When a manual update of the Secure Boot Platform Key (PK) for virtual machines is required in a VMware Cloud Director (VCD) environment, tenant users cannot perform this independently.
The Tenant Portal and VCD API do not provide the functionality to modify advanced configuration parameters, preventing tenant users from completing the update procedure described in following KB 423919.
Manual Update of the Secure Boot Platform Key in Virtual Machines
Note: If the virtual machine is running on VMware ESXi 8.0 U3j (P09) and the vTPM is disabled, the PK can be updated simply by rebooting the guest OS. For more details, refer to KB 423893.
Secure Boot Certificate Expirations and Update Failures in VMware Virtual Machines
VMware Cloud DIrector 10.6.x
VCD does not provide tenant users with the functionality to directly modify a virtual machine's advanced configuration parameters.Therefore, enabling and disabling the uefi.allowAuthBypass = "TRUE" setting needs to be performed by the Provider Administrator via the vSphere Client.
Other steps, such as taking snapshots, attaching a disk for OEM PK placement, and enrolling the key from the UEFI, can be performed directly from the Tenant Portal.
Note: By attaching a named disk to any virtual machine, formatting it with FAT32, and placing the PK from the guest OS side, other virtual machines can reuse the PK on this named disk.
The following is an example of the procedure for adding a PK to VCD tenant virtual machines using a named disk:
Note: Refer to KB 423919 for details on obtaining the WindowsOEMDevicesPK.der file and the procedure for enrolling the PK from the UEFI.
To add the PK to other virtual machines, repeat the process from Step 2 onwards for each target VM.