VMware:如何恢复安全 ESXi 配置

摘要: 本文提供有关在 ESXi 主机上更换系统主板或 TPM 后用户如何输入其恢复密钥的说明。

本文适用于 本文不适用于 本文并非针对某种特定的产品。 本文并非包含所有产品版本。

说明

前提条件: 

步骤:

  1. 在 ESXi 启动过程中,出现提示时按 SHIFT+O (字母 O,而不是数字 0/0):
在 ESXi 启动屏幕中,按 SHIFT+O
  1. 使用从前提条件收集的恢复密钥,将以下内容附加到启动配置: 
 
提醒:如果 iDRAC 为 v9 或更高版本且具有数据中心许可证,则可使用虚拟控制台剪贴板选项,这使得控制台复制和粘贴更加容易。
 
encryptionRecoveryKey=customer-recovery-key-here
Verify customer-recovery-key-here on command promtp
  1. <Enter> 键启动至 ESXi
  2. 通过 SSH 连接到 主机 
  3. 使用以下命令将更改写入磁盘:
[root@host1:~] /sbin/auto-backup.sh
Bootbank lock is /tmp/9f8acea1-504b6f07-568a-71c4e1a8ad0f.lck
Saving current state in /bootbank
Creating ConfigStore Backup
Locking esx.conf
Creating archive
Unlocked esx.conf
Using key ID 525ecf1a-d78f-3834-29aa-62600aee5fe4 to encrypt
Clock updated.
Time: 15:53:53   Date: 12/05/2023   UTC

受影响的产品

VMware ESXi 6.7.X, VMware ESXi 7.x, VMware ESXi 8.x

产品

PowerEdge XR2, PowerEdge C6420, PowerEdge C6520, PowerEdge C6525, PowerEdge C6615, PowerEdge C6620, PowerEdge FC640, PowerEdge M640, PowerEdge M640 (for PE VRTX), PowerEdge MX740C, PowerEdge MX750c, PowerEdge MX760c, PowerEdge MX840C, PowerEdge R240 , PowerEdge R250, PowerEdge R260, PowerEdge R340, PowerEdge R350, PowerEdge R360, PowerEdge R440, PowerEdge R450, PowerEdge R540, PowerEdge R550, PowerEdge R640, PowerEdge R6415, PowerEdge R650, PowerEdge R650xs, PowerEdge R6515, PowerEdge R6525, PowerEdge R660, PowerEdge R660xs, PowerEdge R6615, PowerEdge R6625, PowerEdge R740, PowerEdge R740XD, PowerEdge R740XD2, PowerEdge R7415, PowerEdge R7425, PowerEdge R750, PowerEdge R750XA, PowerEdge R750xs, PowerEdge R7515, PowerEdge R7525, PowerEdge R760, PowerEdge R760XA, PowerEdge R760xd2, PowerEdge R760xs, PowerEdge R7615, PowerEdge R7625, PowerEdge R840, PowerEdge R860, PowerEdge R940, PowerEdge R940xa, PowerEdge R960, PowerEdge T140, PowerEdge T150, PowerEdge T160, PowerEdge T340, PowerEdge T350, PowerEdge T360, PowerEdge T440, PowerEdge T550, PowerEdge T560, PowerEdge T640, PowerEdge XR11, PowerEdge XR12, PowerEdge XR4510c, PowerEdge XR4520c ...
文章属性
文章编号: 000220179
文章类型: How To
上次修改时间: 07 11月 2025
版本:  8
从其他戴尔用户那里查找问题的答案
支持服务
检查您的设备是否在支持服务涵盖的范围内。