RecoverPoint for VMs: 5.3 SP4 Patch 1 support for UEFI Secure Boot
Summary: RecoverPoint for Virtual Machines (VMs) 5.3 SP4 Patch 1 (5.3.4.1) does not have support for Unified Extensible Firmware Interface (UEFI) Secure Boot by default. This article explains the limitations and available options. ...
Symptoms
The RecoverPoint for VMs 5.3 SP4 Patch 1 Splitter vSphere Installation Bundle (VIB) cannot be installed when Secure Boot is enabled.
Testing Secure Boot with the splitter installation shows this error:
[root@vApp13-esx-100:~] /usr/lib/vmware/secureboot/bin/secureBoot.py -c Secure boot CANNOT be enabled : Failed to verify signatures of the following vib(s): [RP-Splitter]. All tardisks validated. All acceptance levels validated
Error on the ESXi host (/var/run/log/esxupdate.log) upon deploying the splitter:
Could not stage image profile '(Updated) ESXi-6.5.0-2018050xxx-standard': ('EMC_Recoverpoint_bootbank_RP-Splitter_RPESX-00.5.3.4.1.0.m.184.000', "('EMC_Recoverpoint_bootbank_RP-Splitter_RPESX-00.5.3.4.1.0.m.184.000', 'The VIB EMC_Recoverpoint_bootbank_RP-Splitter_RPESX-00.5.3.4.1.0.m.184.000 does not contain a signature.')")"" reporting on the VC tasks.
RecoverPoint for VMs 5.3 SP4 Patch 1 installation fails at 53% if the hosts are in Secure Boot mode.
The error in Deployment Manager:
Installation has failed. Review the error messages below to identify the cause. Installing vRPAs cluster, and verifying all vRPAs are attached. (x) could not deploy ESX splitter.
Cause
The RecoverPoint for VMs 5.3 SP4 Patch 1 Splitter VIB RPESX-00.5.3.4.1.0.m.184.000 is not signed.
Secure Boot is not supported with this splitter version.
Resolution
The RecoverPoint for VMs 5.3 SP4 Patch 1 Splitter VIB RPESX-00.5.3.4.1.0.m.184.000 is not signed and does not support Secure Boot.
- Secure Boot is not supported for vSphere 8.0 environments with RecoverPoint for VMs 5.3 SP4 Patch 1.
- Secure Boot is supported with the RecoverPoint for VMs 5.3.4.0 Splitter for vSphere 7.0.x environments with RecoverPoint for VMs 5.3 SP4 Patch 1.
Workaround for vSphere 8.0.x:
- Disable Secure Boot on ESXi hosts.
- Install the RecoverPoint for VMs 5.3 SP4 Patch 1 Splitter with the
--no-sig-checkoption:
esxcli software vib install -v /<Full_path_to_vib_file> --no-sig-check
Workaround options for older vSphere releases:
For vSphere 6.x and vSphere 7.0.x vSphere environments, follow one of these options:
- Use the 5.3 SP4 Splitter VIB: EMC_bootbank_RP-Splitter_RPESX-00.5.3.4.0.0.m.739.000.vib Install it manually.
- Disable Secure Boot and use the
RPESX-00.5.3.4.1.0.m.184.000splitter in the same way as vSphere 8.0.
See page 29 in the Deployment Guide, "Install the splitter with the RecoverPoint for VMs VIB installer" section.
Additional Information
This is true for RecoverPoint for VMs 5.3 SP3 Patch 3 VIB - EMC_bootbank_RP-Splitter_RPESX-00.5.3.3.3.0.m.176.000.vib.
RecoverPoint for VMs 6.0.x with VMware vSphere Application Programming Interfaces (APIs) for I/O Filtering (VAIO) Splitter continues to support Secure Boot.