System boot or manual encryption load/disable fails to read TMP key
vyos@VyOS-for-Smoke-Tests:~$ encryption load TPM key invalid or not found, recovery key required Enter recovery key:
Steps to reproduce:
- encryption enable
- reboot
During system boot the config load error appears 'TPM key invalid or not found', system config can decrypted only using recovery key.
Version: VyOS 1.5.0 Release train: circinus Release flavor: exoscale Built by: VyOS Inc. Built on: Thu 26 Mar 2026 00:20 UTC Build UUID: 92abd7d7-8d48-4505-b936-f9184458e7b4 Build commit ID: d4b1eacce19987 Architecture: x86_64 Boot via: installed image System type: KVM guest Hardware vendor: Exoscale Hardware model: Exoscale Compute Platform Hardware S/N: Hardware UUID: 188af269-a3d2-4e69-8522-2982cf5fdfe4
UPD:
Apparently on Exoscale PCR #2 value gets changed during the first reboot and remains constant across further reboots.
So if the system is encrypted during initial boot then unseal fails as pcr values don't match anymore.
Re-encrypt solves the issue as PCR #2 remains unchanged during further reboots
Before the first reboot:
vyos@VyOS-for-Smoke-Tests:~$ sudo tpm2_pcrread sha256:0,2,4,7
sha256:
0 : 0xE21B703EE69C77476BCCB43EC0336A9A1B2914B378944F7B00A10214CA8FEA93
2 : 0x7BB0F94F8072FA80AB818DC90D800BBBB83443B3F498FD17041D4CFCB32C58D0
4 : 0xA396AFC7B063562EC1F12225DD191BC80235B6566AE1966657D91CFA4E4E54BD
7 : 0xE21B703EE69C77476BCCB43EC0336A9A1B2914B378944F7B00A10214CA8FEA93After:
vyos@VyOS-for-Smoke-Tests:~$ sudo tpm2_pcrread sha256:0,2,4,7
sha256:
0 : 0xE21B703EE69C77476BCCB43EC0336A9A1B2914B378944F7B00A10214CA8FEA93
2 : 0x1026D8A10D1EAEA6155D0A070B3BB9412B4FC1CB61590E57E9E52ACF93646653
4 : 0xA396AFC7B063562EC1F12225DD191BC80235B6566AE1966657D91CFA4E4E54BD
7 : 0xE21B703EE69C77476BCCB43EC0336A9A1B2914B378944F7B00A10214CA8FEA93//test edit