Open
Conversation
… incorrect, now getting it right from the ouptut of tpm2_evictcontrol
…ted. Removed tpm2keyunlock service, user needs to enable secure boot before executing tpm2PolicyConfig
remove PCR8 (kernel cmdline?) because it was changing after seal
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
After struggling to understand what to do, and encountering some errors along the way, I've updated the instructions and scripts in the following ways:
tpm2PolicyConfig)scriptwith information regarding which password/passphrase is being requested (I didn't know, for instance, that one of the passwords I was entering was for the MOK Enrollment)tpm2PolicyConfigdirectly after conditions have been met. I could be wrong on this, but I had to do some work turning Secure Boot off for Step 1, then back on after Step 1 - but before Step 2. Also seemed to help with clarity about what was going on, and if it was successfulpersistent-handleright from the output oftpm2_evictcontrol(while still printing to the terminal), this fixes The correct reference isn't always the last one #8 (which I also encountered)