IncusOS on old hardware fails: cryptenroll: automatically discovered security TPM2 token unlocks volume

I’m trying to install IncusOS on the same machine I’d tried to get IncusOS running last December. The system boots, but it goes into a loop showing an error

ERROR Failed to run: systemd-cryptenroll --unlock-tpm2-device-auto --recovery-key /dev/sdb10: exit status 1 (Automatically discovered security  TPM2 token unlocks volume.)

In the image customizer, I had selected USB type, Operation usage, stable channel, pasted in my client cert, and no TPM 2.0 module. In my system firmware setup, I enabled secure boot and set the TPM device to “hidden.” I downloaded IncusOS_202608102114.img and flashed it to a 256 GB microSD card in a USB 3.0 reader. During boot, IncusOS displays a message about falling back to swtpm, as expected. IncusOS had rebooted once on its own before getting to this state.

Is there an issue with swtpm and cryptenroll, or is it just not possible to run IncusOS on this admittedly outdated hardware?

I deployed a fresh system using swtpm yesterday and that worked just fine, though that system really didn’t have any TPM at all. Maybe yours isn’t hiding it hard enough somehow?

@gibmat any idea?