You are not logged in.

#26 2026-09-28 16:44:19

jbosboom
Member
Registered: 2023-10-14
Posts: 3

Re: TPM2 errors after updates - TPM key integrity check failed

I use an old-fashioned separate kernel and initramfs and had no problems with the update.  TPM LUKS unlocking still works.  Because I don't use a UKI, ConditionSecurity=measure-os isn't satisfied and systemd-pcrextend, systemd-pcrosseparator, systemd-pcrphase-initrd, systemd-pcrphase, systemd-tpm2-setup-early, systemd-pcrnvdone, systemd-pcrproduct, systemd-tpm2-setup, systemd-pcrmachine, and systemd-pcrphase-sysinit are all skipped. `sudo systemd-analyze nvpcrs` shows that no NvPCRs were created.

You can opt out of these services by adding `systemd.tpm2_measured_os=0` to your kernel command line.  Note this will change the values of (regular) PCRs along with skipping the NvPCRs.  This was added to allow opting in to measurements on systems without hardware TPMs, not to opt out, but it is documented in `man systemd.unit` and `man kernel-command-line`.

Offline

#27 2026-09-28 17:06:26

ugjka
Member
From: Latvia
Registered: 2014-04-01
Posts: 1,960
Website

Re: TPM2 errors after updates - TPM key integrity check failed

jbosboom wrote:

adding `systemd.tpm2_measured_os=0` to your kernel command line.

This is what I was looking for, I use tpm to encrypt some credentials but i don't need the full systemd suite

Last edited by ugjka (2026-09-28 17:11:54)

Offline

#28 2026-09-29 07:01:13

zse
Member
Registered: 2024-05-28
Posts: 54

Re: TPM2 errors after updates - TPM key integrity check failed

jbosboom wrote:

adding `systemd.tpm2_measured_os=0` to your kernel command line.

Awesome, thank you. Exactly what I wanted as well.

Offline

#29 2026-10-03 12:03:55

ugjka
Member
From: Latvia
Registered: 2014-04-01
Posts: 1,960
Website

Re: TPM2 errors after updates - TPM key integrity check failed

Was reading the github issue, this seems the proper fix:

Ferdi265 wrote:

For me, the following settings worked to fix the errors:

OS: Arch Linux 
Secure Boot: via sbctl 
Initramfs/UKI Generator: `mkinitcpio` with UKI enabled 
LUKS: yes, but without TPM unlock

# /etc/kernel/uki.conf
[UKI]
SignInitrdPCRs=yes

[PCRSignature:all]
PCRPrivateKey=/etc/systemd/tpm2-pcr-private-key.pem
PCRPublicKey=/etc/systemd/tpm2-pcr-public-key.pem

run:

# pacman -S systemd-ukify
# ukify genkey \
        --pcr-private-key=/etc/systemd/tpm2-pcr-private-key.pem \
        --pcr-public-key=/etc/systemd/tpm2-pcr-public-key.pem
# mkinitcpio -P

nothing else was needed.

I had to reboot and run mkinitcpio -P twice for all errers disappear though, no clue why but whatever...

Offline

#30 2026-10-05 09:57:28

Foucault
Member
From: Athens, Greece
Registered: 2010-04-06
Posts: 222

Re: TPM2 errors after updates - TPM key integrity check failed

ugjka wrote:

Was reading the github issue, this seems the proper fix:

Ferdi265 wrote:

For me, the following settings worked to fix the errors:

OS: Arch Linux 
Secure Boot: via sbctl 
Initramfs/UKI Generator: `mkinitcpio` with UKI enabled 
LUKS: yes, but without TPM unlock

# /etc/kernel/uki.conf
[UKI]
SignInitrdPCRs=yes

[PCRSignature:all]
PCRPrivateKey=/etc/systemd/tpm2-pcr-private-key.pem
PCRPublicKey=/etc/systemd/tpm2-pcr-public-key.pem

run:

# pacman -S systemd-ukify
# ukify genkey \
        --pcr-private-key=/etc/systemd/tpm2-pcr-private-key.pem \
        --pcr-public-key=/etc/systemd/tpm2-pcr-public-key.pem
# mkinitcpio -P

nothing else was needed.

I had to reboot and run mkinitcpio -P twice for all errers disappear though, no clue why but whatever...


I can't pretend I understand exactly why, but this also worked for me.

Offline

#31 Yesterday 17:06:21

tropicalia
Member
Registered: 2025-11-13
Posts: 23

Re: TPM2 errors after updates - TPM key integrity check failed

ugjka wrote:

Was reading the github issue, this seems the proper fix:

Ferdi265 wrote:

For me, the following settings worked to fix the errors:

OS: Arch Linux 
Secure Boot: via sbctl 
Initramfs/UKI Generator: `mkinitcpio` with UKI enabled 
LUKS: yes, but without TPM unlock

# /etc/kernel/uki.conf
[UKI]
SignInitrdPCRs=yes

[PCRSignature:all]
PCRPrivateKey=/etc/systemd/tpm2-pcr-private-key.pem
PCRPublicKey=/etc/systemd/tpm2-pcr-public-key.pem

run:

# pacman -S systemd-ukify
# ukify genkey \
        --pcr-private-key=/etc/systemd/tpm2-pcr-private-key.pem \
        --pcr-public-key=/etc/systemd/tpm2-pcr-public-key.pem
# mkinitcpio -P

nothing else was needed.

I had to reboot and run mkinitcpio -P twice for all errers disappear though, no clue why but whatever...

Is this also recommended (safe) if the system is configured for TPM unlock?

Offline

#32 Yesterday 22:30:23

Koli
Member
Registered: 2025-12-03
Posts: 4

Re: TPM2 errors after updates - TPM key integrity check failed

I am also in the crowd of not using LUKS in any capacity, and booting an UKI created by mkinitcpio, and I have the same services fail. I don't remember configuring anything for TPM in fact, it's just enabled and left as is. Anyone has a lead for how to resolve the failing services for this?
Logs just in case

Oct 07 22:09:28 archlinux systemd-tpm2-setup[223]: SRK public key saved to '/run/systemd/tpm2-srk-public-key.pem' in PEM format.
Oct 07 22:09:28 archlinux systemd-tpm2-setup[223]: SRK public key saved to '/run/systemd/tpm2-srk-public-key.tpm2b_public' in TPM2B_PUBLIC format.
Oct 07 22:09:28 archlinux systemd-tpm2-setup[223]: Failed to initialize NvPCR index: No such file or directory
Oct 07 22:09:28 archlinux systemd-tpm2-setup[223]: Failed to initialize NvPCR index: No such file or directory
Oct 07 22:09:28 archlinux systemd-tpm2-setup[223]: Failed to initialize NvPCR index: No such file or directory
Oct 07 22:09:28 archlinux systemd-tpm2-setup[223]: Failed to initialize NvPCR index: No such file or directory
Oct 07 22:09:28 archlinux systemd-tpm2-setup[223]: 4 NvPCRs failed to initialize, proceeding anyway.
Oct 07 22:09:28 archlinux systemd[1]: systemd-tpm2-setup-early.service: Main process exited, code=exited, status=1/FAILURE

Offline

Board footer

Powered by FluxBB