Open dankcatlord opened 1 year ago
I'm pretty sure the PCRs are only written if measured boot is enabled, which it is not currently.
Ah ok, is measured boot planned to be enabled in the future?
wasn't planning on it, but I can do so on a test build and see if that resolves the issue for you. shoot me an email or msg on Discord
PCRs can’t be written by edk2 on Bluebird because there’s no CR50 driver
PCRs can’t be written by edk2 on Bluebird because there’s no CR50 driver
The full uefi image test build with measured boot enabled fills in PCR 2 of the sha256 bank with data but none of the other PCRs. AFAIK from looking at the MrChromebox/coreboot repo, there is some support for CR50 in version 4.20.0 looking at the commits.
When I run tpm2_pcrread, PCRs 0-7 isnt being set by the firmware. I'm running ArchLinux on a Samsung Chromebook 4+ (CASTA) with the 4.20.0 firmware. This issue prevents me from sealing keys in my TPM securely. I think the firmware might not be initializing the TPM on startup.