Device security reports "checks failed" even achiving HSI:3

Bug #2039314 reported by Marcos Alano
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
gnome-control-center (Ubuntu)
Expired
Low
Unassigned

Bug Description

If I execute "fwupdmgr security", I get the information that my device complies with HSI:3, but even then the Privacy > Device Security on GNOME Control Center reports "Failed Checks".

Tags: bot-comment
Revision history for this message
Marcos Alano (mhalano) wrote :

This is the exit of the command. SecureBoot isn't actived, but the checks are valid if "Runtime Suffix" verifications are true?

➜ fwupdmgr security
Host Security ID: HSI:3! (v1.9.5)

HSI-1
✔ MEI key manifest: Valid
✔ Platform debugging: Disabled
✔ SPI BIOS region: Locked
✔ SPI lock: Enabled
✔ SPI write: Disabled
✔ Supported CPU: Valid
✔ TPM empty PCRs: Valid
✔ TPM v2.0: Found
✔ UEFI bootservice variables: Locked
✔ csme manufacturing mode: Locked
✔ csme override: Locked
✔ csme v0:15.0.45.2411: Valid

HSI-2
✔ BIOS rollback protection: Enabled
✔ IOMMU: Enabled
✔ Intel BootGuard: Enabled
✔ Intel BootGuard ACM protected: Valid
✔ Intel BootGuard OTP fuse: Valid
✔ Intel BootGuard verified boot: Valid
✔ Intel GDS mitigation: Enabled
✔ Platform debugging: Locked
✔ TPM PCR0 reconstruction: Valid

HSI-3
✔ Intel BootGuard error policy: Valid
✔ Intel CET Enabled: Enabled
✔ Pre-boot DMA protection: Enabled
✔ Suspend-to-idle: Enabled
✔ Suspend-to-ram: Disabled

HSI-4
✔ Intel SMAP: Enabled
✘ Encrypted RAM: Not supported

Runtime Suffix -!
✔ Intel CET Active: Not supported
✔ Linux swap: Disabled
✔ fwupd plugins: Untainted
✘ Linux kernel: Tainted
✘ Linux kernel lockdown: Disabled
✘ UEFI secure boot: Disabled

This system has HSI runtime issues.
 » https://fwupd.github.io/hsi.html#hsi-runtime-suffix

Host Security Events
  2023-09-16 22:51:13: ✔ Pre-boot DMA protection is enabled
  2023-09-13 18:20:16: ✘ Secure Boot disabled
  2023-09-13 18:20:16: ✘ Pre-boot DMA protection is disabled
  2023-09-13 12:27:38: ✔ TPM v2.0 changed: Not found → Found
  2023-09-13 12:11:31: ✘ TPM v2.0 changed: Found → Not found
  2023-09-11 13:40:01: ✘ Kernel lockdown disabled
  2023-09-11 13:40:01: ✔ TPM v2.0 changed: Not found → Found
  2023-09-11 13:31:29: ✘ Kernel is tainted
  2023-09-11 13:12:55: ✔ Kernel is no longer tainted
  2023-09-11 13:12:55: ✔ Kernel lockdown enabled
  2023-09-11 13:12:55: ✔ Secure Boot enabled
  2023-09-11 03:02:26: ✘ TPM v2.0 changed: Found → Not found
  2023-09-11 03:00:59: ✔ TPM v2.0 changed: Not found → Found

Revision history for this message
Ubuntu Foundations Team Bug Bot (crichton) wrote :

Thank you for taking the time to report this bug and helping to make Ubuntu better. It seems that your bug report is not filed about a specific source package though, rather it is just filed against Ubuntu in general. It is important that bug reports be filed about source packages so that people interested in the package can find the bugs about it. You can find some hints about determining what package your bug might be about at https://wiki.ubuntu.com/Bugs/FindRightPackage. You might also ask for help in the #ubuntu-bugs irc channel on Libera.chat.

To change the source package that this bug is filed about visit https://bugs.launchpad.net/ubuntu/+bug/2039314/+editstatus and add the package name in the text box next to the word Package.

[This is an automated message. I apologize if it reached you inappropriately; please just reply to this message indicating so.]

tags: added: bot-comment
Marcos Alano (mhalano)
affects: ubuntu → gnome-control-center (Ubuntu)
Revision history for this message
Sebastien Bacher (seb128) wrote :

Thank you for your bug report. Which version of Ubuntu are you using?

Changed in gnome-control-center (Ubuntu):
importance: Undecided → Low
status: New → Incomplete
Revision history for this message
Marcos Alano (mhalano) wrote :

Ubuntu 23.10.

➜ dpkg -l |grep gnome-control-center
ii gnome-control-center 1:45.0-1ubuntu3 amd64 utilities to configure the GNOME desktop
ii gnome-control-center-data 1:45.0-1ubuntu3 all configuration applets for GNOME - data files
ii gnome-control-center-faces 1:45.0-1ubuntu3 all utilities to configure the GNOME desktop - faces images

Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for gnome-control-center (Ubuntu) because there has been no activity for 60 days.]

Changed in gnome-control-center (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.