You are not logged in.

#26 Yesterday 16:44:19

jbosboom
Member
Registered: 2023-10-14
Posts: 3

Re: TPM2 errors after updates - TPM key integrity check failed

I use an old-fashioned separate kernel and initramfs and had no problems with the update.  TPM LUKS unlocking still works.  Because I don't use a UKI, ConditionSecurity=measure-os isn't satisfied and systemd-pcrextend, systemd-pcrosseparator, systemd-pcrphase-initrd, systemd-pcrphase, systemd-tpm2-setup-early, systemd-pcrnvdone, systemd-pcrproduct, systemd-tpm2-setup, systemd-pcrmachine, and systemd-pcrphase-sysinit are all skipped. `sudo systemd-analyze nvpcrs` shows that no NvPCRs were created.

You can opt out of these services by adding `systemd.tpm2_measured_os=0` to your kernel command line.  Note this will change the values of (regular) PCRs along with skipping the NvPCRs.  This was added to allow opting in to measurements on systems without hardware TPMs, not to opt out, but it is documented in `man systemd.unit` and `man kernel-command-line`.

Offline

#27 Yesterday 17:06:26

ugjka
Member
From: Latvia
Registered: 2014-04-01
Posts: 1,958
Website

Re: TPM2 errors after updates - TPM key integrity check failed

jbosboom wrote:

adding `systemd.tpm2_measured_os=0` to your kernel command line.

This is what I was looking for, I use tpm to encrypt some credentials but i don't need the full systemd suite

Last edited by ugjka (Yesterday 17:11:54)

Offline

#28 Today 07:01:13

zse
Member
Registered: 2024-05-28
Posts: 54

Re: TPM2 errors after updates - TPM key integrity check failed

jbosboom wrote:

adding `systemd.tpm2_measured_os=0` to your kernel command line.

Awesome, thank you. Exactly what I wanted as well.

Offline

Board footer

Powered by FluxBB