Skip to content

TPM PCR0 reconstruction fails with Boot Guard enabled #1476

@mkopec

Description

@mkopec

Component

Dasharo firmware

Device

NovaCustom V54 14th Gen

Dasharo version

v1.0.0-rc4

Dasharo Tools Suite version

n/a

Test case ID

No response

Brief summary

Running fwupdtool security on a btg-provisioned laptop results in a failure to reconstruct PCR0 merasurements:

HSI-2
✔ Intel BootGuard ACM protected: Valid
✔ Intel BootGuard:               Enabled
✔ IOMMU:                         Enabled
✔ Platform debugging:            Locked
✘ Intel BootGuard OTP fuse:      Invalid
✘ TPM PCR0 reconstruction:       Invalid

Context: #463 (comment)

How reproducible

No response

How to reproduce

Run fwupdtool security

Expected behavior

PCR0 reconstruction passes

Actual behavior

PCR0 reconstruction fails

Screenshots

No response

Additional context

No response

Solutions you've tried

No response

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions