[Bug 1229048] New: Always prompted for recovery key, but could not update predictions
https://bugzilla.suse.com/show_bug.cgi?id=1229048 Bug ID: 1229048 Summary: Always prompted for recovery key, but could not update predictions Classification: openSUSE Product: openSUSE Aeon Version: Current Hardware: x86-64 OS: Other Status: NEW Severity: Major Priority: P5 - None Component: Base Assignee: rbrown@suse.com Reporter: vandeft@gmail.com QA Contact: qa-bugs@suse.de Target Milestone: --- Found By: --- Blocker: --- User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:129.0) Gecko/20100101 Firefox/129.0 Build Identifier: The recovery key prompt started after disabling and enabling Secure Boot. I tried running the following command as recommended on the troubleshooting page: sudo sdbootutil --ask-pin update-predictions The problem is that I get the error: "Provided PIN Incorrect or TPM2 locked after too many retries" even after only entering the recovery key once. I know it was entered correctly because I copied it from my password manager. Reproducible: Always Steps to Reproduce: 1. Disable Secure Boot and restart 2. Enable Secure Boot and restart 3. Boot openSUSE Aeon and enter recovery key 4. Open terminal and run "sudo sdbootutil --ask-pin update-predictions" 5. Enter recovery key Actual Results: sdbootutil tries to restore the link between my system and its encryption, but fails. Expected Results: sdbootutil should succeed in restoring the link between my system and its encryption. ○ → sudo sdbootutil -vv --ask-pin update-predictions Found cgroup2 on /sys/fs/cgroup/, full unified hierarchy Found container virtualization none. Failed to check file system type of "/efi": No such file or directory File system "/boot" is not a FAT EFI System Partition (ESP) file system. Using EFI System Partition at /boot/efi. Directory "/boot" is not the root of the file system. Didn't find an XBOOTLDR partition, using the ESP as $BOOT. Reading EFI variable /sys/firmware/efi/efivars/LoaderEntries-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f. Reading EFI variable /sys/firmware/efi/efivars/LoaderEntryOneShot-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f. open("/sys/firmware/efi/efivars/LoaderEntryOneShot-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f") failed: No such file or directory Reading EFI variable /sys/firmware/efi/efivars/LoaderEntryDefault-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f. Reading EFI variable /sys/firmware/efi/efivars/LoaderEntrySelected-4a67b082-0a4c-41cf-b6c7-440b29bb8c4f. Found default: id "opensuse-aeon-6.10.3-1-default-22.conf" is matched by LoaderEntryDefault TPM PC Client Platform Firmware Profile: family 2.0, revision 0.0 Ignoring device path element type=0x04 subtype=0x07 Ignoring device path element type=0x04 subtype=0x06 Ignoring device path element type=0x02 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x03 subtype=0x17 Ignoring device path element type=0x04 subtype=0x01 Garbage after device path end, ignoring. Loaded 'libtss2-esys.so.0' via dlopen() Loaded 'libtss2-rc.so.0' via dlopen() Loaded 'libtss2-mu.so.0' via dlopen() Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'. Loaded 'libtss2-tcti-device.so.0' via dlopen() Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux kernel interface.) [Version 2] TPM successfully started up. Getting TPM2 capability 0x0000 property 0x0001 count 127. Getting TPM2 capability 0x0002 property 0x011f count 256. Getting TPM2 capability 0x0008 property 0x0000 count 508. Getting TPM2 capability 0x0005 property 0x0000 count 1. Reading PCR selection: [sha1(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(0+1+2+3+4+5+6+7)] PCR value: 0:sha1=23745cb6a52f04f520bcb67a57a8ceeaa67cdcf7 PCR value: 1:sha1=b57cd41bd48870f77d0d89830a04ee328fe916b0 PCR value: 2:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 3:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 4:sha1=5822de53cb1b4fb68f7535304b12309e833c93c8 PCR value: 5:sha1=4fd367f64ae596ff430c5c81ccd39c8f3febf992 PCR value: 6:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 7:sha1=e820d059eeab7d4b134ceae88672f569d4a7eb74 Reading PCR selection: [sha1(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(8+9+10+11+12+13+14+15)] PCR value: 8:sha1=0000000000000000000000000000000000000000 PCR value: 9:sha1=28420f38f0c0493e60bc4349ff11f2bc1cadf744 PCR value: 10:sha1=0f7ed4a3679f7f30a7934952afd2de10d93ad37b PCR value: 11:sha1=0000000000000000000000000000000000000000 PCR value: 12:sha1=b170a442bed9b3c14c3b6a72cc3866dc6d844382 PCR value: 13:sha1=0000000000000000000000000000000000000000 PCR value: 14:sha1=677f1f77d72332e8e8041f16b6c082bf077ece84 PCR value: 15:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha1(16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(16+17+18+19+20+21+22+23)] PCR value: 16:sha1=0000000000000000000000000000000000000000 PCR value: 17:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(0+1+2+3+4+5+6+7)] PCR value: 0:sha256=c1f2e40d330b6a6b982f00c5aa76ac32800a36f7afdb294bf34569f1433335bb PCR value: 1:sha256=da33d382da316e5c6be06d1164b785dbec2ed2c9aaf3938c43dbcf675d074846 PCR value: 2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 4:sha256=2c8acbf406e4ea74fa014baf1180c8f28d7c60cb3a27265d274b027885cc2416 PCR value: 5:sha256=c0b661f390b58a95f7c0173ae70e0cccaa6917f6108de9542463c578cee1d203 PCR value: 6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 7:sha256=22f5a51babd581abe57a405f84e41c8f3da14c41ab345f274ba406d998886962 Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(8+9+10+11+12+13+14+15)] PCR value: 8:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 9:sha256=d4d845f23d71324ec38766e1c19f2cfe2bd413ecf27ae3b0681a5aaab38d897f PCR value: 10:sha256=e47fa4366c3527eabfabcdbb73db784214a87af792ffcdd0fc2ff44c76185f93 PCR value: 11:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 12:sha256=a443f6cf29ccc0245b39893ebf2d8bd221a021d9f68c3124849f0cb20e965832 PCR value: 13:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 14:sha256=1095b057262e3e9e1b0f3952228f2b2741be5d85dbfe5951c7e41279ceb2ebe8 PCR value: 15:sha256=0000000000000000000000000000000000000000000000000000000000000000 Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(16+17+18+19+20+21+22+23)] PCR value: 16:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha256=0000000000000000000000000000000000000000000000000000000000000000 /var/lib/pcrlock.d/250-firmware-code-early.pcrlock.d/generated.pcrlock written. /var/lib/pcrlock.d/550-firmware-code-late.pcrlock.d/generated.pcrlock written. TPM PC Client Platform Firmware Profile: family 2.0, revision 0.0 Ignoring device path element type=0x04 subtype=0x07 Ignoring device path element type=0x04 subtype=0x06 Ignoring device path element type=0x02 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x03 subtype=0x17 Ignoring device path element type=0x04 subtype=0x01 Garbage after device path end, ignoring. Loaded 'libtss2-esys.so.0' via dlopen() Loaded 'libtss2-rc.so.0' via dlopen() Loaded 'libtss2-mu.so.0' via dlopen() Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'. Loaded 'libtss2-tcti-device.so.0' via dlopen() Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux kernel interface.) [Version 2] TPM successfully