignature:all] PCRPrivateKey=/etc/systemd/tpm2-pcr-private-key.pem PCRPublicKey=/etc/systemd/tpm2-pcr-public-key.pemrun:
# pacman -S systemd-ukify # ukify genkey \ --pcr-private-key=/etc/systemd/tpm2-pcr-private-key.pem \ --pcr-public-key=/etc/systemd/tpm2-pcr-public-key.pem # mkinitcpio -Pnothing else was needed.
I had to reboot and run mkinitcpio -P twice for all errers disappear though, no clue why but whatever...
Offline