Unsolved
1 Rookie
•
88 Posts
0
26
February 6th, 2025 14:42
Firmware Updates + Secure Boot + TPM Enabled
Im trying to update firmware on our ESXi hosts via OMIVV. The install acts like its working but im assuming the firmware is not being applied because a rescan of the firmware shows they still need an update. I also tried via OME and iDrac upload/install. Im starting to think its because of Secure Boot being enabled, TPM enabled, and also Lockdown mode enabled in VMware. Odd thing is this never happened before. Is there a procedure to follow when installing firmware with Secure Boot, TPM and Lockdown mode turned on?
No Events found!
DELL-Charles R
Moderator
Moderator
•
4.1K Posts
0
February 6th, 2025 19:40
Hello,
Has anything changed since the last time it worked properly?
Is Collect System Inventory On Restart (CSIOR) enabled in the system BIOS?
If you give the DRAC a reboot; does it report correctly?
Does it give you any information about the update status in the LifeCycle Log and the iDRAC System Event Log?
If you have a maintenance window you may try a flea power drain:
drain flea power (shut down, disconnect power cables and Network cables, hold in power button 20 seconds with cords removed).
After flea power drain, system has to set for 3 minutes for DRAC to reset without any power plugged in,
Then plug in NIC and power but wait 2 minutes before power on to give DRAC time to initialize.
Check firmware reporting.
What model server are you working with?
tkutil
1 Rookie
1 Rookie
•
88 Posts
0
February 6th, 2025 22:16
This is what I can tell you so far. Turns out our network admin made some "changes" to the vlan/firewall connection for the iDRAC network. Now that they have fixed the iDRAC vlan I can use OME to update firmware on all of the servers they I tested except for my vmware esxi hosts. Here is the details from an attempted BIOS fw update from OME to an idrac on an esxi host
DELL-Young E
Moderator
Moderator
•
4.6K Posts
0
February 7th, 2025 05:39
Hello, can you confirm if "If you give the DRAC a reboot; does it report correctly?" this was performed? I think you can try directly from idrac instead of via OME.
Respectfully,