PowerEdge: CTPM - Cannot Support ESXi TPM Encryption Function
Summary: China-specific Trusted Platform Module (CTPM) Part Number (PN) WFD8R cannot support ESXi 7.0 and 8.0 Trusted Platform Module (TPM) encryption function.
Symptoms
A NationZ CTPM in a 14G server, R6515 or R7515 with an ESXi 7.0 and ESXi 8.0 that has the TPM function enabled displays the following error message:
-
esxcli system settings encryption set --mode=TPMUnable to change the encryption mode and policy. Verify that the current host configuration can satisfy the new requirement.
-
esxcli system settings encryption set --require-secure-boot=TRUEUnable to change the encryption mode and policy. Verify that the current host configuration can satisfy the new requirement.

Cause
NationZ CTPM (PN: WFD8R) do not include Endorsement Key (EK) certificates. If you want to trust individual ESXi hosts, the TPM must include an EK certificate.
ESXi document: https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-B648273C-B7A9-42D5-BE35-A5577814392D.html
Resolution
If allowed by Chinese law, TPM (PN: FXJVY) can be used. This is because the TPM can support the ESXi TPM encryption function.
More:
Not all CTPMs do not support ESXi TPM encryption features. 15G CTPM PN: 2VJ50 and HDNTW can support the ESXi TPM encryption function. But 15G TPM PN 2VJ50 and HDNTW cannot (used in R6515 and R7515).