VMware ESXi:如何從啟用 TPM 安全性的主機收集復原金鑰

Summary: 本文說明客戶如何從啟用可信賴平台模組 (TPM) 的主機收集復原金鑰。客戶應將每個主機的復原金鑰保存在安全的地方。更換主機板等硬體更換活動需要復原金鑰才能順利進行。

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

1) SSH 進入 ESXi 主機

2) 確認 TPM 是否已安裝,且 BIOS 中的「TPM 安全性」已啟用:
 
[root@host1:~] esxcli hardware trustedboot get
   Drtm Enabled: true
   Tpm Present: true

顯示復原金鑰:
 
[root@host1:~] esxcli system settings encryption recovery list
Recovery ID                             Key
--------------------------------------  ---
{95D596B6-F9B9-4EAE-9957-5F34340B0332}  576950-585883-508642-213447-669596-497854-451424-683261-618428-522564-132967-573419-333169-023300-403351-572521
復原金鑰是顯示的第二組數字:十六組,每組六個數字,如上圖所示,不是 {} 之間的英數字元。

請客戶複製復原金鑰,並建議他們將其連同主機名稱一起保存在安全的地方:
 
[root@host1:~] hostname
host1.local

更換主機板或 TPM 後,您必須還原 ESXi 安全性組態:ESXi - 如何復原安全的 ESXi 組態

Affected Products

PowerFlex rack, C Series, HS Series, Modular Infrastructure, Rack Servers, Tower Servers, XR Servers, Dell EMC vSAN Ready Nodes, OEM Server Solutions, VMware ESXi 5.x, VMware ESXi 6.5.X, VMware ESXi 6.7.X, VMware ESXi 6.x, VMware ESXi 7.x , VMware ESXi 8.x ...

Products

VMware ESXi 6.x, VMware ESXi 7.x, VMware ESXi 8.x
Article Properties
Article Number: 000220136
Article Type: How To
Last Modified: 10 Dec 2024
Version:  7
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.