<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure Boot support for Alletra 6k dHCI in HPE Alletra Storage</title>
    <link>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7208686#M624</link>
    <description>&lt;P&gt;Download SCM from Infosight and reinstall the SCM. This should resolve the signature issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2024 06:18:20 GMT</pubDate>
    <dc:creator>BoonL</dc:creator>
    <dc:date>2024-03-12T06:18:20Z</dc:date>
    <item>
      <title>Secure Boot support for Alletra 6k dHCI</title>
      <link>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7208189#M622</link>
      <description>&lt;P&gt;Hello guys,&lt;/P&gt;&lt;P&gt;i have a pair of new DL360 Gen11 hosts deployed at a customer site as part of a greenfield Alletra 6030 dHCI environment. Now i get the error "Host TPM attension alarm" in vCenter - which I generally expect.&lt;/P&gt;&lt;P&gt;Normaly i would acitvate Secure boot and all the TPM stuff needed to fix this. however, the hosts now PSOD stating the secure boot failed as it was unable to validate the signatures for the Nimble SCM vib(s)&lt;/P&gt;&lt;P&gt;Is there a workaround for this or is secure boot simply not an option for Gen11 hosts and we have to live with getting the Attestation alarm after every reboot?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 09:57:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7208189#M622</guid>
      <dc:creator>jlangmead</dc:creator>
      <dc:date>2024-03-07T09:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Boot support for Alletra 6k dHCI</title>
      <link>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7208254#M623</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;talk to Nimble support they should have an answer.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 08:26:55 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7208254#M623</guid>
      <dc:creator>giladzzz</dc:creator>
      <dc:date>2024-03-07T08:26:55Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Boot support for Alletra 6k dHCI</title>
      <link>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7208686#M624</link>
      <description>&lt;P&gt;Download SCM from Infosight and reinstall the SCM. This should resolve the signature issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 06:18:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7208686#M624</guid>
      <dc:creator>BoonL</dc:creator>
      <dc:date>2024-03-12T06:18:20Z</dc:date>
    </item>
    <item>
      <title>Betreff: Secure Boot support for Alletra 6k dHCI</title>
      <link>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7226430#M625</link>
      <description>&lt;P&gt;I know this is an old thread but i just had this issue today and&amp;nbsp; with a bunch of DL380 Gen11 and an Alletra 6k (6030) which had been "&lt;U&gt;&lt;STRONG&gt;factory setup"&lt;/STRONG&gt;&lt;/U&gt;.&lt;BR /&gt;(We didnt do anything to the DL Compute nodes apart from racking the up and plugging them in - we assumed since that whole PCBE bundle was set up by the factory, things just work) - well ... assumptions in It don't go far &lt;LI-EMOJI id="lia_slightly-smiling-face" title=":leicht_lächelndes_Gesicht:"&gt;&lt;/LI-EMOJI&gt;&lt;/P&gt;&lt;P&gt;The &lt;STRONG&gt;errors&lt;/STRONG&gt; were:&lt;/P&gt;&lt;P&gt;- vCenter Alarms/Warnings like :&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;"Host TPM attestation alarm" or ""Unable to acquire ownership of TPM 2.0 device. Please clear TPM through the BIOS."&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Enabling Secure Boot in BIOS/RBSU leads to an ESX Pink Screen of death&lt;/P&gt;&lt;P&gt;It took me a whole day but I resolved it like this:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I first checked whether this ESX host was even capable of "Secure Boot" (which is a requirement of vSpheres TPM usage afaik) via SSH:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; /usr/lib/vmware/secureboot/bin/secureBoot.py -c&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Secure boot CANNOT be enabled: &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Failed to verify signatures of the following vib(s): [HPE-Storage-Connection-Service HPE-Storage-psp]. &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;All tardisks validated. All acceptance levels validated.&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;Which i've already seen on the Pink Screen, so i tried &lt;STRONG&gt;BoonL's&lt;/STRONG&gt; suggestion.&lt;/LI&gt;&lt;LI&gt;So i downloaded HPE-Storage-Connection-Manager-for-VMware-7.0-7.0.2-700014.zip from &lt;A href="https://infosight.hpe.com/" target="_blank" rel="noopener"&gt;https://infosight.hpe.com/&lt;/A&gt;&amp;nbsp; (Software Downloads), but not without checking the actual installed vibs with:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; esxcli software vib list | grep HPE-Storage&lt;BR /&gt;HPE-Storage-Connection-Service 7.0.2-700014&amp;nbsp;&amp;nbsp; HPE&amp;nbsp;&amp;nbsp; VMwareAccepted 2024-08-23&amp;nbsp; host&lt;BR /&gt;HPE-Storage-psp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 7.0.2-700014&amp;nbsp;&amp;nbsp; HPE&amp;nbsp;&amp;nbsp; VMwareAccepted 2024-08-23&amp;nbsp; host&lt;BR /&gt;&lt;/FONT&gt;So the (factory preinstalled) version was 7.0.2-700014 ... strange - thats the current version.