Error: Attempting to mount a tardisk from a vib without valid signature on ESXi
search cancel

Error: Attempting to mount a tardisk from a vib without valid signature on ESXi

book

Article ID: 445840

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

This article addresses an alarm.HostErrorAlarm in vCenter Server where ESXi hosts report an attempt to mount a tardisk from a VIB without a valid signature following an environment update.

Environment

 

  • VMware ESXi 8.x
  • VMware vCenter Server 8.x
  • Nutanix G8 Platforms (NX-3170-G8)
  • Symptoms:

    • vCenter triggers alarm.HostErrorAlarm on one or more hosts.
    • The alarm message states: Issue detected on ####: Attempting to mount a tardisk from a vib without valid signature, this may result in security breach.
    • The issue typically appears immediately after a host reboot or environment update.

 

Cause

During the host boot cycles following an update, ESXi may detect legacy or residual signature data and trigger a security notification. If the host passes secure boot checks, the alarm in vCenter is a stale, leftover notification from that specific boot cycle.

Resolution

 

  • Log in to the ESXi host via SSH.
  • Run the following command to verify the integrity of VIBs and tardisks:
    bash
     
    /usr/lib/vmware/secureboot/bin/secureBoot.py -c
  • Confirm the output shows: Secure boot can be enabled: All vib signatures verified. All tardisks validated. All acceptance levels validated.
  • If the output is positive, the alarm is stale. In vCenter Server, navigate to Monitor > Issues and Alarms > Triggered Alarms.
  • Select the alarm.HostErrorAlarm associated with the tardisk message.
  • Click Acknowledge, then click Reset to Green.

 

Additional Information

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.