"Host Requires Encryption Mode Enabled" Alarm on ESXi hosts
book
Article ID: 400316
calendar_today
Updated On:
Feedback
Subscribe
Products
VMware vCenter Server
Show More
Show Less
Issue/Introduction
After enabling the Native Key Provider (NKP) on the vCenter Server Appliance, ESXi hosts have an alarm on them that says "Host Requires Encryption Mode Enabled".
When hosts with TPM are added to a cluster containing non-TPM enabled hosts, an alarm is reported on the non-TPM enabled hosts, stating "Host Requires Encryption Mode Enabled".
Environment
VMware vCenter Server 7.x - 8.x VMware vSphere ESXi 7.x - 8.x
Cause
The Host encryption alarm can be triggered due to two primary reasons:
There are cryptographic operations that require the ESXi host to have this feature enabled.
Due to the mixed nature of the cluster, with TPM-enabled and non-TPM enabled hosts, this alarm is triggered on the non-TPM enabled hosts.
Resolution
There are several approaches to resolve this issue: If the TPM is enabled on the host and encryption is required to be enabled -
Enable the ESXi encryption mode by selecting the ESXi host, Configure and then Security Profile.
Under the Host Encryption Mode, click the Edit button and then change the mode to Enabled and click the OK button.
If encryption and TPM functionality is not required -
Log in to the vSphere Client.
Navigate to the vCenter Server object in the inventory.
Go to Configure > Alarm Definitions.
In the filter field next to "Alarm Name", enter "encryption".
Select the radio button next to "Host Requires Encryption Mode Enabled Alarm".
Click the EDIT control.
In the alarm configuration dialogue, click NEXT until you reach the "Review" screen.
Find the "Disable this alarm" option and select it.
Click SAVE to apply the changes.
After applying any of these solutions, monitor the vSphere UI for 24 hours to confirm that the alarm is no longer triggered.
Additional Information
Disabling the Encryption Mode alarm does not affect the security of your environment if you're not utilizing TPM-based features.
You can re-enable the alarm in the future if you implement TPM-based security features in your environment.
Feedback
thumb_up
Yes
thumb_down
No