You are not logged in.

#26 2026-09-28 16:44:19

jbosboom
Member
Registered: 2023-10-14
Posts: 3

Re: TPM2 errors after updates - TPM key integrity check failed

I use an old-fashioned separate kernel and initramfs and had no problems with the update.  TPM LUKS unlocking still works.  Because I don't use a UKI, ConditionSecurity=measure-os isn't satisfied and systemd-pcrextend, systemd-pcrosseparator, systemd-pcrphase-initrd, systemd-pcrphase, systemd-tpm2-setup-early, systemd-pcrnvdone, systemd-pcrproduct, systemd-tpm2-setup, systemd-pcrmachine, and systemd-pcrphase-sysinit are all skipped. `sudo systemd-analyze nvpcrs` shows that no NvPCRs were created.

You can opt out of these services by adding `systemd.tpm2_measured_os=0` to your kernel command line.  Note this will change the values of (regular) PCRs along with skipping the NvPCRs.  This was added to allow opting in to measurements on systems without hardware TPMs, not to opt out, but it is documented in `man systemd.unit` and `man kernel-command-line`.

Offline

#27 2026-09-28 17:06:26

ugjka
Member
From: Latvia
Registered: 2014-04-01
Posts: 1,960
Website

Re: TPM2 errors after updates - TPM key integrity check failed

jbosboom wrote:

adding `systemd.tpm2_measured_os=0` to your kernel command line.

This is what I was looking for, I use tpm to encrypt some credentials but i don't need the full systemd suite

Last edited by ugjka (2026-09-28 17:11:54)

Offline

#28 2026-09-29 07:01:13

zse
Member
Registered: 2024-05-28
Posts: 54

Re: TPM2 errors after updates - TPM key integrity check failed

jbosboom wrote:

adding `systemd.tpm2_measured_os=0` to your kernel command line.

Awesome, thank you. Exactly what I wanted as well.

Offline

#29 Yesterday 12:03:55

ugjka
Member
From: Latvia
Registered: 2014-04-01
Posts: 1,960
Website

Re: TPM2 errors after updates - TPM key integrity check failed

Was reading the github issue, this seems the proper fix:

Ferdi265 wrote:

For me, the following settings worked to fix the errors:

OS: Arch Linux 
Secure Boot: via sbctl 
Initramfs/UKI Generator: `mkinitcpio` with UKI enabled 
LUKS: yes, but without TPM unlock

# /etc/kernel/uki.conf
[UKI]
SignInitrdPCRs=yes

[PCRSignature:all]
PCRPrivateKey=/etc/systemd/tpm2-pcr-private-key.pem
PCRPublicKey=/etc/systemd/tpm2-pcr-public-key.pem

run:

# pacman -S systemd-ukify
# ukify genkey \
        --pcr-private-key=/etc/systemd/tpm2-pcr-private-key.pem \
        --pcr-public-key=/etc/systemd/tpm2-pcr-public-key.pem
# mkinitcpio -P

nothing else was needed.

I had to reboot and run mkinitcpio -P twice for all errers disappear though, no clue why but whatever...

Offline

Board footer

Powered by FluxBB