started up. Getting TPM2 capability 0x0000 property 0x0001 count 127. Getting TPM2 capability 0x0002 property 0x011f count 256. Getting TPM2 capability 0x0008 property 0x0000 count 508. Getting TPM2 capability 0x0005 property 0x0000 count 1. Reading PCR selection: [sha1(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(0+1+2+3+4+5+6+7)] PCR value: 0:sha1=23745cb6a52f04f520bcb67a57a8ceeaa67cdcf7 PCR value: 1:sha1=b57cd41bd48870f77d0d89830a04ee328fe916b0 PCR value: 2:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 3:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 4:sha1=5822de53cb1b4fb68f7535304b12309e833c93c8 PCR value: 5:sha1=4fd367f64ae596ff430c5c81ccd39c8f3febf992 PCR value: 6:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 7:sha1=e820d059eeab7d4b134ceae88672f569d4a7eb74 Reading PCR selection: [sha1(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(8+9+10+11+12+13+14+15)] PCR value: 8:sha1=0000000000000000000000000000000000000000 PCR value: 9:sha1=28420f38f0c0493e60bc4349ff11f2bc1cadf744 PCR value: 10:sha1=0f7ed4a3679f7f30a7934952afd2de10d93ad37b PCR value: 11:sha1=0000000000000000000000000000000000000000 PCR value: 12:sha1=b170a442bed9b3c14c3b6a72cc3866dc6d844382 PCR value: 13:sha1=0000000000000000000000000000000000000000 PCR value: 14:sha1=677f1f77d72332e8e8041f16b6c082bf077ece84 PCR value: 15:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha1(16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(16+17+18+19+20+21+22+23)] PCR value: 16:sha1=0000000000000000000000000000000000000000 PCR value: 17:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(0+1+2+3+4+5+6+7)] PCR value: 0:sha256=c1f2e40d330b6a6b982f00c5aa76ac32800a36f7afdb294bf34569f1433335bb PCR value: 1:sha256=da33d382da316e5c6be06d1164b785dbec2ed2c9aaf3938c43dbcf675d074846 PCR value: 2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 4:sha256=2c8acbf406e4ea74fa014baf1180c8f28d7c60cb3a27265d274b027885cc2416 PCR value: 5:sha256=c0b661f390b58a95f7c0173ae70e0cccaa6917f6108de9542463c578cee1d203 PCR value: 6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 7:sha256=22f5a51babd581abe57a405f84e41c8f3da14c41ab345f274ba406d998886962 Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(8+9+10+11+12+13+14+15)] PCR value: 8:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 9:sha256=d4d845f23d71324ec38766e1c19f2cfe2bd413ecf27ae3b0681a5aaab38d897f PCR value: 10:sha256=e47fa4366c3527eabfabcdbb73db784214a87af792ffcdd0fc2ff44c76185f93 PCR value: 11:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 12:sha256=a443f6cf29ccc0245b39893ebf2d8bd221a021d9f68c3124849f0cb20e965832 PCR value: 13:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 14:sha256=1095b057262e3e9e1b0f3952228f2b2741be5d85dbfe5951c7e41279ceb2ebe8 PCR value: 15:sha256=0000000000000000000000000000000000000000000000000000000000000000 Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(16+17+18+19+20+21+22+23)] PCR value: 16:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha256=0000000000000000000000000000000000000000000000000000000000000000 /var/lib/pcrlock.d/250-firmware-config-early.pcrlock.d/generated.pcrlock written. /var/lib/pcrlock.d/550-firmware-config-late.pcrlock.d/generated.pcrlock written. /var/lib/pcrlock.d/600-gpt.pcrlock.d/generated.pcrlock written. Hashing 216 @ 0 → 216 Hashing 76 @ 220 → 296 Hashing 720 @ 304 → 1024 Hashing 117760 @ 1024 → 118784 Hashing 379392 @ 118784 → 498176 Hashing 512 @ 498176 → 498688 Hashing 512 @ 498688 → 499200 Hashing 179712 @ 499200 → 678912 Hashing 6656 @ 678912 → 685568 Hashing 512 @ 685568 → 686080 Hashing 111616 @ 686080 → 797696 Hashing 512 @ 797696 → 798208 Hashing 125368 @ 798208 → 923576 Hashing 216 @ 0 → 216 Hashing 76 @ 220 → 296 Hashing 720 @ 304 → 1024 Hashing 117760 @ 1024 → 118784 Hashing 379392 @ 118784 → 498176 Hashing 512 @ 498176 → 498688 Hashing 512 @ 498688 → 499200 Hashing 179712 @ 499200 → 678912 Hashing 6656 @ 678912 → 685568 Hashing 512 @ 685568 → 686080 Hashing 111616 @ 686080 → 797696 Hashing 512 @ 797696 → 798208 Hashing 125368 @ 798208 → 923576 Hashing 216 @ 0 → 216 Hashing 76 @ 220 → 296 Hashing 720 @ 304 → 1024 Hashing 117760 @ 1024 → 118784 Hashing 379392 @ 118784 → 498176 Hashing 512 @ 498176 → 498688 Hashing 512 @ 498688 → 499200 Hashing 179712 @ 499200 → 678912 Hashing 6656 @ 678912 → 685568 Hashing 512 @ 685568 → 686080 Hashing 111616 @ 686080 → 797696 Hashing 512 @ 797696 → 798208 Hashing 125368 @ 798208 → 923576 Hashing 216 @ 0 → 216 Hashing 76 @ 220 → 296 Hashing 720 @ 304 → 1024 Hashing 117760 @ 1024 → 118784 Hashing 379392 @ 118784 → 498176 Hashing 512 @ 498176 → 498688 Hashing 512 @ 498688 → 499200 Hashing 179712 @ 499200 → 678912 Hashing 6656 @ 678912 → 685568 Hashing 512 @ 685568 → 686080 Hashing 111616 @ 686080 → 797696 Hashing 512 @ 797696 → 798208 Hashing 125368 @ 798208 → 923576 /var/lib/pcrlock.d/630-shim-efi-application.pcrlock.d/generated.pcrlock written. Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 784 @ 240 → 1024 Hashing 74752 @ 1024 → 75776 Hashing 20480 @ 75776 → 96256 Hashing 512 @ 96256 → 96768 Hashing 512 @ 96768 → 97280 Hashing 512 @ 97280 → 97792 Hashing 512 @ 97792 → 98304 Hashing 512 @ 98304 → 98816 Hashing 0 @ 98816 → 98816 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 784 @ 240 → 1024 Hashing 74752 @ 1024 → 75776 Hashing 20480 @ 75776 → 96256 Hashing 512 @ 96256 → 96768 Hashing 512 @ 96768 → 97280 Hashing 512 @ 97280 → 97792 Hashing 512 @ 97792 → 98304 Hashing 512 @ 98304 → 98816 Hashing 0 @ 98816 → 98816 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 784 @ 240 → 1024 Hashing 74752 @ 1024 → 75776 Hashing 20480 @ 75776 → 96256 Hashing 512 @ 96256 → 96768 Hashing 512 @ 96768 → 97280 Hashing 512 @ 97280 → 97792 Hashing 512 @ 97792 → 98304 Hashing 512 @ 98304 → 98816 Hashing 0 @ 98816 → 98816 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 784 @ 240 → 1024 Hashing 74752 @ 1024 → 75776 Hashing 20480 @ 75776 → 96256 Hashing 512 @ 96256 → 96768 Hashing 512 @ 96768 → 97280 Hashing 512 @ 97280 → 97792 Hashing 512 @ 97792 → 98304 Hashing 512 @ 98304 → 98816 Hashing 0 @ 98816 → 98816 /var/lib/pcrlock.d/640-boot-loader-efi-application.pcrlock.d/generated.pcrlock written. /var/lib/pcrlock.d/641-sdboot-loader-conf.pcrlock written. Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 3856 @ 240 → 4096 Hashing 12288 @ 4096 → 16384 Hashing 4096 @ 16384 → 20480 Hashing 14741504 @ 20480 → 14761984 Hashing 4608 @ 14761984 → 14766592 Hashing 0 @ 14766592 → 14766592 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 3856 @ 240 → 4096 Hashing 12288 @ 4096 → 16384 Hashing 4096 @ 16384 → 20480 Hashing 14741504 @ 20480 → 14761984 Hashing 4608 @ 14761984 → 14766592 Hashing 0 @ 14766592 → 14766592 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 3856 @ 240 → 4096 Hashing 12288 @ 4096 → 16384 Hashing 4096 @ 16384 → 20480 Hashing 14741504 @ 20480 → 14761984 Hashing 4608 @ 14761984 → 14766592 Hashing 0 @ 14766592 → 14766592 Hashing 152 @ 0 → 152 Hashing 76 @ 156 → 232 Hashing 3856 @ 240 → 4096 Hashing 12288 @ 4096 → 16384 Hashing 4096 @ 16384 → 20480 Hashing 14741504 @ 20480 → 14761984 Hashing 4608 @ 14761984 → 14766592 Hashing 0 @ 14766592 → 14766592 /var/lib/pcrlock.d/650-kernel-efi-application.pcrlock.d/linux-1.pcrlock