1. Still can reproduce the issue (#31) after deleting PK and enrolling db/KEK/custom PK vis BIOS settings.
For details, please refer to #38 and [1].
2. Can install the uc20 test image[2][3] with TPM and secure boot enabled on other x86 machines (not TGL-H and EHL).
And, I only enrolled KEK and DB via BIOS settings.
For details, please refer to #36
3. When I enroll the key by mokutil, the error message is different from #31.
For details, please refer to #39.
@Chris
Any thoughts on this?
Based on above test results, it looks like #31 is a BIOS issue?
Summary:
1. Still can reproduce the issue (#31) after deleting PK and enrolling db/KEK/custom PK vis BIOS settings.
For details, please refer to #38 and [1].
2. Can install the uc20 test image[2][3] with TPM and secure boot enabled on other x86 machines (not TGL-H and EHL).
And, I only enrolled KEK and DB via BIOS settings.
For details, please refer to #36
3. When I enroll the key by mokutil, the error message is different from #31.
For details, please refer to #39.
@Chris
Any thoughts on this?
Based on above test results, it looks like #31 is a BIOS issue?
--- /bugs.launchpad .net/intel/ +bug/1939505/ comments/ 3 /github. com/EthanHsieh/ secboot/ commit/ f1b9e1593b2a952 be77b63f8b31cc3 787b1e3e0d /github. com/EthanHsieh/ go-tpm2/ commit/ b5a8526eb240268 9024c0deeba7787 33036a3084
[1] https:/
[2] https:/
[3] https:/