Symptoms:
Possible Error Messages:
The system has found a problem on your machine and cannot continue.Unable to restore the system configuration. A security violation was detected. https://via.vmw.com/security-violation

Failed to decrypt system configuration. https://via.vmw.com/config-decryption-failedUnable to recover the system configuration. https://via.vmw.com/recovery-failedNOTE: In ESXi versions before 8.0 Update 1 Quick Boot cannot be used when TPM is enabled.
The system performs an intended security lockout after detecting a hardware replacement.
Because the encrypted configuration is hardware-bound to the TPM, a change in the physical board renders the configuration unreadable.
Validate that each step below is true in the environment. Each step provides instructions or a link to a document to eliminate possible causes and take corrective action as necessary.
execInstalledOnly boot option is set to FALSE, change it back to its initial value (i.e. TRUE).>execInstalledOnly has been disabled, add "execInstalledOnly=TRUE" to the boot command-line (press shift+O during the 5 second countdown when mboot starts, right after the BIOS finishes running).encryptionRecoveryKey=######-######-######-######-######-######-######-######-######-######-######-######-######esxcli system settings encryption recovery list" while the ESXi host is healthy. The key consists of 16 sets of six digit values, with a dash between each set.execInstalledOnly=TRUE encryptionRecoveryKey=######-######-######-######-######-######-######-######-######-######-######-######-######-######-######-####### /sbin/auto-backup.shThe new host TPM endorsement key doesn't match the one stored in the DB.This means that a genuine ESXi version has booted but, the configuration data has been tampered with or is corrupted and cannot be recovered. Refer to Install and upgrade ESXi step by step procedures.
This means that ESXi is unable to be recovered with the provided recovery key. Ensure the input recovery key is correct; otherwise refer to Install and upgrade ESXi step by step procedures.
If a PSOD is encountered during ESXi reinstallation, check the system BIOS for an option to clear the TPM cache. Firmware updates can cause discrepancies between active TPM values and BIOS-cached values, triggering failures during fresh installations.