Home / Alt manpages / systemd-pcrphase.service(8)

  • systemd-pcrphase.service(8)
  • Admin command
  • linux

Use systemd PCR Barriers to Bind TPM2 Policy to Boot Phases

You will finish with a safe way to inspect systemd's TPM2 measurement units, understand the PCR values they extend, and decide whether a machine is ready for phase-bound policy. The examples use systemd 255.4-1ubuntu8.17, installed here as systemd 255. The guide does not change a unit file or manually extend a PCR.

Allow about 20 minutes. You need a shell and systemd 255 or newer. A unified kernel image (UKI) launched by systemd-stub is required for these services to measure anything. You also need TPM2 firmware, kernel and device support if you want actual measurements. Commands that only inspect state are unprivileged; commands that invoke the measurement tool can change TPM state and must be treated as security-sensitive.

1. Check the installed tool and package

Start with read-only checks. They confirm the binary, package version and option spelling on this host:

$ command -v systemd-pcrextend
/usr/lib/systemd/systemd-pcrextend
$ /usr/lib/systemd/systemd-pcrextend --version
systemd 255 (255.4-1ubuntu8.17)
$ /usr/lib/systemd/systemd-pcrextend --help
systemd-pcrextend  [OPTIONS...] WORD
systemd-pcrextend  [OPTIONS...] --file-system=PATH
systemd-pcrextend  [OPTIONS...] --machine-id

The executable is called systemd-pcrextend, while the service names describe the measurements that systemd schedules. In this version, --bank=, --pcr=, --tpm2-device= and --graceful are available. The manual records --bank as added in version 252, and the PCR selector as added in version 255.

Checkpoint

If the version or option list differs, stop and read the installed manual page before copying any example. The PCR index and supported banks are not assumptions to carry between systemd releases.

2. Understand what each service measures

The regular units are conditional barriers, not switches that enable TPM2. They have ConditionSecurity=measured-uki, so they run only when systemd detects a measured UKI. Without that boot arrangement, the units do no measurement.

UnitPCRMeasurement point
systemd-pcrphase-initrd.service11enter-initrd on start, leave-initrd on stop
systemd-pcrphase-sysinit.service11sysinit on start, final on stop
systemd-pcrphase.service11ready on start, shutdown on stop
systemd-pcrmachine.service15The host machine ID
systemd-pcrfs-root.service15Identity data for the root file system
[email protected]15Identity data for a selected mounted file system

PCR 11 records a sequence of literal phase strings. The normal runtime phase path is enter-initrd:leave-initrd:sysinit:ready. The initrd path is enter-initrd. An empty pre-initrd path can be represented by a single colon when it must be passed as an argument. Local administrators can define additional phases, so those strings are the default contract, not a universal complete history.

PCR 15 carries system identity. The machine measurement is based on /etc/machine-id. File system measurements include the mount point identity, file system type, UUID and label, plus partition identity where available.

3. Inspect the units without changing state

Ask systemd to show the installed unit definitions. This is an ordinary read-only command:

$ systemctl cat systemd-pcrphase.service
$ systemctl cat systemd-pcrphase-initrd.service
$ systemctl cat systemd-pcrmachine.service
$ systemctl cat systemd-pcrfs-root.service

Look for three details: ConditionSecurity=measured-uki, the --graceful option, and the literal argument after the executable. --graceful makes a missing TPM2 firmware, driver or device a successful no-op for the service. It does not manufacture a measurement and it does not make a non-UKI boot measured.

Check the unit's current condition and result without starting it:

$ systemctl show systemd-pcrphase.service \
    -p LoadState -p ActiveState -p Result -p ConditionResult
LoadState=loaded
ActiveState=inactive
Result=success
ConditionResult=no

The values are host-specific. A failed condition is expected on an ordinary non-UKI boot. Do not start the service merely to make the status look active: on a measured system, doing so can extend a real PCR value at the wrong point in the boot lifecycle.

