following output from fwupdmgr security:
HSI-1
✔ BIOS firmware updates: Enabled
✔ Fused platform: Locked
✔ Supported CPU: Valid
✔ TPM empty PCRs: Valid
✔ TPM v2.0: Found
✔ UEFI bootservice variables: Locked
✔ UEFI secure boot: Enabled
HSI-2
✔ SPI write protection: Enabled
✔ IOMMU: Enabled
✔ Platform debugging: Locked
✘ TPM PCR0 reconstruction: Invalid
HSI-3
✔ CET Platform: Supported
✔ Pre-boot DMA protection: Enabled
✘ SPI replay protection: Not supported
✘ Suspend-to-idle: Disabled
✘ Suspend-to-ram: Enabled
HSI-4
✔ Encrypted RAM: Encrypted
✔ SMAP: Enabled
✘ Processor rollback protection: Disabled
Runtime Suffix -!
✔ CET OS Support: Supported
✔ fwupd plugins: Untainted
✔ Linux kernel lockdown: Enabled
✔ Linux swap: Encrypted
✘ Linux kernel: Tainted
after changing from fTPM to pluton TPM reconstruction is invalid, haven't found a setting to clear/reset TPM in my BIOS but I could be wrong
I'm using B650 gigabyte aorus elite AX with latest BIOS