diff options
author | Lennart Poettering <lennart@poettering.net> | 2022-03-16 22:32:43 +0100 |
---|---|---|
committer | GitHub <noreply@github.com> | 2022-03-16 22:32:43 +0100 |
commit | e127ac90efe209a9e84ffad0ec4aa7e1ed389c71 (patch) | |
tree | a6ada8e72e699fa434f4c98e28f9dbb51753db1a /NEWS | |
parent | 06fb09cf40e75b04e75ea502ddeee96ca29269fc (diff) | |
parent | bbfabc449831d0b1aa80eeeda1a9569f331394b7 (diff) | |
download | systemd-e127ac90efe209a9e84ffad0ec4aa7e1ed389c71.tar.gz |
Merge pull request #22761 from poettering/pcr-fix
sd-boot: change kernel cmdline PCR from 8 to 12
Diffstat (limited to 'NEWS')
-rw-r--r-- | NEWS | 13 |
1 files changed, 13 insertions, 0 deletions
@@ -120,6 +120,19 @@ CHANGES WITH 251: 250. For newer kernels, non-x86 systems, or older x86 systems, there should be no visible changes. + * sd-boot will now measure the kernel command line into TPM PCR 12 + rather than PCR 8. This improves usefulness of the measurements on + sytems where sd-boot is chainloaded from Grub. Grub measures all + commands its executes into PCR 8, which makes it very hard to use + reasonably, hence separate ourselves from that and use PCR 12 + instead, which is already what certain Ubuntu editions use it for. To + retain compatibility with systems running older systemd systems a new + Meson option 'efi-tpm-pcr-compat' has been added (which defaults to + false). If enabled, the measurement is done twice: into the new-style + PCR 12 *and* the old-style PCR 8. It's strongly advised to migrate + all users to PCR 12 for this purpose in the long run, as we intend to + remove this compatibility feature again in two year's time. + CHANGES WITH 250: * Support for encrypted and authenticated credentials has been added. |