On RHEL installed with UEFI, tboot must be uninstalled before enabling TPM/TXT hardware
tboot on UEFI is specifically disabled by the grub2-efi maintainers, because the grub2-efi modules required to make tboot work may compromise security. There is a way to fix this, but business justification has not reached the critical mass necessary to foster such an effort. See Advisory https://access.redhat.com/articles/2217041 for details.
If tboot is installed on a UEFI-based RHEL ...
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.