Installing Windows 11 with KVM and it wants TPM enabled

I really don’t want to use TPM with my EndeavourOS installation so, will I be obligated to do that if I enable TPM on my motherboard?

If so, screw it, I’ll just find a Windows 10 iso. I’m just seeing if I can use it run the few things I still need Windows for.

Install swtpm. It’s a software TPM emulator, qemu can use it to tell Win11 that it has a TPM while not requiring you to have or use a hardware TPM.

..and I can get it without having to use the AUR, perfect. Thanks :slight_smile:

In the end, I ultimately had better luck with Windows 10. Needed USB pass through so, perhaps it wasn’t liking software emulated TPM. Not sure but, Windows 11 is a bloated toad anyways…
..
Thanks anyways though, that is good to know.

About the only advantage I experienced with enabling TPM was being able to pass through the physical device. This way, since my system already had a digital license for Windows 11, the new KVM install saw that and activated.

That goes back to my original question; If i enable TPM, am I required to set up EndeavourOS to use it or can it still just boot as normal without it?

EOS didn’t care in the slightest.

Here’s my latest boot log showing what’s happening with the TPM device:

$ journalctl -b -g tpm --no-pager
Aug 05 20:20:38 eos-hyprland-host kernel: efi: ACPI=0x74c1e000 ACPI 2.0=0x74c1e014 TPMFinalLog=0x74d6c000 SMBIOS=0x7793c000 SMBIOS 3.0=0x7793b000 MEMATTR=0x6c60d098 ESRT=0x6df0d518 RNG=0x74b67f18 INITRD=0x63b85f98 TPMEventLog=0x74a5b018 
Aug 05 20:20:38 eos-hyprland-host kernel: ACPI: TPM2 0x0000000074A64000 00004C (v04 ALASKA A M I    00000001 AMI  00000000)
Aug 05 20:20:38 eos-hyprland-host kernel: ACPI: Reserving TPM2 table memory at [mem 0x74a64000-0x74a6404b]
Aug 05 20:20:38 eos-hyprland-host systemd[1]: systemd 261.2-1-arch running in system mode (+PAM +AUDIT -SELINUX +APPARMOR -IMA +IPE +SMACK +SECCOMP +GCRYPT +GNUTLS +OPENSSL +ACL +BLKID +CURL +ELFUTILS +FIDO2 +IDN2 +KMOD +LIBCRYPTSETUP +LIBCRYPTSETUP_PLUGINS +LIBFDISK +PCRE2 +PWQUALITY +P11KIT +QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD +BPF_FRAMEWORK +BTF +XKBCOMMON +UTMP +LIBARCHIVE)
Aug 05 20:20:38 eos-hyprland-host systemd[1]: TPM PCR Barrier (initrd) skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:02 eos-hyprland-host systemd[1]: systemd 261.2-1-arch running in system mode (+PAM +AUDIT -SELINUX +APPARMOR -IMA +IPE +SMACK +SECCOMP +GCRYPT +GNUTLS +OPENSSL +ACL +BLKID +CURL +ELFUTILS +FIDO2 +IDN2 +KMOD +LIBCRYPTSETUP +LIBCRYPTSETUP_PLUGINS +LIBFDISK +PCRE2 +PWQUALITY +P11KIT +QRENCODE +TPM2 +BZIP2 +LZ4 +XZ +ZLIB +ZSTD +BPF_FRAMEWORK +BTF +XKBCOMMON +UTMP +LIBARCHIVE)
Aug 05 20:21:02 eos-hyprland-host systemd[1]: TPM PCR Measurements skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:02 eos-hyprland-host systemd[1]: Make TPM PCR Policy skipped, unmet condition check ConditionSecurity=measured-uki
Aug 05 20:21:02 eos-hyprland-host systemd[1]: TPM PCR Machine ID Measurement skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:02 eos-hyprland-host systemd[1]: TPM PCR OS Separator skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:02 eos-hyprland-host systemd[1]: Early TPM SRK Setup skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:02 eos-hyprland-host systemd[1]: TPM PCR NvPCR Initialization Separator skipped, unmet condition check ConditionPathExists=/etc/initrd-release
Aug 05 20:21:02 eos-hyprland-host systemd[1]: TPM NvPCR Product ID Measurement skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:02 eos-hyprland-host systemd[1]: TPM SRK Setup skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: Condition check resulted in /dev/tpmrm0 being skipped.
Aug 05 20:21:03 eos-hyprland-host systemd[1]: Expecting device /dev/tpm0...
Aug 05 20:21:03 eos-hyprland-host systemd[1]: Condition check resulted in /dev/tpm0 being skipped.
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM PCR Machine ID Measurement skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM PCR OS Separator skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: Early TPM SRK Setup skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM PCR NvPCR Initialization Separator skipped, unmet condition check ConditionPathExists=/etc/initrd-release
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM NvPCR Product ID Measurement skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM SRK Setup skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM PCR Machine ID Measurement skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM PCR OS Separator skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: Early TPM SRK Setup skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM PCR NvPCR Initialization Separator skipped, unmet condition check ConditionPathExists=/etc/initrd-release
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM NvPCR Product ID Measurement skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM SRK Setup skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM PCR Machine ID Measurement skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM PCR OS Separator skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: Early TPM SRK Setup skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM PCR NvPCR Initialization Separator skipped, unmet condition check ConditionPathExists=/etc/initrd-release
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM NvPCR Product ID Measurement skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:03 eos-hyprland-host systemd[1]: TPM SRK Setup skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:09 eos-hyprland-host systemd[1]: TPM PCR Barrier (Initialization) skipped, unmet condition check ConditionSecurity=measured-os
Aug 05 20:21:09 eos-hyprland-host systemd[1]: TPM PCR Barrier (User) skipped, unmet condition check ConditionSecurity=measured-os

As you can see, every pre-check fails; exactly what I want.

Yea, looks like I have TPM enabled and I’m booting OK without being configured for it.

played around a little more with getting pass through to work on windows 11. No luck. I understand it’s possible to go into the registry and disable TPM but, windows 10 is working for me so I’ll just stay with that.

OP, why not use Windows 11 IoT? It doesn’t have that stupid requirement as far as I can tell. Here

Didn’t know there was a Windows 11 IoT. I’ll take a look. They seem real coy about divulging how much the license will cost after the 90 day trial though.

Looks like GPU pass through, should I decide to tinker with that, will be a project in and of itself. I was kind of hoping this could be a potential solution for software like “Training Peaks Virtual” or “Zwift” but, not if I need to scare up a second graphics card. Still researching what’s involved though. Also, I can can run Zwift in Linux using a solution developed by “netbrain” (https://github.com/netbrain/zwift)

Stop promoting illegal content. This has been discussed before and you know it! Geez how hard is it to follow the rules!

Moderator Note

I had to delete a post for promoting illegal content. Please follow the rules.

Not sure why you seem to be indignated but fair enough.

OP, if you really, truly need Windows, wouldn’t Windows 10 suffice? It’s still supported by apps and I imagine that would probably be a better option than Windows 11. Alternatively, I believe older versions of the OS had that bypass for TPM? I honestly don’t know what to tell you, so I maybe should just shut the hell up, since I seem to have roughed some people up.

Windows 10 probably will suffice but this exercise is as much about the journey (I.E. - learning KVM, which I’ve not used before) as it is the destination. :wink:

Then have fun, I guess. I’m going out.

Moderator Note

Unfortunately, this is no longer about the topic itself

closed