Unused vTPM keys are not deleted from Standard Key Provider in vCenter Server
search cancel

Unused vTPM keys are not deleted from Standard Key Provider in vCenter Server

book

Article ID: 450613

calendar_today

Updated On:

Products

VMware vCenter Server

Issue/Introduction

When using virtual Trusted Platform Module (vTPM) with technologies such as Omnissa Instant Clones or Full Clones, vCenter Server requests unique keys from the configured Key Provider for each virtual machine. In environments using a third-party Standard Key Provider (KMS), users may observe high key creation counts and notice that keys for deleted virtual machines are not automatically removed from the KMS.

  • The Standard Key Provider (KMS) shows a high number of active keys.
  • Key creation counts increase rapidly when deploying or refreshing Instant Clones.
  • Keys associated with deleted virtual machines remain in the KMS database.

Environment

  • VMware vCenter Server 7.x / 8.x
  • Third-party Standard Key Provider (KMS)
  • Virtual Machines configured with vTPM
  • Omnissa Horizon Instant Clones

Cause

vCenter Server does not include functionality to manage the deletion or lifecycle of keys stored on a third-party Standard Key Provider. vCenter requests keys for encryption and vTPM operations, but the cleanup of those keys is the responsibility of the Key Management Server (KMS).

Resolution

vCenter Server does not support the automatic deletion of keys from a Standard Key Provider. To manage high key counts or remove unused keys, perform the following:

  1. Review the documentation for the specific third-party Key Provider (e.g., Thales, HyTrust, Dell) regarding key lifecycle management.
  2. Configure key expiration or automated cleanup policies within the KMS administration console if supported by the vendor.
  3. Contact the KMS vendor support team for assistance with identifying and deleting keys that are no longer in use by vSphere.
  4. For environments requiring tighter integration of key lifecycle management, evaluate the use of vSphere Native Key Provider, which handles key persistence differently.

To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.

Additional Information

Download Broadcom products, patches and software

Contact Support