canonical / canonical/secboot

Ubuntu 26.04 - Hardware-backed encryption could not be enabled

Open
#540 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
23
Forks
29
Avg merge
2d 8h
Merged PRs (30d)
2

Description

ThinkPad X1 Carbon 8th Gen — TPM‑FDE Fails During Ubuntu Installation

When selecting tpm-fde in the Ubuntu installer, the process fails with the following message:

Hardware-backed encryption could not be enabled.
This computer does not have the required security hardware (TPM 2.0)
for this encryption method.
Contact IT support.

Technical details:
NO_SUITABLE_TPM2_DEVICE
Error with TPM2 device: cannot check TPM discreteness using Intel BootGuard status:
no TPM2 device is available.

I have a discrete TPM, and TPM‑FDE worked perfectly on previous Ubuntu 24.04 releases.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.