If an ESXi host utilizes a Trusted Platform Module (TPM), specific preparation steps are required before initiating any hardware changes while the host remains accessible via SSH.
The ESXi host experiences a Purple Screen of Death (PSOD) following the below changes:
The following KB article lists PSODs and error messages associated with boot-time encryption failures,
ESXi boot failures due to system configuration issues - restore security configuration, decrypt system configuration, recover system configuration
VMware vSphere ESXi 7.x
VMware vSphere ESXi 8.x
Unable to restore the system configuration. A security violation was detected.Preparation (Before Hardware Maintenance):
Connect to the ESXi host via SSH as the root user.
Verify the current encryption status to determine if "Require Secure Boot" or encryption is active:
esxcli system settings encryption get
Generate the recovery key:
esxcli system settings encryption recovery list
Store the generated recovery key in a secure, off-host location.
Generate and export a configuration backup to complement the encryption key:
vim-cmd /hostsvc/firmware/sync_config
vim-cmd /hostsvc/firmware/backup_config
Recovery (After Hardware Maintenance):
encryptionRecoveryKey=####-####-####-####esxcli system settings encryption set --mode=TPM
/sbin/auto-backup.shIf the recovery key was never captured, a full ESXi reinstallation is required.