I was setting up my new Librem 14 and decided to reboot it as it wasn’t showing that it was plugged in (other than the power LED). I had installed a few software packages, but nothing too radical (I thought). When I went to reboot, I inserted my Librem Key and got a message (that is now gone) that said that there was a checksum error on some file like
/boot/initrd….
I selected to update the checksum (after I tried not to). Now I get:
Gpg: verify signature failed: Unknown system error
Invalid signature on exec boot params
!!! Failed default boot
New value of PCR[4]: 8a6a9….b3
!!! Starting recovery shell
Factory user PIN of Librem Key should be 123456 but in my case it was 12345678, that is equal to admin PIN, so that upon my first reboot after initial boot, when I chose to re-sign the files in /boot using my Librem Key, I entered 123456 but it failed, then it started recovery shell, there I typed gui-init
then I entered the menu to re-sign, now using 12345678 and it succeeded.
The confirmation of the error in factory configuration was given by changing default PINs following the documentation: https://docs.puri.sm/Librem_Key/Getting_Started/User_Manual.html#change-or-unblock-a-pin-on-the-librem-key
To change PIN, you first need to type the old PIN, typing 123456 for user PIN failed to change, it worked using 12345678. For admin PIN the old value was correctly 12345678.
I ask @joao.azevedo if the error of factory configuring user PIN = admin PIN is common.