tpm2-setup: measure "anchor" extension early at boot into nvpcrs

This commit is contained in:
Lennart Poettering
2024-06-04 18:16:03 +02:00
parent 2da86d62ff
commit 8a6e77f1a8
3 changed files with 142 additions and 5 deletions

View File

@@ -14,7 +14,7 @@ DefaultDependencies=no
Conflicts=shutdown.target
After=tpm2.target systemd-tpm2-setup-early.service systemd-remount-fs.service
Before=sysinit.target shutdown.target
RequiresMountsFor=/var/lib/systemd/tpm2-srk-public-key.pem
RequiresMountsFor=/var/lib/systemd
ConditionSecurity=measured-uki
ConditionPathExists=!/etc/initrd-release