VMware: How to Recover the Secure ESXi Configuration
Summary:This article provides instructions on how the user inputs their recovery key after system board or TPM replacement on an ESXi host.
Please select a product to check article relevancy
This article applies to This article does not apply toThis article is not tied to any specific product.Not all product versions are identified in this article.
Ensure that the BIOS configuration is set up correctly for TPM. Review the hardware owner’s manual.
Steps:
During boot of ESXi, press SHIFT+O when prompted (the letter O, not the number Zero/0):
Append the following to the boot configuration with the recovery key gathered from Pre-requisites:
Note: If the iDRAC is v9 or later with a data center license, the virtual console clipboard option is available which makes console copy and paste easier.
encryptionRecoveryKey=customer-recovery-key-here
Press <ENTER> to boot into ESXi
SSH into the host
Write changes to disk with the following:
[root@host1:~] /sbin/auto-backup.sh
Bootbank lock is /tmp/9f8acea1-504b6f07-568a-71c4e1a8ad0f.lck
Saving current state in /bootbank
Creating ConfigStore Backup
Locking esx.conf
Creating archive
Unlocked esx.conf
Using key ID 525ecf1a-d78f-3834-29aa-62600aee5fe4 to encrypt
Clock updated.
Time: 15:53:53 Date: 12/05/2023 UTC