A user reports the following issue.
Some BIOS firmware on NUC8v5PNB devices measures an event of type EV_EFI_ACTION saying "Security Level is Downgraded to 0", which breaks the computation of the PCR policy, with this error:
cannot measure secure boot policy: unexpected event type (EV_EFI_ACTION) found in log
This can be fixed on these devices either by configuring the BIOS to the most secure option for Thunderbolt, or by updating the firmware.
Having a Thunderbolt security level of zero means that in some situations a malicious Thunderbolt device could access potentially sensitive data in your system’s memory.
In spite of that, because of operational constraints, the user would like an option to workaround this issue and still be able to use TPM-backed encryption.
A user reports the following issue.
Some BIOS firmware on NUC8v5PNB devices measures an event of type EV_EFI_ACTION saying "Security Level is Downgraded to 0", which breaks the computation of the PCR policy, with this error:
This can be fixed on these devices either by configuring the BIOS to the most secure option for Thunderbolt, or by updating the firmware.
Having a Thunderbolt security level of zero means that in some situations a malicious Thunderbolt device could access potentially sensitive data in your system’s memory.
In spite of that, because of operational constraints, the user would like an option to workaround this issue and still be able to use TPM-backed encryption.