written. /tmp/sdbootutil.pzayUU/cmdline.pcrlock written. /var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-1.pcrlock written. /tmp/sdbootutil.pzayUU/cmdline.pcrlock written. /var/lib/pcrlock.d/710-kernel-cmdline-boot-loader.pcrlock.d/cmdline-2.pcrlock written. Recovery PIN: TPM PC Client Platform Firmware Profile: family 2.0, revision 0.0 Ignoring device path element type=0x04 subtype=0x07 Ignoring device path element type=0x04 subtype=0x06 Ignoring device path element type=0x02 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x01 subtype=0x01 Ignoring device path element type=0x03 subtype=0x17 Ignoring device path element type=0x04 subtype=0x01 Garbage after device path end, ignoring. Loaded 'libtss2-esys.so.0' via dlopen() Loaded 'libtss2-rc.so.0' via dlopen() Loaded 'libtss2-mu.so.0' via dlopen() Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'. Loaded 'libtss2-tcti-device.so.0' via dlopen() Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux kernel interface.) [Version 2] TPM successfully started up. Getting TPM2 capability 0x0000 property 0x0001 count 127. Getting TPM2 capability 0x0002 property 0x011f count 256. Getting TPM2 capability 0x0008 property 0x0000 count 508. Getting TPM2 capability 0x0005 property 0x0000 count 1. Reading PCR selection: [sha1(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(0+1+2+3+4+5+6+7)] PCR value: 0:sha1=23745cb6a52f04f520bcb67a57a8ceeaa67cdcf7 PCR value: 1:sha1=b57cd41bd48870f77d0d89830a04ee328fe916b0 PCR value: 2:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 3:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 4:sha1=5822de53cb1b4fb68f7535304b12309e833c93c8 PCR value: 5:sha1=4fd367f64ae596ff430c5c81ccd39c8f3febf992 PCR value: 6:sha1=b2a83b0ebf2f8374299a5b2bdfc31ea955ad7236 PCR value: 7:sha1=e820d059eeab7d4b134ceae88672f569d4a7eb74 Reading PCR selection: [sha1(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(8+9+10+11+12+13+14+15)] PCR value: 8:sha1=0000000000000000000000000000000000000000 PCR value: 9:sha1=28420f38f0c0493e60bc4349ff11f2bc1cadf744 PCR value: 10:sha1=0f7ed4a3679f7f30a7934952afd2de10d93ad37b PCR value: 11:sha1=0000000000000000000000000000000000000000 PCR value: 12:sha1=b170a442bed9b3c14c3b6a72cc3866dc6d844382 PCR value: 13:sha1=0000000000000000000000000000000000000000 PCR value: 14:sha1=677f1f77d72332e8e8041f16b6c082bf077ece84 PCR value: 15:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha1(16+17+18+19+20+21+22+23)] Read PCR selection: [sha1(16+17+18+19+20+21+22+23)] PCR value: 16:sha1=0000000000000000000000000000000000000000 PCR value: 17:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha1=ffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha1=0000000000000000000000000000000000000000 Reading PCR selection: [sha256(0+1+2+3+4+5+6+7+8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(0+1+2+3+4+5+6+7)] PCR value: 0:sha256=c1f2e40d330b6a6b982f00c5aa76ac32800a36f7afdb294bf34569f1433335bb PCR value: 1:sha256=da33d382da316e5c6be06d1164b785dbec2ed2c9aaf3938c43dbcf675d074846 PCR value: 2:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 3:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 4:sha256=2c8acbf406e4ea74fa014baf1180c8f28d7c60cb3a27265d274b027885cc2416 PCR value: 5:sha256=c0b661f390b58a95f7c0173ae70e0cccaa6917f6108de9542463c578cee1d203 PCR value: 6:sha256=3d458cfe55cc03ea1f443f1562beec8df51c75e14a9fcf9a7234a13f198e7969 PCR value: 7:sha256=22f5a51babd581abe57a405f84e41c8f3da14c41ab345f274ba406d998886962 Reading PCR selection: [sha256(8+9+10+11+12+13+14+15+16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(8+9+10+11+12+13+14+15)] PCR value: 8:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 9:sha256=d4d845f23d71324ec38766e1c19f2cfe2bd413ecf27ae3b0681a5aaab38d897f PCR value: 10:sha256=e47fa4366c3527eabfabcdbb73db784214a87af792ffcdd0fc2ff44c76185f93 PCR value: 11:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 12:sha256=a443f6cf29ccc0245b39893ebf2d8bd221a021d9f68c3124849f0cb20e965832 PCR value: 13:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 14:sha256=1095b057262e3e9e1b0f3952228f2b2741be5d85dbfe5951c7e41279ceb2ebe8 PCR value: 15:sha256=0000000000000000000000000000000000000000000000000000000000000000 Reading PCR selection: [sha256(16+17+18+19+20+21+22+23)] Read PCR selection: [sha256(16+17+18+19+20+21+22+23)] PCR value: 16:sha256=0000000000000000000000000000000000000000000000000000000000000000 PCR value: 17:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 18:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 19:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 20:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 21:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 22:sha256=ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff PCR value: 23:sha256=0000000000000000000000000000000000000000000000000000000000000000 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. 'content_type' missing from TPM measurement log file entry, ignoring. Found 2 possible variants of component '650-kernel-efi-application' in event log (linux-1, linux-2). Proceeding. Couldn't find component '750-enter-initrd' in event log. Didn't find component '800-leave-initrd' in event log, assuming system hasn't reached it yet. Didn't find component '850-sysinit' in event log, assuming system hasn't reached it yet. Didn't find component '900-ready' in event log, assuming system hasn't reached it yet. Skipped 2 components after location '940-' (950-shutdown, 990-final). Unable to recognize 1 components in event log. Event log record 29 (PCR 14, "Raw: MokList\000") not matching any component. PCR 0 (platform-code) matches event log and fully consists of recognized measurements. Including in set of PCRs. PCR 4 (boot-loader-code) matches event log and fully consists of recognized measurements. Including in set of PCRs. PCR 5 (boot-loader-config) matches event log and fully consists of recognized measurements. Including in set of PCRs. PCR 7 (secure-boot-policy) matches event log and fully consists of recognized measurements. Including in set of PCRs. PCR 9 (kernel-initrd) matches event log and fully consists of recognized measurements. Including in set of PCRs. No PCRs dropped from protection mask. PCRs in protection mask: 0 (platform-code), 4 (boot-loader-code), 5 (boot-loader-config), 7 (secure-boot-policy), 9 (kernel-initrd) Added prediction result 1 for PCR 0 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 2 for PCR 0 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 1 for PCR 4 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 2 for PCR 4 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 1 for PCR 5 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 2 for PCR 5 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@600-absent:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 3 for PCR 5 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 4 for PCR 5 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@600-0xffffffff:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@600-absent:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 1 for PCR 7 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 2 for PCR 7 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@600-0xffffffff:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 