linuxboot / linuxboot/heads

can't sign multiple OSes with LUKS (0x45 from TPM_IncrementCounter)

Open
#1,531 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Makefile
Stars
1.6k
Forks
211
Avg merge
4d 21h
Merged PRs (30d)
6

Description

Qubes 4.2.0-rc4 LUKS (/dev/nvme*)
Ubuntu 23.10 LUKS (/dev/sda*)
third disk drive - /dev/mmcblk0 - empty

FW_VER - CBET4000 Heads-v0.2.0-1914-g1f39d16-dirty
X230-maximized-eDP
gpg smart card : Nitrokey start

here steps what i do :

1. OEM Factory Reset / Re-Ownershp
2. Qubes signed /boot normally and works
3. Go to -> Change configurations settings -> Change boot device -> /dev/sda2
4. Default boot -> Yes -> Failed update checksums /sign and TPM want to reset himself.
5. Reset and goto step 1. Loop.

The same thing happens in reverse order. Ubuntu sign first, then Qubes won't.

In previous firmware I remember that it worked fine but Qubes + Void

![heads](https://github.com/linuxboot/heads/assets/106248555/6f60d4be-8263-41ae-9ccf-67841780d20d)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the reported loop by signing the Qubes and Ubuntu LUKS installations in both orders, following the listed boot-device and OEM reset steps. Start by investigating the TPM_IncrementCounter 0x45 failure during checksum/signing; done means multiple LUKS installations can be signed without the TPM requesting another reset.

Written by the indexing model from the issue text.

Assessment

Tech stack
linux, ubuntu
Domain
operating-systems, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.