Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1189354

Bug#1065392: Additional information : secure boot involved

From <pdormeau@free.fr>
Newsgroups linux.debian.bugs.dist, linux.debian.kernel
Subject Bug#1065392: Additional information : secure boot involved
Date 2024-03-07 10:50 +0100
Message-ID <IfixX-eZWN-1@gated-at.bofh.it> (permalink)
References <If5r3-eRPj-1@gated-at.bofh.it> <IdZe1-ec5Q-15@gated-at.bofh.it> <If5r3-eRPj-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Cross-posted to 2 groups.

Show all headers | View raw


Hello,

I made additional tests this morning showing that the problem is
related to the secure boot (even when the secure-boot-policy PCR binding
is not used).

- secure boot enabled, no PCR binding (--tpm2-pcrs="" passed to
  systemd-cryptenroll) : OK

- secure boot enabled, PCR binding (--tpm2-pcrs=any value other than 7
  passed to systemd-cryptenroll) : NOK

- secure boot disabled, PCR binding (--tpm2-pcrs=any value other than 7
  passed to systemd-cryptenroll) : OK

According to the systemd-cryptenroll manual, if no PCR binding is
specified the default is to use PCR 7 only. I can infer that when a
PCR value other than 7 is passed to system-cryptenroll, the
secure-boot-policy binding does not apply.

In conclusion, linux-image-6.7.7-amd64 fails to decrypt the LUKS volume
with tpm2 when secure boot is enabled and a PCR binding is used.

Due to the secure boot involvement, this not something that I can debug
myself using gitbisect (https://wiki.debian.org/DebianKernel/GitBisect
says secure boot should be disable)

Best regards

Back to linux.debian.bugs.dist | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

Bug#1065392: linux-image-6.7.7-amd64: Regression : "Failed to unseal secret using TPM2: Invalid argument" pdormeau@free.fr - 2024-03-03 20:00 +0100
  Bug#1065392: Additional information <pdormeau@free.fr> - 2024-03-06 20:50 +0100
    Bug#1065392: Additional information : secure boot involved <pdormeau@free.fr> - 2024-03-07 10:50 +0100

csiph-web