Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Usually, no. Ubuntu 20.04 (Focal) includes swtpm in its official archive. Enable the universe repository, then install both swtpm and swtpm-tools. The second package matters for virtualisation setups that need the swtpm_setup helper. Use a PPA only if the official packages are genuinely unavailable or you need a specific, release-compatible backport.
swtpm is an open-source software TPM emulator used by virtual machines; it is not an IBM commercial product or a substitute for a hardware TPM. The upstream project has IBM contributors and uses the libtpms library. Upstream project details.
Check your Ubuntu base first
These instructions are for Ubuntu 20.04 LTS, whose codename is focal. Kubuntu 20.04 uses the same Ubuntu package repositories, so there is no separate KDE-specific TPM emulator package.
. /etc/os-release
printf '%sn' "$PRETTY_NAME" "$VERSION_CODENAME"
On Ubuntu 20.04, the codename should be focal. If you use Linux Mint or another derivative, its displayed codename may differ from the Ubuntu base. Check the derivative’s documentation rather than guessing a codename or adding a PPA intended for another release.
#1 Best Overall
- Compatible with TPM-M R2.0
- Chipset: Infineon SLB9665
- PIN DEFINE:14Pin
- Interface:LPC
- Please check the Pinout of mainboard at the official website and make sure it compatible with the pinout of TPM module before purchasing, thank you.
Install from Ubuntu’s repository
First enable universe, where the packages are normally available, refresh APT’s package lists, and install the emulator and its utilities:
sudo add-apt-repository universe
sudo apt update
sudo apt install swtpm swtpm-tools
swtpm is the emulator. swtpm-tools provides setup and management utilities, including swtpm_setup. Installing only the emulator can leave libvirt or another virtualisation tool unable to find that helper. Ubuntu’s archive lists Focal packages for swtpm; versions and availability can vary with the configured archive pockets and mirrors. Ubuntu source package history.
If you also need a QEMU/libvirt host and have not installed that stack, install it separately:
sudo apt install qemu-kvm libvirt-daemon-system libvirt-clients virt-manager
This command installs virtualisation software; it is not required just to install swtpm.
Verify the packages and their origin
command -v swtpm
command -v swtpm_setup
swtpm --version
apt-cache policy swtpm swtpm-tools
The first two commands should print executable paths, normally under /usr/bin. The policy output should show a candidate from an Ubuntu archive or its regional mirror, commonly under universe. If no candidate appears, inspect package discovery and repository configuration:
Rank #2
- Nuvoton NPCT650
- TCG PC Client Platform TPM Profile (PTP) Specification; Family 2.0 (Trusted Platform Module Library; Family 2.0)
- TCG PC Client Specific TPM Interface Specification (TIS), Version 1.3 (TPM Main Specification; Family 1.2 Revision 116)
- Low Standby Power Consumption
apt-cache search '^swtpm'
apt-cache policy swtpm swtpm-tools
Do not assume that a package came from Ubuntu just because it is installed: use apt-cache policy to inspect the available origin and candidate.
Using an emulated TPM with virt-manager or libvirt
Installing the packages makes the emulator available; it does not automatically attach a TPM to every virtual machine. In virt-manager, shut down the VM, open its hardware details, add a TPM device, and select an emulated backend and TPM 2.0 where those options are available and appropriate. Labels and capabilities can vary by virt-manager, libvirt, and guest configuration.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Libvirt normally starts and manages the emulator for a VM configured with an emulated TPM. If startup fails, check that the helper exists and that libvirt is running:
ls -l /usr/bin/swtpm /usr/bin/swtpm_setup
sudo systemctl status libvirtd
virsh list --all
For a reported error such as Unable to find 'swtpm_setup' binary in $PATH, install or reinstall swtpm-tools first:
sudo apt install swtpm-tools
command -v swtpm_setup
dpkg -S "$(command -v swtpm_setup)"
Do not copy the helper manually into /usr/local/bin; that can create a version mismatch and conceal which package owns the executable. A successful package check also does not prove that a VM’s TPM configuration, permissions, or firmware settings are correct. Inspect libvirt and system logs for the specific VM failure; where present, swtpm logs may be under /var/log/swtpm.
Rank #3
- Compatible with:TPM2.0(MS-4462)
- Chipset: INFINEON 9670 TPM 2.0
- PIN DEFINE:12-1Pin
- Interface:SPI
- Supports:MSI Intel 400 Series and 500 Series Motherboards,MSI AMD B550 and A520 Series Motherboards,Windows 10 TPM 2.0
Optional: smoke-test the emulator
This starts a temporary TPM 2.0 socket emulator. It checks that the binary can launch, but it does not connect the emulator to QEMU or configure libvirt.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorstmpdir="$(mktemp -d)"
swtpm socket
--tpm2
--tpmstate "dir=$tmpdir"
--ctrl "type=unixio,path=$tmpdir/swtpm.sock"
--daemon
After testing, stop the process you started and remove its temporary state directory. Avoid broad process-kill commands on a machine running other virtual machines; identify the test process carefully before stopping it.
