Starting with package version `42-1`, the mkinitcpio systemd hook now includes `systemd-pcrosseparator.service` (as [intended by systemd v261]). This affects the measurements of PCR values `0-7`, `9` and `12-14`. If you configured the systemd hook and unlock LUKS partitions, that depend on these values, you need to re-enroll the [TPM2] in use. For guidance, please refer to [systemd-cryptenroll(1)], or the [ArchWiki article on systemd-cryptenroll], when using pinned values. Refer to [systemd-pcrlock(8)], when relying on custom policies and a disabled `systemd-pcrlock-make-policy.service`. [ArchWiki article on systemd-cryptenroll]: https://wiki.archlinux.org/title/Systemd-cryptenroll [TPM2]: https://wiki.archlinux.org/title/Trusted_Platform_Module [intended by systemd v261]: https://github.com/systemd/systemd/blob/1f9d56a7ab1d814044ac02939b42fd0efb99a8ab/NEWS#L69 [systemd-cryptenroll(1)]: https://man.archlinux.org/man/systemd-cryptenroll.1 [systemd-pcrlock(8)]: https://man.archlinux.org/man/core/systemd/systemd-pcrlock.8 URL: https://archlinux.org/news/mkinitcpio-42-requires-manual-intervention-for-tpm2-based-unlocking-of-luks-devices/
No comments:
Post a Comment