canonical / canonical/secboot

SHA-1 TPMs not supported with 26.04

Open
#547 6 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
23
Forks
29
Avg merge
2d 8h
Merged PRs (30d)
2

Description

Hello! I have a quite old but capable machine where I don't have never firmware for my bios by now and the tpm chip only returns SHA-1 which I've found that for some reason it gives

```
MEASURED_BOOT
error with or detected from measurement log: invalid log spec

```
Is there any possible way to fix this?

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the MEASURED_BOOT failure on a machine whose TPM returns only SHA-1, then trace the measurement-log handling that reports “invalid log spec.” Determine whether SHA-1 logs should be supported or rejected, and consider the work complete when the behavior is covered by a reproducible test or the limitation is clearly established.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.