2023-09-26 22:25:53 +03:00
<?xml version="1.0"?>
<!-- * - nxml - * -->
< !DOCTYPE refentry PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
2023-12-25 17:48:33 +03:00
"http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd">
2023-09-26 22:25:53 +03:00
<!-- SPDX - License - Identifier: LGPL - 2.1 - or - later -->
<refentry id= "systemd-tpm2-setup.service" conditional= 'ENABLE_BOOTLOADER'
xmlns:xi="http://www.w3.org/2001/XInclude">
<refentryinfo >
<title > systemd-tpm2-setup.service</title>
<productname > systemd</productname>
</refentryinfo>
<refmeta >
<refentrytitle > systemd-tpm2-setup.service</refentrytitle>
<manvolnum > 8</manvolnum>
</refmeta>
<refnamediv >
<refname > systemd-tpm2-setup.service</refname>
<refname > systemd-tpm2-setup-early.service</refname>
<refname > systemd-tpm2-setup</refname>
<refpurpose > Set up the TPM2 Storage Root Key (SRK) at boot</refpurpose>
</refnamediv>
<refsynopsisdiv >
<para > <filename > systemd-tpm2-setup.service</filename> </para>
<para > <filename > /usr/lib/systemd/systemd-tpm2-setup</filename> </para>
</refsynopsisdiv>
<refsect1 >
<title > Description</title>
<para > <filename > systemd-tpm2-setup.service</filename> and
<filename > systemd-tpm2-setup-early.service</filename> are services that generate the Storage Root Key
(SRK) if it hasn't been generated yet, and stores it in the TPM.</para>
<para > The services will store the public key of the SRK key pair in a PEM file in
<filename > /run/systemd/tpm2-srk-public-key.pem</filename> and
2024-02-29 05:46:25 +03:00
<filename > /var/lib/systemd/tpm2-srk-public-key.pem</filename> . They will also store it in TPM2B_PUBLIC
2023-11-09 00:24:33 +03:00
format in <filename > /run/systemd/tpm2-srk-public-key.tpm2_public</filename> and
<filename > /var/lib/systemd/tpm2-srk-public-key.tpm2b_public</filename> .</para>
2023-09-26 22:25:53 +03:00
<para > <filename > systemd-tpm2-setup-early.service</filename> runs very early at boot (possibly in the
2023-11-09 00:24:33 +03:00
initrd), and writes the SRK public key to <filename > /run/systemd/tpm2-srk-public-key.*</filename> (as
2023-09-26 22:25:53 +03:00
<filename > /var/</filename> is generally not accessible this early yet), while
<filename > systemd-tpm2-setup.service</filename> runs during a later boot phase and saves the public key
2023-11-09 00:24:33 +03:00
to <filename > /var/lib/systemd/tpm2-srk-public-key.*</filename> .</para>
2023-09-26 22:25:53 +03:00
</refsect1>
<refsect1 >
<title > Files</title>
<variablelist >
<varlistentry >
<term > <filename > /run/systemd/tpm2-srk-public-key.pem</filename> </term>
2023-11-09 00:24:33 +03:00
<term > <filename > /run/systemd/tpm2-srk-public-key.tpm2b_public</filename> </term>
2023-09-26 22:25:53 +03:00
2023-11-09 00:24:33 +03:00
<listitem > <para > The SRK public key in PEM and TPM2B_PUBLIC format, written during early boot.</para>
2023-10-01 13:49:44 +03:00
<xi:include href= "version-info.xml" xpointer= "v255" /> </listitem>
2023-09-26 22:25:53 +03:00
</varlistentry>
<varlistentry >
<term > <filename > /var/lib/systemd/tpm2-srk-public-key.pem</filename> </term>
2023-11-09 00:24:33 +03:00
<term > <filename > /var/lib/systemd/tpm2-srk-public-key.tpm2_public</filename> </term>
2023-09-26 22:25:53 +03:00
2023-11-09 00:24:33 +03:00
<listitem > <para > The SRK public key in PEM and TPM2B_PUBLIC format, written during later boot (once
2023-10-01 13:49:44 +03:00
<filename > /var/</filename> is available).</para>
<xi:include href= "version-info.xml" xpointer= "v255" /> </listitem>
2023-09-26 22:25:53 +03:00
</varlistentry>
</variablelist>
</refsect1>
<refsect1 >
<title > See Also</title>
<para >
<citerefentry > <refentrytitle > systemd</refentrytitle> <manvolnum > 1</manvolnum> </citerefentry>
</para>
</refsect1>
</refentry>