{
    "mode": "man",
    "parameter": "systemd.pcrlock.d",
    "section": "5",
    "url": "https://www.chedong.com/phpMan.php/man/systemd.pcrlock.d/5/json",
    "generated": "2026-10-10T07:34:31Z",
    "synopsis": "/etc/pcrlock.d/*.pcrlock\n/etc/pcrlock.d/*.pcrlock.d/*.pcrlock\n/run/pcrlock.d/*.pcrlock\n/run/pcrlock.d/*.pcrlock.d/*.pcrlock\n/var/lib/pcrlock.d/*.pcrlock\n/var/lib/pcrlock.d/*.pcrlock.d/*.pcrlock\n/usr/local/pcrlock.d/*.pcrlock\n/usr/local/pcrlock.d/*.pcrlock.d/*.pcrlock\n/usr/lib/pcrlock.d/*.pcrlock\n/usr/lib/pcrlock.d/*.pcrlock.d/*.pcrlock",
    "sections": {
        "NAME": {
            "content": "systemd.pcrlock, systemd.pcrlock.d - PCR measurement prediction files\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "/etc/pcrlock.d/*.pcrlock\n/etc/pcrlock.d/*.pcrlock.d/*.pcrlock\n/run/pcrlock.d/*.pcrlock\n/run/pcrlock.d/*.pcrlock.d/*.pcrlock\n/var/lib/pcrlock.d/*.pcrlock\n/var/lib/pcrlock.d/*.pcrlock.d/*.pcrlock\n/usr/local/pcrlock.d/*.pcrlock\n/usr/local/pcrlock.d/*.pcrlock.d/*.pcrlock\n/usr/lib/pcrlock.d/*.pcrlock\n/usr/lib/pcrlock.d/*.pcrlock.d/*.pcrlock\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "*.pcrlock files define expected TPM2 PCR measurements of components involved in the boot\nprocess.  systemd-pcrlock(1) uses such pcrlock files to analyze and predict TPM2 PCR\nmeasurements. The pcrlock files are JSON arrays that follow a subset of the TCG Common Event\nLog Format (CEL-JSON)[1] specification. Specifically the \"recnum\", \"content\", and\n\"contenttype\" record fields are not used and ignored if present. Each pcrlock file defines\none set of expected, ordered PCR measurements of a specific component of the boot.\n\n*.pcrlock files may be placed in various .d/ drop-in directories (see above for a full list).\nAll matching files discovered in these directories are sorted alphabetically by their file\nname (without taking the actual directory they were found in into account): pcrlock files\nwith alphabetically earlier names are expected to cover measurements done before those with\nalphabetically later names. In order to make positioning pcrlock files in the boot process\nconvenient the files are expected (by convention, this is not enforced) to be named\n\"NNN-component.pcrlock\" (where NNN is a three-digit decimal number), for example\n750-enter-initrd.pcrlock.\n\nFor various components of the boot process more than one alternative pcrlock file shall be\nsupported (i.e. \"variants\"). For example to cover multiple kernels installed in parallel in\nthe access policy, or multiple versions of the boot loader. This can be done by placing\n*.pcrlock.d/*.pcrlock in the drop-in dirs, i.e. a common directory for a specific component,\nthat contains one or more pcrlock files each covering one variant of the component. Example:\n650-kernel.pcrlock.d/6.5.5-200.fc38.x8664.pcrlock and\n650-kernel.pcrlock.d/6.5.7-100.fc38.x8664.pcrlock\n\nUse systemd-pcrlock list-components to list all pcrlock files currently installed.\n\nUse the various lock-* commands of systemd-pcrlock to automatically generate suitable pcrlock\nfiles for various types of resources.\n",
            "subsections": []
        },
        "WELL-KNOWN COMPONENTS": {
            "content": "Components of the boot process may be defined freely by the administrator or OS vendor. The\nfollowing components are well-known however, and are defined by systemd. The list below is\nuseful for ordering local pcrlock files properly against these components of the boot.\n\n240-secureboot-policy.pcrlock\nThe SecureBoot policy, as recorded to PCR 7. May be generated via systemd-pcrlock\nlock-secureboot-policy.\n\nAdded in version 255.\n\n250-firmware-code-early.pcrlock\nFirmware code measurements, as recorded to PCR 0 and 2, up to the separator measurement\n(see 400-secureboot-separator.pcrlock.  below). May be generated via systemd-pcrlock\nlock-firmware-code.\n\nAdded in version 255.\n\n250-firmware-config-early.pcrlock\nFirmware configuration measurements, as recorded to PCR 1 and 3, up to the separator\nmeasurement (see 400-secureboot-separator.pcrlock.  below). May be generated via\nsystemd-pcrlock lock-firmware-config.\n\nAdded in version 255.\n\n350-action-efi-application.pcrlock\nThe EFI \"Application\" measurement done once by the firmware. Statically defined.\n\nAdded in version 255.