Skip to content

tpm-pcr-registry: document systemd extending PCR 7 with leave-initrd#209

Open
src-up wants to merge 1 commit intouapi-group:mainfrom
src-up:pcr7-leave-initrd
Open

tpm-pcr-registry: document systemd extending PCR 7 with leave-initrd#209
src-up wants to merge 1 commit intouapi-group:mainfrom
src-up:pcr7-leave-initrd

Conversation

@src-up
Copy link

@src-up src-up commented Mar 3, 2026

PCR7 is only extended on leave-initrd, so it differs in the main
OS. This enables distinguishing initrd vs OS when sealing keys to PCR7
(e.g. for systemd-repart-created volumes).

Since systemd/systemd#40914

…barrier

Since systemd/systemd#40914

Do not extend PCR7 on enter-initrd, so PCR7 in the initrd stays equal to
the firmware value and existing PCR7-only sealed disks still unseal
there.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant