June 27, 2026 (System76, Dasharo/coreboot+UEFI v1.0.1) · Ubuntu 26.04 LTS, kernel 7.0.0-27-generic
ubuntuukisystemd-bootlukstpm2secure-bootdasharomeasured-bootcoreboot
I spent a day migrating my encrypted Ubuntu install from shim/GRUB to a measured Unified Kernel Image, getting TPM auto-unlock working again, enabling Secure Boot without bricking the machine, and learning - repeatedly - that rebuilding the UKI without re-enrolling the TPM is a great way to lock yourself out of your own disk at boot.