canonical / canonical/secboot

Unable to encrypt due to PCR4 measurement error

Open
#456 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
23
Forks
29
Avg merge
2d 8h
Merged PRs (30d)
2

Description

Image

When booting the questing-desktop-amd64.iso (md5sum: a34d4a7677f882e8304b40ca81ba89f7) via a Ventoy bootable USB, the option to encrypt using TPM-FDE is greyed out with the above error.
The same ISO written directly to the USB works just fine and the option is available.

If I understand the error message correctly, this is because PCR 4 is measured using the Ventoy bootloader, which does not match the Ubuntu EFI bootloader included in the ISO (`/cdrom/EFI/boot/bootx64.efi`).

This seems like the correct behaviour, but I thought I should raise it anyway just in case it's not expected. I hadn't seen any reports of the same.

Contributor guide

Open the contributing guide

Research direction

Reproduce the issue by booting questing-desktop-amd64.iso from Ventoy and compare it with an ISO written directly to USB. Check the PCR4 measurement against /cdrom/EFI/boot/bootx64.efi and determine whether the TPM-FDE option being unavailable is expected; done means documenting the confirmed behavior or identifying a concrete correction.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, linux, ubuntu
Domain
operating-systems, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.