Remix.run Logo
noisem4ker 2 days ago

Yes. The PCR state after booting won't match that of the regular system, so the TPM will refuse to give up the key.

evan_a_a a day ago | parent [-]

This is contingent on the sealing policy including PCRs that would change as a result of booting a different operating system, like PCR 11, which, when booting a UKI, contains those measurements. Only sealing against PCR 7 would allow this attack, since the default platform secure boot policy would not need to change.