When a PPA may be appropriate
A PPA is a third-party package archive, not a routine prerequisite for Ubuntu 20.04. Consider one only after confirming that universe is enabled and package lists are current, or when a documented application issue requires a particular compatible backport. Check that the PPA publishes for focal, review its package and signing information, and accept that it is maintained outside Ubuntu’s standard archive. Ubuntu’s PPA guidance explains the distinction.
Scott Moser’s swtpm PPA
Launchpad identifies ppa:smoser/swtpm as an archive for QEMU and swtpm. Its published notes describe no-change backports from Ubuntu 22.04 beginning in November 2021, and the listed Focal swtpm build is dated November 17, 2021. Treat this as a historical fallback, not an automatically maintained current solution. Check the PPA’s current Focal publishing and signing details before using it: Scott Moser’s Launchpad archive.
If you have verified that it is suitable for your system and still want to add it, Launchpad’s command form is:
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #4
- TPM 2.0 module for Asus motherboard.
- TPM 2.0 module chip 2.0mm pitch, 2x7P, 14 pin security module
- LPC 14 Pin for AsusTPM chip is better compatible with DDR4 memory module of motherboard, built in support memory type higher than DDR3! Supported states may vary by motherboard specification.
- Note: Don't support laptops and motherboards prior to X99; Don't support DDR3 memory.
- Packing list:1x TPM 2.0 Module for ASUS
sudo add-apt-repository ppa:smoser/swtpm
sudo apt update
sudo apt install swtpm swtpm-tools
Do not add this PPA merely because swtpm_setup is missing; that helper is supplied by swtpm-tools.
Historical Focal-specific upstream-related PPA
Upstream troubleshooting from 2021 points to stefanberger/swtpm-focal for a case where swtpm_setup was missing. Treat that reference as historical, not proof that the archive is currently maintained or suitable for every Focal system. Check the archive’s current Launchpad instructions and Focal builds before considering it: Stefan Berger’s Focal PPA and the upstream issue. Do not paste an old, unauthenticated repository line or substitute a different Ubuntu codename.
Troubleshooting
APT says “Unable to locate package swtpm”
Common causes are a disabled universe component, stale package lists, an unexpected OS release, or derivative-specific repository configuration. Check the actual system release, enable the repository, update, and inspect the candidate:
. /etc/os-release
printf '%sn' "$PRETTY_NAME" "$VERSION_ID" "$VERSION_CODENAME"
sudo add-apt-repository universe
sudo apt update
apt-cache policy swtpm swtpm-tools
If the system is genuinely Ubuntu 20.04 but its configured mirror no longer serves the release, follow Ubuntu’s applicable archive guidance. Do not “fix” the error by entering jammy, focal, or another codename that does not match the system.
The helper is still missing
Install swtpm-tools, then check its contents and command path:
Best Value
- Product Color: Black
- Width: 0.6"
- Depth: 0.5"
- Additional Information: Interface: SPI Features: TPM IC: Nuvoton NPCT750 TPM Version: TPM 2.0 Pin Dimension: 14-1pin System Requirements: Windows® 10, UEFI OS
- Country of Origin: Vietnam
sudo apt install swtpm-tools
dpkg -L swtpm-tools | grep -E '/swtpm_(setup|bios|localca)$'
command -v swtpm_setup
A PPA produces a GPG or signature error
Do not disable APT signature verification. Remove the PPA and return to the official archive if possible:
sudo add-apt-repository --remove ppa:smoser/swtpm
sudo apt update
If you added a repository manually, identify its source file before removing or editing it:
grep -Rni swtpm /etc/apt/sources.list /etc/apt/sources.list.d/ 2>/dev/null
If PPA packages already replaced Ubuntu packages, removing the source alone may not revert them. A package-downgrade tool such as ppa-purge may be appropriate if available and compatible with the release, but do not assume it is a guaranteed recovery path.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchThe PPA reports a missing Release file or wrong codename
That usually means the archive does not publish for the configured series, or the source was configured with the wrong codename. A Focal package is not interchangeable with a Bionic or Jammy package. Check the PPA’s Launchpad series page and correct or remove the source; do not mix releases to force installation.
What an emulated TPM does—and does not—provide
swtpm presents a virtual TPM interface to a guest and supports TPM 1.2 and TPM 2.0 use cases. It does not turn the host into a hardware-backed security module, nor does its software-managed state provide the same protection as a discrete or firmware TPM. Upstream swtpm manual.
For a Windows 11 virtual machine, an emulated TPM can satisfy the TPM-related part of a configuration, but it does not guarantee installation or compatibility. Secure Boot, virtual firmware, CPU configuration, memory, storage, and installer checks are separate requirements.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Recommended Free Tools

