Frustratingly, when trying to redo the whole process (again in “Secure Boot setup mode” and after clearing the target disk with a GParted live ISO; reflashing the USB drive and then booting from it), it also boots from the USB drive and shows the “I am going to enroll the key” message, but at the next reboot directly(!, without even trying to write any data to the target disk) shows the PCR-04 error…
Note BTW that the “[Secure Boot] setup mode” I am referring to, when enabled (aka I selected the highlighted “Reset to Setup Mode”) shows this (IMHO confusing) state:
“Secure Boot Mode” shows what I guess it should be set to “Custom” - the first lines I interpret as "Secure Bot is currently enabled, but disabled in next reboot [for the “setup mode”/“purpose”)? But I may be wrong here.
