[Bug 1969375] [NEW] systemd-cryptenroll does not support TPM2 devices

2022-04-18 Thread Dean Huffman
Public bug reported: systemd-cryptenroll can make use of tpm2 modules to bind against secure boot pcrs and enable auto unlocking of luks devices. Following the instructions here: https://wiki.archlinux.org/title/Trusted_Platform_Module#systemd-cryptenroll the following commands fail on ubuntu ja

[Bug 1961758] Re: Fail to run tpm2 command under ubuntu server 22.04

2022-03-01 Thread Dean Huffman
I can confirm the following steps work on 21.10 fresh install to enroll a TPM2.0 for use with a LUKS encrypted partition but do not work on 22.04. apt install clevis clevis-tpm2 clevis-luks clevis-udisks2 clevis-systemd clevis-initramfs udevadm trigger clevis luks bind -d /dev/sda3 tpm2 '{"pcr_ba