May 2, 2021

TPM Encryption Recovery Key Backup Alarm - ESXi 7u2

Recovery Key Alarm 
This is A new alarm which triggered to prompt the administrator to back up the
recovery key.
 
 
 
https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-6B13C88E-B57A-46B7-B3EC-0EE3F6C4D346.html 
 
Login to the ESXi and note down the key.
 
 [root@host1] esxcli system settings encyption recovery list

Recovery ID                             Key
--------------------------------------  ---
{2DDD5424-7F3F-406A-8DA8-D62630F6C8BC}  478269-039194-473926-430939-686855-231401-642208-184477-602511
-225586-551660-586542-338394-092578-687140-267425
 
 
 
This is really important as this key is needed to recover the Host in case, 

  • You cleared the TPM
  • The TPM failed.

https://docs.vmware.com/en/VMware-vSphere/7.0/com.vmware.vsphere.security.doc/GUID-23FFB8BB-BD8B-46F1-BB59-D716418E889A.html

if you have the key recorded you can use below steps. 

Procedure

  1. (Optional) If the TPM failed, move the disk (having the boot bank) to another host with a TPM.
  2. Start the ESXi host.
  3. When the ESXi installer window appears, press Shift+O to edit boot options.
  4. At the command prompt, enter the boot option to recover the configuration.
    encryptionRecoveryKey=recovery_key




No comments:

Post a Comment