systemd-tpm2-setup.service - Man Page

Set up the TPM2 Storage Root Key (SRK), Endorsement Key (EK), and initialize NvPCRs at boot

Synopsis

systemd-tpm2-setup​.service

/usr/lib/systemd/systemd-tpm2-setup

Description

systemd-tpm2-setup​.service and systemd-tpm2-setup-early​.service are services that generate the Storage Root Key (SRK) and Endorsement Key (EK) if they have not been generated yet, and stores them in the TPM​. If NvPCRs (additional PCR registers in TPM NV Indexes) are defined, these are initialized with the anchoring secret​.

The services will store the public key of the SRK key pair in a PEM file in /run/systemd/tpm2-srk-public-key​.pem and /var/lib/systemd/tpm2-srk-public-key​.pem​. They will also store it in TPM2B_PUBLIC format in /run/systemd/tpm2-srk-public-key​.tpm2_public and /var/lib/systemd/tpm2-srk-public-key​.tpm2b_public​.

systemd-tpm2-setup-early​.service runs very early at boot (possibly in the initrd), and writes the SRK public key to /run/systemd/tpm2-srk-public-key​.* (as /var/ is generally not accessible this early yet), while systemd-tpm2-setup​.service runs during a later boot phase and saves the public key to /var/lib/systemd/tpm2-srk-public-key​.*​.

Files

/run/systemd/tpm2-srk-public-key​.pem, /run/systemd/tpm2-srk-public-key​.tpm2b_public

The SRK public key in PEM and TPM2B_PUBLIC format, written during early boot​.

Added in version 255​.

/var/lib/systemd/tpm2-srk-public-key​.pem, /var/lib/systemd/tpm2-srk-public-key​.tpm2_public

The SRK public key in PEM and TPM2B_PUBLIC format, written during later boot (once /var/ is available)​.

Added in version 255​.

/usr/lib/nvpcr/*​.nvpcr

Definition files for NvPCRs​.

Added in version 259​.

See Also

systemd(1)

Referenced By

systemd-cryptenroll(1), systemd.directives(7), systemd.index(7), systemd-tpm2-clear.service(8), ukify(1).

The man pages systemd-tpm2-setup(8) and systemd-tpm2-setup-early.service(8) are aliases of systemd-tpm2-setup.service(8).

systemd 262~rc2