&lt;/LI&gt;&lt;LI&gt;Anyways - again thanks to &lt;STRONG&gt;BoonL&lt;/STRONG&gt; - i just uploaded that zip to a datastore and uninstalled and reinstalled the VIBs:&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;esxcli software vib remove --vibname=HPE-Storage-Connection-Service&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;esxcli software vib remove --vibname=HPE-Storage-psp&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;esxcli software vib install --depot=&amp;lt;full_path_to_file&amp;gt;/HPE-Storage-Connection-Manager-for-VMware-7.0-7.0.2-700014.zip&lt;/FONT&gt;&lt;BR /&gt;Since no reboot was necessary, i checked again&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;&amp;gt; /usr/lib/vmware/secureboot/bin/secureBoot.py -c&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Secure boot CAN be enabled. &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;All vibs validated. &lt;/FONT&gt;&lt;FONT face="courier new,courier"&gt;All tardisks validated. All acceptance levels validated.&lt;BR /&gt;&lt;/FONT&gt;&lt;BR /&gt;Maybe someone with more knowledge than me can explain this.&lt;BR /&gt;Anyways, now i was able to enable "Secure Boot" in RBSU and the ESXi booted up nicely, albeit the vCenter errors were still there.&lt;BR /&gt;The Security Monitor on Datacenter level still read "Internal Error" ... **bleep**.&lt;/LI&gt;&lt;LI&gt;Many hours, trips to RBSU and reboots later i've stumbled across the RBSU Advanced TPM settings &lt;STRONG&gt;"TPM Storage Hierarchy"&lt;/STRONG&gt; and &lt;STRONG&gt;"TPM Endorsement"&lt;/STRONG&gt;&lt;BR /&gt;and i remembered some *cough*competitors*cough* KB article about "TPM history" - how they called it ..&lt;BR /&gt;I gave it a try and enabled both of them (dunno whether thats necessary).&lt;/LI&gt;&lt;LI&gt;This didn't instantly remediate the issue, but the vcenter logs at least didn't complain about "Internal Error".&lt;BR /&gt;The last thing that we needed to do is to rediscover some TPM magick by just disconnecting and reconnecting the questionable host.&lt;BR /&gt;Afterwards the errors/alarms/warnings were gone and the security state was "TPM attestation: passed"&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;I cannot explain, why this left the factory like this - imagine this system would have been shipped directly to the customer .... Big Frustration incoming !&lt;/P&gt;&lt;P&gt;Anyway .. maybe this helps someone in the future&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TLDR:&lt;BR /&gt;&lt;/STRONG&gt;- Reinstall SCM VIB (from infosight) on ESXi host (in maintenance mode)&lt;BR /&gt;- Reboot and enter RBSU&lt;BR /&gt;- Enable in RBSU: "Secure Boot", "TPM Endorsement", "TPM Storage Hierarchy", Save and Exit, then reboot&lt;BR /&gt;- When visible in vCenter, "Disconnect" and&amp;nbsp; "Connect" the host&lt;BR /&gt;- Clear TPM alarms&lt;BR /&gt;- Move on&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Oct 2024 18:24:11 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7226430#M625</guid>
      <dc:creator>WissfeldA</dc:creator>
      <dc:date>2024-10-01T18:24:11Z</dc:date>
    </item>
    <item>
      <title>Betreff: Secure Boot support for Alletra 6k dHCI</title>
      <link>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7235077#M626</link>
      <description>&lt;P&gt;WissfeldA, you saved my day!&amp;nbsp; Your descirption of the problem and solution worked like a charm,.&amp;nbsp; Thank you so much!&lt;/P&gt;&lt;P&gt;Just wondering if the next DHCI 1-Click updates will break ESXi.&lt;/P&gt;&lt;P&gt;Maybe one thing to consider for future DHCI 1-Click updates is to go into the BIOS to disable secure boot temporarily before starting the DHCI 1-Click updates.&lt;/P&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;P&gt;Luis&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 03:45:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7235077#M626</guid>
      <dc:creator>LuisSoares</dc:creator>
      <dc:date>2025-02-14T03:45:07Z</dc:date>
    </item>
    <item>
      <title>Betreff: Secure Boot support for Alletra 6k dHCI</title>
      <link>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7235112#M627</link>
      <description>&lt;P&gt;a) Arrays above 6.1.2.x would be able to handle servers with tpm enable. Earlier version of array OS, before 6.1.2.x, is not able to run SPP update when TPM is enabled.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;b) Advise against disabling TPM after secure boot has been enabled. That will likely lead to PSOD due to security violation.&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledge.broadcom.com/external/article?articleNumber=312109" target="_blank" rel="noopener"&gt;https://knowledge.broadcom.com/external/article?articleNumber=312109&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Feb 2025 09:38:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7235112#M627</guid>
      <dc:creator>BoonL</dc:creator>
      <dc:date>2025-02-14T09:38:35Z</dc:date>
    </item>
    <item>
      <title>Betreff: Secure Boot support for Alletra 6k dHCI</title>
      <link>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7235543#M628</link>
      <description>&lt;P&gt;For me, Secure Boot was already enabled. And since this was a fresh install, I didn't remove SCM, and jumped right into enabling...&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;* &lt;STRONG&gt;Enable in RBSU: "Secure Boot", "TPM Endorsement", "TPM Storage Hierarchy", Save and Exit, then reboot&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Upon reboot, the TMP message was gone!&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;THANK YOU!!!!&lt;/P&gt;</description>
      <pubDate>Thu, 20 Feb 2025 07:02:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/hpe-alletra-storage/secure-boot-support-for-alletra-6k-dhci/m-p/7235543#M628</guid>
      <dc:creator>OmarM21</dc:creator>
      <dc:date>2025-02-20T07:02:37Z</dc:date>
    </item>
  </channel>
</rss>

