Tried to install UC20 with TPM enabled and saw same error message[1] as
TGL-H.

EHL's BIOS doesn't support hash algorithm SHA384 and SM3_256.
For deails, please refer to attached photo.
BIOS version: EHLSFWI1.R00.3162.A01.2104131432

Here are steps:
1. Remove key enrolled by mokutil
2. Re-flash uc20 test image
3. Enroll KEK and Signature via BIOS settings:
[Boot Maintenance Manager Menu][Secure Boot Configuration Menu][Secure Boot 
Mode][Custom Mode][Custom Secure Boot Option]
[PK Options] => [Delete PK]
[PK Options] => [Enroll PK] => PkKek-1-snakeoil.der
[KEK Option][Enroll KEK] => PkKek-1-snakeoil.der
[DB Option][Enroll Signature] => PkKek-1-snakeoil.der
4. Clear TPM
[Intel Advanced Menu][TPM Configuration][TCG2 Configuration][TPM2 Operation]

---
[1] https://bugs.launchpad.net/intel/+bug/1938678/comments/31

** Attachment added: "PXL_20210820_073717729.MP.jpg"
   
https://bugs.launchpad.net/intel/+bug/1939505/+attachment/5519333/+files/PXL_20210820_073717729.MP.jpg

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1939505

Title:
  [ehl] Ubuntu Core boot fails on EHL

To manage notifications about this bug go to:
https://bugs.launchpad.net/intel/+bug/1939505/+subscriptions


-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to