1 for PCR 9 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-1:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 2 for PCR 9 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-2:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Added prediction result 3 for PCR 9 (path: 240-secureboot-policy@generated:250-firmware-code-early@generated:250-firmware-config-early@generated:350-action-efi-application:400-secureboot-separator@300-0x00000000:500-separator@300-0x00000000:550-firmware-code-late@generated:550-firmware-config-late@generated:600-gpt@generated:620-secureboot-authority@generated:630-shim-efi-application@generated:640-boot-loader-efi-application@generated:641-sdboot-loader-conf:650-kernel-efi-application@linux-1:700-action-efi-exit-boot-services@300-present:710-kernel-cmdline-boot-loader@cmdline-1:710-kernel-cmdline-initrd-entry@cmdline-initrd-3:750-enter-initrd:800-leave-initrd:850-sysinit:900-ready) Predicted future PCRs in 1.979ms. [ { "pcr" : 0, "values" : [ "c1f2e40d330b6a6b982f00c5aa76ac32800a36f7afdb294bf34569f1433335bb", "42898f424c28badd6fe7cbeb49c107f80ac910760b69ed9b6bd32920a2a65b33" ] }, { "pcr" : 4, "values" : [ "2c8acbf406e4ea74fa014baf1180c8f28d7c60cb3a27265d274b027885cc2416", "27cbe31f31e033805684ec185def5e32b6d4cb08432d64f43a377bec0243cefb" ] }, { "pcr" : 5, "values" : [ "c0b661f390b58a95f7c0173ae70e0cccaa6917f6108de9542463c578cee1d203", "935075d2a20e8ddc861722f2bdc0de78aad8f306843f092910c6ed32dbe888e4", "072b91ff3de7696151dbb5584575e8ac348c670a34f271fb099f617c2afd4448", "0ed87e2ffb634d91b6e20da816eec3dd2284b8fe0035fde8531c3e96370a8f18" ] }, { "pcr" : 7, "values" : [ "22f5a51babd581abe57a405f84e41c8f3da14c41ab345f274ba406d998886962", "1a2deb2d5316c9093ef8a6f4e20dbac5e0be296eb0efe0be0a3e23e621157a3c" ] }, { "pcr" : 9, "values" : [ "d4d845f23d71324ec38766e1c19f2cfe2bd413ecf27ae3b0681a5aaab38d897f", "0d1b30845de98a7dd32201a94aad68f18a0665cd25cde2d599cccb0b363ee2b9", "433a0b89e7fcab6694c177acb686489bec81018e14fe4ce954d5438316603177" ] } ] Using TPM2 TCTI driver 'device' with device '/dev/tpmrm0'. Loaded 'libtss2-tcti-device.so.0' via dlopen() Loaded TCTI module 'tcti-device' (TCTI module for communication with Linux kernel interface.) [Version 2] TPM successfully started up. Getting TPM2 capability 0x0000 property 0x0001 count 127. Getting TPM2 capability 0x0002 property 0x011f count 256. Getting TPM2 capability 0x0008 property 0x0000 count 508. Getting TPM2 capability 0x0005 property 0x0000 count 1. Starting HMAC encryption session. Converting PIN into TPM2 HMAC-SHA256 object. Loading external key into TPM. Starting policy session. Submitting PolicySigned policy for HMAC-SHA256. Acquiring policy digest. Session policy digest: c3261b61d61ae9cebc2fbe4e64ab2548b58ef9dd3643d1cf172bd28a74132fd5 Calculating new PCR policy to write... PolicyPCR calculated digest: 6b4175491ce0b23cd5d93dbc3f3364768a64283951ae62610c56871f1843d8fd Calculated PCR policy variant 1 for PCR 0 PolicyPCR calculated digest: c2bb1c9990f5b7b6b8dfb343b21b2d532e20486b871387679b6f82ef6e5ea27e Calculated PCR policy variant 2 for PCR 0 OR Branch #0: 6b4175491ce0b23cd5d93dbc3f3364768a64283951ae62610c56871f1843d8fd OR Branch #1: c2bb1c9990f5b7b6b8dfb343b21b2d532e20486b871387679b6f82ef6e5ea27e PolicyOR calculated digest: cd5d6970e6b52fc15ab5d3b9ce978cd2848198ac7d1f902dd9b660f13d58ff8f Combined 2 variants in OR policy. PolicyPCR calculated digest: 32aced0716b3b3a9385be277f969bfb6dd7d683ed1a881212d736bd2ecc08701 Calculated PCR policy variant 1 for PCR 4 PolicyPCR calculated digest: c07fdb3efd446bff0d2fa4c59e78da8bf66437052b487e22df015363827fd844 