Enabling host encryption or configuring a Virtual Trusted Platform Module (vTPM) fails with a runtime error regarding the encryption policy or key provider compatibility.
The vSphere Client displays one of the following errors:
"A general system runtime has occurred. Cannot apply encryption policy. You must set default key provider."Trusted Key provider is not compatible with host. Reason: "The host does not support Native Key Provider because it is not in a cluster."/var/log/vmware/vpxd/vpxd.log) show entries similar to: [YYYY-MM-DDTHH:MM] error vpxd[#####] [Originator@#### sub=CryptoManager opID=########-####-auto-####-##:########-##] [vim.HostSystem:<host-moid>,<host-fqdn>] is not compatible with key provider TestKeyProvider: native key providers not supported.[YYYY-MM-DDTHH:MM] error vpxd[#####] [Originator@#### sub=CryptoManager opID=########-####-auto-####-##:########-##] Trusted Key Provider is not compatible with host: com.vmware.vim.vpxd.encryption.NativeKeyProviderNotSupported
Use key provider only with TPM protected ESXi hosts" enforcement, the task will fail on any host that does not have a physical TPM 2.0 device installed and enabled in the BIOS.This issue occurs for the following reasons:
Follow the below options depending on the error.
Default key provider" error:Not in a cluster" or compatibility errors:For more details, see vSphere Native Key Provider Overview