#TPM PCR0 reconstruction invalid

1 messages · Page 1 of 1 (latest)

slow drum
#

following output from fwupdmgr security:
HSI-1
✔ BIOS firmware updates: Enabled
✔ Fused platform: Locked
✔ Supported CPU: Valid
✔ TPM empty PCRs: Valid
✔ TPM v2.0: Found
✔ UEFI bootservice variables: Locked
✔ UEFI secure boot: Enabled

HSI-2
✔ SPI write protection: Enabled
✔ IOMMU: Enabled
✔ Platform debugging: Locked
✘ TPM PCR0 reconstruction: Invalid

HSI-3
✔ CET Platform: Supported
✔ Pre-boot DMA protection: Enabled
✘ SPI replay protection: Not supported
✘ Suspend-to-idle: Disabled
✘ Suspend-to-ram: Enabled

HSI-4
✔ Encrypted RAM: Encrypted
✔ SMAP: Enabled
✘ Processor rollback protection: Disabled

Runtime Suffix -!
✔ CET OS Support: Supported
✔ fwupd plugins: Untainted
✔ Linux kernel lockdown: Enabled
✔ Linux swap: Encrypted
✘ Linux kernel: Tainted

after changing from fTPM to pluton TPM reconstruction is invalid, haven't found a setting to clear/reset TPM in my BIOS but I could be wrong
I'm using B650 gigabyte aorus elite AX with latest BIOS

sturdy timber
#

could just be a detection issue with Pluton or config issue, not much you can do on SB for that

sturdy timber
slow drum
#

isn't the fact I'm booting showing me that TPM is working?

#

I expect it would hang at LUKS or secureboot if it wasn,t right?

slow drum
#

this is the output of tpm2_getcap pcrs
selected-pcrs:

  • sha1: [ ]
  • sha256: [ 0, 1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11, 12, 13, 14, 15, 16, 17, 18, 19, 20, 21, 22, 23 ]
  • sha384: [ ]
#

output of tpm2_pcrread sha256
sha256:
0 : 0xCF50C90EF7AE84508E22E751AE28F66F2797205B9182E62E1844C0C0D5B9F2B8
1 : 0x4F18B44A67987723E876E144798CFF2E44C4524CB95428A5D2EFDB166C31EC56
2 : 0x351D2A8B9BB981764C78C9A8B18FA890C46AA13F78AFA9FB44292422718FF386
3 : 0x3D458CFE55CC03EA1F443F1562BEEC8DF51C75E14A9FCF9A7234A13F198E7969
4 : 0xCF22228B9669EC139741588D70054D241EA0D746941A242FE629BEBE6F243C48
5 : 0xF10460FCAFB61E1C92375EE1D73DB661DB717FB49B57A15D853A2E230AAA05B6
6 : 0x3D458CFE55CC03EA1F443F1562BEEC8DF51C75E14A9FCF9A7234A13F198E7969
7 : 0x1B10226D9F5E9BC15B19C23F8E8B27FA22641C9CB192EDCD66D61AD5C4796499
8 : 0x29A8598B046B5A6E33FEE1C30E8D8B19808D2B6ED5352275CE6492E8EFA3B27F
9 : 0xDD966B788C33B3BB5CDEDD3110C29AC663BA55A088619BA81B06616EB4B1471A
10: 0xFF75AFB7F506C0E4679C6511390BC4EC49980DCA9BF9E5847807FBF6B9FFB0C7
11: 0x0000000000000000000000000000000000000000000000000000000000000000
12: 0x0000000000000000000000000000000000000000000000000000000000000000
13: 0x0000000000000000000000000000000000000000000000000000000000000000
14: 0xFB37D61C5DAB4792EBD34CF85D749FBA5D1E947A91DD24C496DFDED32432BE71
15: 0x0000000000000000000000000000000000000000000000000000000000000000
16: 0x0000000000000000000000000000000000000000000000000000000000000000
17: 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
18: 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
19: 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
20: 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
21: 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
22: 0xFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF
23: 0x0000000000000000000000000000000000000000000000000000000000000000