The AEM package was upgraded recently (probably because of this thread: 
https://groups.google.com/forum/#!topic/qubes-users/3ZkmS5v7E38), and after I 
installed the updated version, AEM stopped working completely.

Now, it asks me for the AEM password. I type it in, and it doesn't display my 
secret message. Instead, it immediately asks me for the disk password, and 
while it boots the system, I see a message telling me: "PCR sanity check 
failed".

I have tried to completely clear and reinstall AEM several times, but the same 
issue persists.

This is the content of the journalctl log:

Jul 07 16:25:36 dom0 systemd[1]: Starting Anti Evil Maid sealing...
Jul 07 16:25:39 dom0 anti-evil-maid-seal[1982]: tpm_z_srk: detecting whether 
SRK is password protected
Jul 07 16:25:39 dom0 anti-evil-maid-seal[1982]: Tspi_Key_CreateKey failed: 
0x00000001 - layer=tpm, code=0001 (1), Authentication failed
Jul 07 16:25:39 dom0 anti-evil-maid-seal[1982]: tpm_z_srk: yes, SRK is password 
protected; resetting dictionary attack lock...
Jul 07 16:25:39 dom0 anti-evil-maid-seal[1982]: PCR-17: FF FF FF FF FF FF FF FF 
FF FF FF FF FF FF FF FF FF FF FF FF
Jul 07 16:25:39 dom0 anti-evil-maid-seal[1982]: PCR-18: FF FF FF FF FF FF FF FF 
FF FF FF FF FF FF FF FF FF FF FF FF
Jul 07 16:25:39 dom0 anti-evil-maid-seal[1982]: PCR-19: FF FF FF FF FF FF FF FF 
FF FF FF FF FF FF FF FF FF FF FF FF
Jul 07 16:25:39 dom0 systemd[1]: anti-evil-maid-seal.service: Main process 
exited, code=exited, status=1/FAILURE

Any idea what the cause of this issue could be?

Regards,
Elias

-- 
You received this message because you are subscribed to the Google Groups 
"qubes-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to qubes-users+unsubscr...@googlegroups.com.
To post to this group, send email to qubes-users@googlegroups.com.
To view this discussion on the web visit 
https://groups.google.com/d/msgid/qubes-users/36028d9f-fb42-4761-b605-ef69d219fb18%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to