This article addresses frequently asked questions concerning the alarm "The new host TPM endorsement key doesn't match the one stored in the DB" observed in vSAN and VMware Cloud Foundation (VCF) environments
Background:
After changing the mother board with TPM, the following message may appear within the vSphere Client or host summary pageAlarm: “The new host TPM endorsement key doesn't match the one stored in the DB”
This alarm typically appears in the vSphere Client or on the host summary page following a system board replacement that includes a Trusted Platform Module (TPM). The underlying cause is a mismatch between the endorsement key generated by the new TPM and the corresponding key value previously stored within the vCenter Server database's (VPX_HOST) table for that specific host.
vCenter Server
The 'Endorsement Key' is something that is hardcoded by the manufacturer and used to uniquely identify a TPM device. This is different from other keys used by Broadcom to encrypt/decrypt configuration and something we cannot recover upon motherboard replacement. This is the reason vCenter doesn't automatically update the TPM endorsement key after the ESXi host configuration is restored.
reset to green", the alarm will come back once host gets reconnected or when it takes a reboot.acknowledge", the alarm will be permanently muted.