Basic TPM Usage

About This Task

Once a TPM 2.0 device is available in the system, you can use the tpm2-tools utilities to read Platform Configuration Registers (PCRs), inspect the firmware event log, and confirm that boot measurements have been recorded. Use this procedure to perform these basic operations.

Before You Begin

Procedure

  1. Read the PCRs with tpm2_pcrread.

    $ sudo tpm2_pcrread sha256:0,1,2,3,4,5,6,7,10
    

    Platform Configuration Registers are where the TPM stores the measurements taken as the system starts. Reading them is the first check of a measured boot: it confirms the TPM is responding and shows the current value of each register. The command requests the SHA-256 bank for registers 0 through 7, which hold the firmware and boot-loader measurements, and register 10, which holds the runtime measurements recorded by IMA. The hashes you see here are the values a verifier later compares against known-good references to decide whether the system can be trusted.

  2. Read the firmware event log with tpm2_eventlog.

    $ sudo tpm2_eventlog /sys/kernel/security/tpm0/binary_bios_measurements
    

    A Platform Configuration Register (PCR) holds only a single rolling hash, so its value alone tells you nothing about which components produced it. The event log fills that gap: it is the running record of each measurement the firmware took during boot, kept in a readable form that names the component behind every hash.

    The event log serves three purposes:

    • It describes each boot measurement. Every item the firmware measures at startup, from UEFI code and bootloaders to the kernel image and ACPI tables, is written to the log with enough detail to identify it.

    • It explains the PCR values. Each measurement is folded into a PCR as it occurs. Since the register itself keeps only the accumulated hash, the log preserves the per-step metadata needed to understand how that hash was reached.

    • It supports attestation. A verifier can walk the log, recompute the PCR values it should produce, and check them against the quote the TPM signed. A match confirms the system started from software that has not been tampered with.

  3. Verify that the boot PCRs are populated.

    Boot measurements should extend PCRs 0-7 so that they are non-zero.

    $ for pcr in 0 1 2 3 4 5 6 7; do
          echo -n "PCR $pcr: "
          cat /sys/class/tpm/tpm0/pcr-sha256/$pcr
      done
    

Results

The PCR values for registers 0-7 are non-zero, confirming that firmware and boot-loader measurements were extended into the TPM during boot. These measurements form the basis of the auditable chain of trust used for Remote Attestation.