Disable TPM from iDRAC.
search cancel

Disable TPM from iDRAC.

book

Article ID: 410791

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Sometimes TPM function could be misconfigured and causes unwanted error message. For environment where TPM isn't required, disabling TPM from UEFI/BIOS can be fast solving problems.

This KB shows how to disable TPM from iDRAC BIOS. For UEFI/BIOS of other brand, please consult hardware vendor for guidance.

Resolution

  1. Verify TPM is visible from ESXi.
    [root@esxi:~] esxcli hardware trustedboot get

       Drtm Enabled: false             

       Tpm Present: true 
  2. Verify ESXi boot mode is NOT configured to TPM. 
     [root@esxi:~] esxcli system settings encryption get

    Mode: NONE                      

    Require Executables Only From Installed VIBs: false    

     Require Secure Boot: false                       
  3. Power off ESXi.
  4. Enter iDRAC management IP address and open iDRAC web page.
  5. Click "Maintenance" >> "System Security".
  6. Find "TPM Security" item. Change it to "Off". Click "Apply", "Off" will shows at right side as a Pending Value. 
  7. Scroll down to the bottom of this page. Click "Apply And Reboot". iDRAC will reboot automatically. TPM will be disabled after reboot.