canonical / canonical/secboot

TPM backed encryption on Dell Precision 5490 results in asking for Recovery Key endlessly.

Open
#542 5 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
23
Forks
29
Avg merge
2d 8h
Merged PRs (30d)
2

Description

There are a number of issues here. The primary one being that im asked for the recovery key after installing ubuntu 26.04 LTS.
The other issue is it seems to initiatite a reboot after some time on the recovery key screen. This would be impossible for a person with a disability to enter before the boot happens. My suggestion is drop the restarte on this screen completely and figure out whats wrong with the PCRs. I havent been able to find the specific details.

This happens consistently after numerous rounds of:
- Verifying secure boot is enabled
- Clearing the TPM
- Installing Ubuntut 26.04 LTS and enabling hardware backed (TPM) encryption.

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the issue on the Dell Precision 5490 using the listed secure-boot, TPM-clearing, and Ubuntu installation steps. Investigate the PCR state during the recovery-key prompt and the subsequent reboot behavior; done means identifying the cause and preventing the endless prompt and inaccessible timed restart.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, linux, ubuntu
Domain
cryptography, operating-systems, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.