Checkpoint

You have identified whether the unit is installed and whether its measured-UKI condition is true. If it is false, investigate the UKI and boot path first; changing the service cannot satisfy that condition.

4. Check TPM2 discovery safely

The measurement tool can list suitable TPM2 devices. This does not extend a PCR:

$ /usr/lib/systemd/systemd-pcrextend --tpm2-device=list
TPM2 support is not installed.

On a supported machine, the output will list discovered devices instead. The exact result depends on firmware, the kernel TPM driver and systemd's build options. If no device is found, do not remove --graceful from a service command to force an error unless you are deliberately testing failure handling.

For a host that should provide TPM2, check the kernel-facing device nodes and service logs with your normal administrator privileges:

$ ls -l /dev/tpmrm* /dev/tpm* 2>/dev/null
$ journalctl -b -u systemd-pcrmachine.service -u systemd-pcrfs-root.service
$ journalctl -b -u systemd-pcrphase.service

Use sudo only if your account cannot read the relevant device or journal. A missing device can be a firmware setting, a kernel configuration issue, or a virtual machine limitation. Reinstalling systemd is not a general fix.

5. Treat manual extensions as a security boundary

The command-line form accepts a word and normally extends it into PCR 11:

$ /usr/lib/systemd/systemd-pcrextend --graceful 'maintenance-window'

Warning

This command is not a harmless test on a machine with a working TPM2. If the TPM is available, it can extend PCR 11 and alter the state on which sealed keys or access policy depend. Do not paste it into production merely to see what happens. Use the service units for their intended lifecycle points, and use a disposable test machine when you need to study custom measurements.

The other measurement modes are similarly state-changing. --machine-id measures the host identity into PCR 15, and --file-system=/path measures the identity of an established mount point into PCR 15. They are not queries and they do not print the measurement as a reversible transaction. There is no general undo command for a PCR extension: PCRs are extended for the current TPM lifecycle and normally reset by reboot or TPM policy, not by deleting a file.

For this reason, keep the examples below as review notes rather than commands to run casually:

# Changes PCR 15 if a TPM2 device is available:
/usr/lib/systemd/systemd-pcrextend --graceful --machine-id

# Changes PCR 15 if a TPM2 device is available:
/usr/lib/systemd/systemd-pcrextend --graceful --file-system=/var

Run either only as part of a designed boot or measurement test, with a record of the expected PCR policy and a recovery plan for any sealed data that becomes unavailable. Elevated privileges may be necessary, but sudo does not make an unsafe measurement reversible.

6. Apply the information to TPM2 policy

Phase paths let a TPM2 policy distinguish boot stages. For example, a key needed only while the initrd unlocks storage can be bound to enter-initrd, while a runtime policy can use the longer path ending in ready. The point is to restrict access after a transition, not merely to record that a machine booted.

Use the installed systemd-measure tool where your system provides it to calculate expected PCR 11 values for a phase with its --phase= option. This host does not have that executable installed, so do not substitute a guessed command or hash. The expected value must match the systemd version, TPM bank and exact measured sequence used by the policy.

Read the event log when you need evidence of what was measured:

$ ls -l /run/log/systemd/tpm2-measure.log
$ sed -n '1,5p' /run/log/systemd/tpm2-measure.log

The log is a JSON-SEQ stream and may be absent when no measurements were made. It is runtime data, not a configuration file. A consumer that needs a consistent TPM quote and event-log snapshot should follow the documented shared-lock requirement rather than reading the file while a measurement is being written.

Done means

  • You confirmed the installed systemd version and systemd-pcrextend option set.
  • You know that the services require a measured UKI launched through systemd-stub.
  • You can map the phase units to PCR 11 and identity units to PCR 15.
  • You inspected unit conditions without starting a measurement service.
  • You checked TPM2 discovery and can distinguish missing hardware support from a failed policy.
  • You understand that manual extensions change TPM state and have no ordinary undo operation.