Path: csiph.com!fu-berlin.de!bofh.it!news.nic.it!robomod From: Newsgroups: linux.debian.bugs.dist,linux.debian.kernel Subject: Bug#1065392: Additional information : secure boot involved Date: Thu, 07 Mar 2024 10:50:01 +0100 Message-ID: References: X-Original-To: 1065392@bugs.debian.org X-Mailbox-Line: From debian-bugs-dist-request@lists.debian.org Thu Mar 7 09:42:09 2024 Old-Return-Path: X-Spam-Flag: NO X-Spam-Score: 0.441 Reply-To: , 1065392@bugs.debian.org Resent-To: debian-bugs-dist@lists.debian.org Resent-Cc: Debian Kernel Team X-Debian-Pr-Message: followup 1065392 X-Debian-Pr-Package: src:linux X-Debian-Pr-Source: linux X-Mailer: Claws Mail 4.2.0 (GTK 3.24.41; x86_64-pc-linux-gnu) MIME-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit X-Debian-Message: from BTS X-Mailing-List: archive/latest/1826265 List-ID: List-URL: Approved: robomod@news.nic.it Lines: 28 Organization: linux.* mail to news gateway Sender: robomod@news.nic.it X-Original-Date: Thu, 7 Mar 2024 10:38:31 +0100 X-Original-Message-ID: <20240307103831.315001df@myrtille> X-Original-References: <20240306204519.3cd7bde8@myrtille> <170949203541.1528.15984670514377961240.reportbug@myrtille> <20240306204519.3cd7bde8@myrtille> Xref: csiph.com linux.debian.bugs.dist:1189354 linux.debian.kernel:82038 Hello, I made additional tests this morning showing that the problem is related to the secure boot (even when the secure-boot-policy PCR binding is not used). - secure boot enabled, no PCR binding (--tpm2-pcrs="" passed to systemd-cryptenroll) : OK - secure boot enabled, PCR binding (--tpm2-pcrs=any value other than 7 passed to systemd-cryptenroll) : NOK - secure boot disabled, PCR binding (--tpm2-pcrs=any value other than 7 passed to systemd-cryptenroll) : OK According to the systemd-cryptenroll manual, if no PCR binding is specified the default is to use PCR 7 only. I can infer that when a PCR value other than 7 is passed to system-cryptenroll, the secure-boot-policy binding does not apply. In conclusion, linux-image-6.7.7-amd64 fails to decrypt the LUKS volume with tpm2 when secure boot is enabled and a PCR binding is used. Due to the secure boot involvement, this not something that I can debug myself using gitbisect (https://wiki.debian.org/DebianKernel/GitBisect says secure boot should be disable) Best regards