Pawit Pornkitprasan
1 min readAug 24, 2019

--

Check https://trustedcomputinggroup.org/wp-content/uploads/TCG_EFI_Platform_1_22_Final_-v15.pdf page 28–30. Particularly, the last paragraph of page 29 and the first paragraph of page 30.

The spec requires EFI_SIGNATURE_DATA used to verify the image to be measured in the PCR 7. Thus, all compliant firmwares must do it. Your firmware likely has a bug which causes the PCR 7 value to not be measured correctly.

In any case, I have added a warning to the post so that readers are aware of this potential issue.

--

--

Responses (1)