Skip to content

Unable to encrypt due to PCR4 measurement error #456

@jamesps-ebi

Description

@jamesps-ebi
Image

When booting the questing-desktop-amd64.iso (md5sum: a34d4a7677f882e8304b40ca81ba89f7) via a Ventoy bootable USB, the option to encrypt using TPM-FDE is greyed out with the above error.
The same ISO written directly to the USB works just fine and the option is available.

If I understand the error message correctly, this is because PCR 4 is measured using the Ventoy bootloader, which does not match the Ubuntu EFI bootloader included in the ISO (/cdrom/EFI/boot/bootx64.efi).

This seems like the correct behaviour, but I thought I should raise it anyway just in case it's not expected. I hadn't seen any reports of the same.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions