Poettering: Brave new trusted boot world
Poettering: Brave new trusted boot world
Posted Sep 30, 2023 17:32 UTC (Sat) by kreijack (guest, #43513)In reply to: Poettering: Brave new trusted boot world by dtlin
Parent article: Poettering: Brave new trusted boot world
My understanding is: that the PCR11 starts from 0 and it seems to be updated only by sb-boot. So starting a system without sd-boot is enough to allow an user to set it to an arbitrary value.
$ sudo tpm2_pcrread | egrep 11:
11: 0x0000000000000000000000000000000000000000
11: 0x0000000000000000000000000000000000000000000000000000000000000000
11: 0x000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
11: 0x00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
