Cannot boot on 24.04 with TPM encryption

Bug #2058147 reported by Alexander Koskovich
96
This bug affects 16 people
Affects Status Importance Assigned to Milestone
subiquity
New
Undecided
Unassigned
ubuntu-desktop-provision
Confirmed
Undecided
Unassigned

Bug Description

I installed the daily 24.04 ISO to a spare SSD with TPM encryption, and on first boot it asks me for the recovery password. This also happens on 23.10 with ubuntu-desktop-installer.

Secure Boot is enabled in BIOS and TPM was cleared prior to installation (to get rid of the DA lockout mode error).

Hardware:
AMD Ryzen 9 7950X
ASUS X670E Crosshair Hero
96GB DDR5
RX 7900 XTX

Tags: noble
Paul White (paulw2u)
affects: ubuntu → ubuntu-desktop-installer
affects: ubuntu-desktop-installer → ubuntu-desktop-provision
description: updated
description: updated
Revision history for this message
Alexander Koskovich (nexusprism) wrote (last edit ):

Tested on a Maingear Vector Pro 2 I have, it is able to boot fine on the first boot but after updating and rebooting, it prompts for the recovery password again.

Tested on the Dell XPS 9530 15" and it has the same issue as my desktop where it immediately asks for recovery password on first boot.

Revision history for this message
Alexander Koskovich (nexusprism) wrote (last edit ):
Revision history for this message
Alexander Koskovich (nexusprism) wrote :

Also this is still happening on the daily image released today for 24.04.

Revision history for this message
NIck Amato (namato01) wrote :

Also still seeing this on the daily build 4/8 and 4/9.

Revision history for this message
Dan Bungert (dbungert) wrote :

Thanks for the report.
We need a capture of the logs from /var/log/installer to debug.

Changed in subiquity:
status: New → Incomplete
Revision history for this message
Alexander Koskovich (nexusprism) wrote :
Changed in ubuntu-desktop-provision:
status: New → Confirmed
Dan Bungert (dbungert)
Changed in subiquity:
status: Incomplete → New
Revision history for this message
Sami Piispanen (hienohelma) wrote :

I have this exact issue with a Lenovo Yoga 9 laptop. It seems that the TPM goes in DA lockout mode on nearly every boot as I have always had to clear it manually before being able to install Ubuntu with TPM encryption. Lenovo's BIOS does not have any meaningful settings regarding TPM and TPM works as it should in Windows. It would be nice to be able to check the recovery password during the installation process as it is now possible to end up in a state where Ubuntu is permanently unbootable immediately after installation.

Revision history for this message
WT (wctsai) wrote :
Revision history for this message
Bartosz Woronicz (mastier1) wrote :

Same on my Lenovo T14 gen 4 AMD

I attached sosreport from liveiso

Revision history for this message
Bartosz Woronicz (mastier1) wrote :

Also var log from the /target OS

Revision history for this message
Bartosz Woronicz (mastier1) wrote :

Seems I found workaround/solution for that. I needed to disable Absolute Persistence Module Activation in the EUFI config. See the screenshot.

After that previously install TPM based installation started to working.

Revision history for this message
Aaron Roller (aroller) wrote :

I am blocked on using "Hardware Backed Encryption" installation procedure also. The repeatable experience is described best in the duplicate https://bugs.launchpad.net/ubuntu-desktop-provision/+bug/2063963

I have a Lenovo Thinkpad P1Gen6 with BIOS Version N3ZET41W (1.28). I upgraded from BIOS 1.16 which had the same problem.

Also worth noting when connected to the internet, the installer is updated to the latest with no effect.

I've disabled Absolute Persistence Module Activation without effect.

I'm using image: ubuntu-24.04-desktop-amd64.iso 2024-04-24 11:29

Revision history for this message
Alexander Koskovich (nexusprism) wrote :

I retested again today on the ASUS ROG X670E Crosshair after updating BIOS to 2120 (Beta) which primarily updates AGESA firmware to 1.2.0.0, and TPM encryption works now!

Not sure if this was an AMD or ASUS specific issue but it's resolved now at least on my hardware.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.