Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.kernel > #82038
| Path | csiph.com!fu-berlin.de!bofh.it!news.nic.it!robomod |
|---|---|
| From | <pdormeau@free.fr> |
| Newsgroups | linux.debian.bugs.dist, linux.debian.kernel |
| Subject | Bug#1065392: Additional information : secure boot involved |
| Date | Thu, 07 Mar 2024 10:50:01 +0100 |
| Message-ID | <IfixX-eZWN-1@gated-at.bofh.it> (permalink) |
| References | <If5r3-eRPj-1@gated-at.bofh.it> <IdZe1-ec5Q-15@gated-at.bofh.it> <If5r3-eRPj-1@gated-at.bofh.it> |
| X-Original-To | 1065392@bugs.debian.org |
| X-Mailbox-Line | From debian-bugs-dist-request@lists.debian.org Thu Mar 7 09:42:09 2024 |
| Old-Return-Path | <debbugs@buxtehude.debian.org> |
| X-Spam-Flag | NO |
| X-Spam-Score | 0.441 |
| Reply-To | <pdormeau@free.fr>, 1065392@bugs.debian.org |
| Resent-To | debian-bugs-dist@lists.debian.org |
| Resent-Cc | Debian Kernel Team <debian-kernel@lists.debian.org> |
| X-Debian-Pr-Message | followup 1065392 |
| X-Debian-Pr-Package | src:linux |
| X-Debian-Pr-Source | linux |
| X-Mailer | Claws Mail 4.2.0 (GTK 3.24.41; x86_64-pc-linux-gnu) |
| MIME-Version | 1.0 |
| Content-Type | text/plain; charset=US-ASCII |
| Content-Transfer-Encoding | 7bit |
| X-Debian-Message | from BTS |
| X-Mailing-List | <debian-bugs-dist@lists.debian.org> archive/latest/1826265 |
| List-ID | <debian-bugs-dist.lists.debian.org> |
| List-URL | <https://lists.debian.org/debian-bugs-dist/> |
| Approved | robomod@news.nic.it |
| Lines | 28 |
| Organization | linux.* mail to news gateway |
| Sender | robomod@news.nic.it |
| X-Original-Date | Thu, 7 Mar 2024 10:38:31 +0100 |
| X-Original-Message-ID | <20240307103831.315001df@myrtille> |
| X-Original-References | <20240306204519.3cd7bde8@myrtille> <170949203541.1528.15984670514377961240.reportbug@myrtille> <20240306204519.3cd7bde8@myrtille> |
| Xref | csiph.com linux.debian.bugs.dist:1189354 linux.debian.kernel:82038 |
Cross-posted to 2 groups.
Show key headers only | View raw
Hello, I made additional tests this morning showing that the problem is related to the secure boot (even when the secure-boot-policy PCR binding is not used). - secure boot enabled, no PCR binding (--tpm2-pcrs="" passed to systemd-cryptenroll) : OK - secure boot enabled, PCR binding (--tpm2-pcrs=any value other than 7 passed to systemd-cryptenroll) : NOK - secure boot disabled, PCR binding (--tpm2-pcrs=any value other than 7 passed to systemd-cryptenroll) : OK According to the systemd-cryptenroll manual, if no PCR binding is specified the default is to use PCR 7 only. I can infer that when a PCR value other than 7 is passed to system-cryptenroll, the secure-boot-policy binding does not apply. In conclusion, linux-image-6.7.7-amd64 fails to decrypt the LUKS volume with tpm2 when secure boot is enabled and a PCR binding is used. Due to the secure boot involvement, this not something that I can debug myself using gitbisect (https://wiki.debian.org/DebianKernel/GitBisect says secure boot should be disable) Best regards
Back to linux.debian.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Bug#1065392: linux-image-6.7.7-amd64: Regression : "Failed to unseal secret using TPM2: Invalid argument" pdormeau@free.fr - 2024-03-03 20:00 +0100
Bug#1065392: Additional information <pdormeau@free.fr> - 2024-03-06 20:50 +0100
Bug#1065392: Additional information : secure boot involved <pdormeau@free.fr> - 2024-03-07 10:50 +0100
Bug#1065392: Problem solved with linux-image-6.9.7-amd64 <pdormeau@free.fr> - 2024-06-29 07:50 +0200
Bug#1065392: Problem solved with linux-image-6.9.7-amd64 Salvatore Bonaccorso <carnil@debian.org> - 2024-07-03 09:50 +0200
Bug#1065392: marked as done (linux-image-6.7.7-amd64: Regression : "Failed to unseal secret using TPM2: Invalid argument") "Debian Bug Tracking System" <owner@bugs.debian.org> - 2024-07-03 09:50 +0200
csiph-web