You are not logged in.
I use an old-fashioned separate kernel and initramfs and had no problems with the update. TPM LUKS unlocking still works. Because I don't use a UKI, ConditionSecurity=measure-os isn't satisfied and systemd-pcrextend, systemd-pcrosseparator, systemd-pcrphase-initrd, systemd-pcrphase, systemd-tpm2-setup-early, systemd-pcrnvdone, systemd-pcrproduct, systemd-tpm2-setup, systemd-pcrmachine, and systemd-pcrphase-sysinit are all skipped. `sudo systemd-analyze nvpcrs` shows that no NvPCRs were created.
You can opt out of these services by adding `systemd.tpm2_measured_os=0` to your kernel command line. Note this will change the values of (regular) PCRs along with skipping the NvPCRs. This was added to allow opting in to measurements on systems without hardware TPMs, not to opt out, but it is documented in `man systemd.unit` and `man kernel-command-line`.
Offline
adding `systemd.tpm2_measured_os=0` to your kernel command line.
This is what I was looking for, I use tpm to encrypt some credentials but i don't need the full systemd suite
Last edited by ugjka (Yesterday 17:11:54)
Offline
adding `systemd.tpm2_measured_os=0` to your kernel command line.
Awesome, thank you. Exactly what I wanted as well.
Offline