canonical / canonical/secboot

Unable to enable TPM FDE in installer - Ubuntu 26.04 LTS

Open
#543 7 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
23
Forks
29
Avg merge
2d 8h
Merged PRs (30d)
2

Description

Heyo 👋🏻

Yesterday I did a clean build on my desktop machine, and where in a previous release this worked, I was unable to get the UEFI into a state where the installer would let me use TPM FDE.

I reset the TPM, restored factory keys and otherwise tried all combos I could, but kept getting the error:

"INVALID_SECURE_BOOT_MODE" and "error with secure boot policy (PCR7) measurements, deployed mode should be enabled in order to generate secure boot profiles"

The motherboard is an MSI MPG CARBON X670E - so relatively recent.

Contributor guide

Open the contributing guide

Research direction

No file or test is named. Start by reproducing the TPM FDE installer failure on the reported MSI MPG CARBON X670E with Ubuntu 26.04 LTS, then trace handling of INVALID_SECURE_BOOT_MODE and PCR7 secure-boot policy measurements. Done means the cause is confirmed and TPM FDE can be enabled in the affected setup.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, ubuntu
Domain
operating-systems, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
42/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.