PSOD may occur when upgrading to ESXi 7.0 when Security.AccountUnlockTime is 0
search cancel

PSOD may occur when upgrading to ESXi 7.0 when Security.AccountUnlockTime is 0

book

Article ID: 319855

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

  • Upgrade ESXi 6.x to ESXi 7.0 may cause a PSOD
  • ESXi console displays:

    The system has found a problem your machine and cannot continue.
    Configuration Upgrade Failure.
    Please reboot to rollback to the older version.
    Failed modules: /usr/lib/vmware/configmanager/upgrade/lib/libupgradeSecuritySettings.so

  • ESXi - /var/run/log/configstore-upgrade.log shows a validation error.

    [YYYY-MM-DDTHH:MM:SS] In(05) host-524620 [ConfigStore:198947385344:] [524620][/usr/lib/vmware/configmanager/upgrade/lib/libupgradeSecuritySettings.so] Invoking UpgradeConfig
    [YYYY-MM-DDTHH:MM:SS] Er(02) host-524620 [ConfigStore:198947385344:] [1083]Validation Error: '/account_unlock_time' Long value below minimum: 1
    [YYYY-MM-DDTHH:MM:SS] Er(02) host-524620 [ConfigStore:198947385344:] [1089] Failed to validate Set
    [YYYY-MM-DDTHH:MM:SS] In(05) host-524620 [ConfigStore:198947385344:] ConfigStoreException: [context] ... [/context]
    [YYYY-MM-DDTHH:MM:SS] Er(02) host-524620 [ConfigStore:198947385344:] [524620] /usr/lib/vmware/configmanager/upgrade/lib/libupgradeSecuritySettings.so] Upgrade failed rc: 1

Environment

VMware vSphere ESXi 6.5
VMware vSphere ESXi 6.7
VMware vSphere ESXi 7.0

Cause

This is due to the Security.AccountUnlockTime setting being set to 0 in ESXi 6.x.

Resolution

There is no fix at this time.

Workaround

Change the Security.AccountUnlockTime to between 1 - 3600 and re-try the upgrade.

  1. Log in to ESXi using Host Client.
  2. Select Manage in the left window.
  3. Select System->Advanced Settings in the right window.
  4. Search for "account" in the search box.
  5. Check and change the value of the parameter Security.AccountUnlockTime.

Additional Information

Configure the Passwords and Account Lockout Policy in the VMware Host Client