From ab7e55f19547fb04662d4330d00ae72044634acf Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Thu, 26 Jun 2025 12:16:59 +0200 Subject: [PATCH 1/2] docs/TPM2_PCR_MEASUREMENTS: link to the PCR registry page --- docs/TPM2_PCR_MEASUREMENTS.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/docs/TPM2_PCR_MEASUREMENTS.md b/docs/TPM2_PCR_MEASUREMENTS.md index 2931c22be8..b7f0b09771 100644 --- a/docs/TPM2_PCR_MEASUREMENTS.md +++ b/docs/TPM2_PCR_MEASUREMENTS.md @@ -16,6 +16,10 @@ measurements listed below are (by default) only done if a system is booted with to systemd's UEFI-mode measurements, and if the latter are not done the former aren't made either. +See +[Linux TPM PCR Registry](https://uapi-group.org/specifications/specs/linux_tpm_pcr_registry/) +for an overview of PCRs. + systemd will measure to PCRs 5 (`boot-loader-config`), 11 (`kernel-boot`), 12 (`kernel-config`), 13 (`sysexts`), 15 (`system-identity`). From 85b84437c854b963d1dfe1dd2405ee90a74d2df5 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zbigniew=20J=C4=99drzejewski-Szmek?= Date: Thu, 26 Jun 2025 12:25:30 +0200 Subject: [PATCH 2/2] docs/TPM2_PCR_MEASUREMENTS: fix typo --- docs/TPM2_PCR_MEASUREMENTS.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/TPM2_PCR_MEASUREMENTS.md b/docs/TPM2_PCR_MEASUREMENTS.md index b7f0b09771..c6164b76d2 100644 --- a/docs/TPM2_PCR_MEASUREMENTS.md +++ b/docs/TPM2_PCR_MEASUREMENTS.md @@ -45,7 +45,7 @@ used for new, additional measurements. ## PCR Measurements Made by `systemd-boot` (UEFI) -### PCS 5, `EV_EVENT_TAG`, `loader.conf` +### PCR 5, `EV_EVENT_TAG`, `loader.conf` The content of `systemd-boot`'s configuration file, `loader/loader.conf`, is measured as a tagged event.