(In reply to Alberto Planas Dominguez from comment #58) > (In reply to Artur Kaufmann from comment #57) > > Created attachment 878444 [details] > > > Attached you can find all actions, as update-predictions failed and the TPM > > stays locked. > > Thanks a lot. As I see the re-enrollment worked. I understand that now the > system boot without asking the password? Yes, it worked now again properly. > > What is more interesting is now 2 entries where selected and no PolicyOR > error was present. > > My working theory now is that there are TPM2s with different limits of > PolicyOR branches. Some are 8, other 4, and yours seem to be 2. > > > BR Maybe the revision of the TPM2.0 chip is also important > sudo tpm2_getcap properties-fixed | grep TPM2_PT_REVISION -A2 > TPM2_PT_REVISION: > raw: 0x8A > value: 1.38 BR