\n\n400-secureboot-separator.pcrlock\nThe EFI \"separator\" measurement on PCR 7 done once by the firmware to indicate where\nfirmware control transitions into boot loader/OS control. Statically defined.\n\nAdded in version 255.\n\n500-separator.pcrlock\nThe EFI \"separator\" measurements on PCRs 0-6 done once by the firmware to indicate where\nfirmware control transitions into boot loader/OS control. Statically defined.\n\nAdded in version 255.\n\n550-firmware-code-late.pcrlock\nFirmware code measurements, as recorded to PCR 0 and 2, after the separator measurement\n(see 400-secureboot-separator.pcrlock.  above). May be generated via systemd-pcrlock\nlock-firmware-code.\n\nAdded in version 255.\n\n550-firmware-config-late.pcrlock\nFirmware configuration measurements, as recorded to PCR 1 and 3, after the separator\nmeasurement (see 400-secureboot-separator.pcrlock.  above). May be generated via\nsystemd-pcrlock lock-firmware-config.\n\nAdded in version 255.\n\n600-gpt.pcrlock\nThe GPT partition table of the booted medium, as recorded to PCR 5 by the firmware. May\nbe generated via systemd-pcrlock lock-gpt.\n\nAdded in version 255.\n\n620-secureboot-authority.pcrlock\nThe SecureBoot authority, as recorded to PCR 7. May be generated via systemd-pcrlock\nlock-secureboot-authority.\n\nAdded in version 255.\n\n700-action-efi-exit-boot-services.pcrlock\nThe EFI action generated when ExitBootServices() is generated, i.e. the UEFI environment\nis left and the OS takes over. Covers the PCR 5 measurement. Statically defined.\n\nAdded in version 255.\n\n710-kernel-cmdline.pcrlock\nThe kernel command line, as measured by the Linux kernel to PCR 9. May be generated via\nsystemd-pcrlock lock-kernel-cmdline.\n\nAdded in version 255.\n\n720-kernel-initrd.pcrlock\nThe kernel initrd, as measured by the Linux kernel to PCR 9. May be generated via\nsystemd-pcrlock lock-kernel-initrd.\n\nAdded in version 255.\n\n750-enter-initrd.pcrlock\nThe measurement to PCR 11 systemd-pcrphase-initrd.service(8) makes when the initrd\ninitializes. Statically defined.\n\nAdded in version 255.\n\n800-leave-initrd.pcrlock\nThe measurement to PCR 11 systemd-pcrphase-initrd.service(8) makes when the initrd\nfinishes. Statically defined.\n\nAdded in version 255.\n\n820-machine-id.pcrlock\nThe measurement to PCR 15 systemd-pcrmachine.service(8) makes at boot, covering\n/etc/machine-id contents. May be generated via systemd-pcrlock lock-machine-id.\n\nAdded in version 255.\n\n830-root-file-system.pcrlock\nThe measurement to PCR 15 systemd-pcrfs-root.service(8) makes at boot, covering the root\nfile system identity. May be generated via systemd-pcrlock lock-file-system.\n\nAdded in version 255.\n\n850-sysinit.pcrlock\nThe measurement to PCR 11 systemd-pcrphase-sysinit.service(8) makes when the main\nuserspace did basic initialization and will now proceed to start regular system services.\nStatically defined.\n\nAdded in version 255.\n\n900-ready.pcrlock\nThe measurement to PCR 11 systemd-pcrphase.service(8) makes when the system fully booted\nup. Statically defined.\n\nAdded in version 255.\n\n950-shutdown.pcrlock\nThe measurement to PCR 11 systemd-pcrphase.service(8) makes when the system begins\nshutdown. Statically defined.\n\nAdded in version 255.\n\n990-final.pcrlock\nThe measurement to PCR 11 systemd-pcrphase-sysinit.service(8) makes when the system is\nclose to finishing shutdown. Statically defined.\n\nAdded in version 255.\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "systemd(1), systemd-pcrlock(1)\n",
            "subsections": []
        },
        "NOTES": {
            "content": "1. TCG Common Event Log Format (CEL-JSON)\nhttps://trustedcomputinggroup.org/resource/canonical-event-log-format/\n\nsystemd 255                                                                       SYSTEMD.PCRLOCK(5)",
            "subsections": []
        }
    },
    "summary": "systemd.pcrlock, systemd.pcrlock.d - PCR measurement prediction files",
    "flags": [],
    "examples": [],
    "see_also": [
        {
            "name": "systemd",
            "section": "1",
            "url": "https://www.chedong.com/phpMan.php/man/systemd/1/json"
        },
        {
            "name": "systemd-pcrlock",
            "section": "1",
            "url": "https://www.chedong.com/phpMan.php/man/systemd-pcrlock/1/json"
        }
    ]
}