Calculated PCR policy variant 2 for PCR 4 OR Branch #0: 32aced0716b3b3a9385be277f969bfb6dd7d683ed1a881212d736bd2ecc08701 OR Branch #1: c07fdb3efd446bff0d2fa4c59e78da8bf66437052b487e22df015363827fd844 PolicyOR calculated digest: e5806d8dfbfd4b188b458fa271d2e75490cc659684f238d02b56d1680597eb57 Combined 2 variants in OR policy. PolicyPCR calculated digest: 8cc15772306c7d06c4d1638458d0561318f1b80f3f97b812d401ee45356f3883 Calculated PCR policy variant 1 for PCR 5 PolicyPCR calculated digest: c6c8983c5b6bd48524cc0b84b1d3529ddbb7ddafc439f605e2d1adb296017485 Calculated PCR policy variant 2 for PCR 5 PolicyPCR calculated digest: ad2f61d1f30b27bc2d2139f01a144108ab0b31c2837f18736581d04d1c68d33f Calculated PCR policy variant 3 for PCR 5 PolicyPCR calculated digest: 30f63fb7db60131c9ca62bac1af4269f6947a506a940975b93110ddccdd9099c Calculated PCR policy variant 4 for PCR 5 OR Branch #0: 8cc15772306c7d06c4d1638458d0561318f1b80f3f97b812d401ee45356f3883 OR Branch #1: c6c8983c5b6bd48524cc0b84b1d3529ddbb7ddafc439f605e2d1adb296017485 OR Branch #2: ad2f61d1f30b27bc2d2139f01a144108ab0b31c2837f18736581d04d1c68d33f OR Branch #3: 30f63fb7db60131c9ca62bac1af4269f6947a506a940975b93110ddccdd9099c PolicyOR calculated digest: ed8533e59387bea4f6dfadbfac6e7bc6d43d696be8329ab21a1af31bc16266c5 Combined 4 variants in OR policy. PolicyPCR calculated digest: 62f42e42a8b2bcf3e5b50071e7003f3e84923c77c27e0ba2fee00f80ac636279 Calculated PCR policy variant 1 for PCR 7 PolicyPCR calculated digest: 838e0466d318fae0f4a380d3c50131ad787a608d7a0d87ef1b2a325137121a0e Calculated PCR policy variant 2 for PCR 7 OR Branch #0: 62f42e42a8b2bcf3e5b50071e7003f3e84923c77c27e0ba2fee00f80ac636279 OR Branch #1: 838e0466d318fae0f4a380d3c50131ad787a608d7a0d87ef1b2a325137121a0e PolicyOR calculated digest: 80fc0a160542eac4c8364982675e3e1e6d1f89cf31f61c9e5907f99a753e4f87 Combined 2 variants in OR policy. PolicyPCR calculated digest: 7911cd4e5ff5175d18b57643a3576932a237abd97f5240f2c7318b8586775c53 Calculated PCR policy variant 1 for PCR 9 PolicyPCR calculated digest: 9d69423bfe4901d61f0792e69e2da706b22c8a80d4289abd8d592774c11565d9 Calculated PCR policy variant 2 for PCR 9 PolicyPCR calculated digest: ce0d60c2d319db72aecc881eb8d42d6dc17beca8394af8a832d6a0f297604db1 Calculated PCR policy variant 3 for PCR 9 OR Branch #0: 7911cd4e5ff5175d18b57643a3576932a237abd97f5240f2c7318b8586775c53 OR Branch #1: 9d69423bfe4901d61f0792e69e2da706b22c8a80d4289abd8d592774c11565d9 OR Branch #2: ce0d60c2d319db72aecc881eb8d42d6dc17beca8394af8a832d6a0f297604db1 PolicyOR calculated digest: a95db79012016c57c33f257e0fd02d1da8862c6740bcfa599c5145819e374d24 Combined 3 variants in OR policy. Calculated new PCR policy in 526us. Writing new PCR policy to NV index... WARNING:esys:src/tss2-esys/api/Esys_NV_Write.c:310:Esys_NV_Write_Finish() Received TPM Error ERROR:esys:src/tss2-esys/api/Esys_NV_Write.c:110:Esys_NV_Write() Esys Finish ErrorCode (0x0000099d) Failed to write NV index: tpm:session(1):a policy check failed Failed to write to NV index: State not recoverable Error creating the policy! Provided PIN incorrect or TPM2 locked after too many retries NVIndex policy created -- You are receiving this mail because: You are on the CC list for the bug.
https://bugzilla.suse.com/show_bug.cgi?id=1229048 https://bugzilla.suse.com/show_bug.cgi?id=1229048#c1 --- Comment #1 from Ben Li <vandeft@gmail.com> --- I think this issue might be a duplicate of 1228863. https://bugzilla.opensuse.org/show_bug.cgi?id=1228863 I think I may have needed to re-enroll the encryption key to the TPM. -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com