ProLiant Servers (ML,DL,SL)
1823998 Members
5141 Online
109667 Solutions
New Discussion юеВ

HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

 
SOLVED
Go to solution
adam900331
Frequent Advisor

HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

Hy!

I want to run the latest SPP for my HPE DL380 Gen10 Plus server. The TPM 2.0 is enabled. I use the interactive firmware update option and when the SPP inventory run successfully I get the following warning:

Warning - A Trusted Platform Module (TPM) is enabled in this system.

If TPM features have been configured at the OS, please check that any recovery passwords provided for TPM features are available before continuing the firmware update. Updateing firmware may impact any security functionality enabled on the platform.

The server OS is VMware ESXi.

I dind't do anything like clik on "Ignore Warning". What should I do to update the firmwares safetily?

Thanks.

TPM.JPG

11 REPLIES 11
support_s
System Recommended

Query: HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

System recommended content:

1. HPE ProLiant DL380 Gen10 Plus Server with VMware vSphere Distributed Services Engine User Guide

2. HPE ProLiant DL380 Gen10-Datastores inaccessible after performing SPP SPP2021040.2021_0409.17 update via iLO Amplifier

 

Please click on "Thumbs Up/Kudo" icon to give a "Kudo".

 

Thank you for being a HPE valuable community member.


Accept or Kudo

adam900331
Frequent Advisor

Re: Query: HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

It is not answer for my question...
thutchings
HPE Pro

Re: Query: HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

Hello,

 

Are you performing the update to the server offline (booting from SPP)?  The following page in the HPSUM user guide gives you the various scenario's when using a TPM and the result for each. The page is indicating bitlocker, but the same type of information would apply to an ESXi host as well.

 

https://support.hpe.com/hpesc/public/docDisplay?docId=sd00002247en_us&docLocale=en_US&page=GUID-D7147C7F-2016-0901-0A67-000000000588.html

 

There should be no issue with selecting ignore warning, especially if the update is being performed offline.

 

Thanks



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
adam900331
Frequent Advisor

Re: Query: HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

Hy.

Yes, I update the firmware in offline mode.
adam900331
Frequent Advisor

Re: Query: HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

@thutchings 

Hy!

I have another question. Do I have to disable the TPM before boot SPP to update all firmware?

Thanks.

thutchings
HPE Pro
Solution

Re: Query: HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

Hello,

 

I would not recommend going into the BIOS and disabling the TPM. Selecting the checkbox "ignore warnings" you can see in the screenshot will allow it to continue past the TPM warning and the updates will proceed. 

 

Regards



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
Sunitha_Mod
Moderator

Re: HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

Hello @adam900331,

Let us know if you were able to resolve the issue.

If you have no further query and you are satisfied with the answer then kindly mark the topic as Solved so that it is helpful for all community members.



Thanks,
Sunitha G
I'm an HPE employee.
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
IRS77
Occasional Advisor

Re: HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

@thutchings 

I had made a Firmwareupdate on old MLB and have seen no warning. Because of an intermittend error, we replaced MLB. With new MLP i got a VMware POD indicating a security violation. After that we transfered the TPM from old MLB to the new MLB. Vut still VMware POD with security violation.

We found out that the new MLB was not responsible for our original problem. Therefore I installed old MLB back, with original old TPM. But still we the see POD.

Finally we installed a new TPM. Now the System was very slow at POST, and still we see POD. 

How can can we get out of the Problem? Can someone help me?

 

regards HEiko

 

thutchings
HPE Pro

Re: HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

Hello,

 

You should never move a TPM from a system onto a replacement system board. If you get a replacement system board, you should also get a replacement TPM.

 

In your situation, the problem may be due to having secure boot enabled in the BIOS. If any actions are taken that results in the keys being cleared from the TPM, then the chances are that secure boot will be disabled on the next boot. This will result in a purple screen on ESXi with the security violation message. To correct this, you may only need to go into the BIOS and under the secure boot options select to enable it again.

 

Regards



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo
IRS77
Occasional Advisor

Re: HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

@thutchings 

So if I had installed a new System Board, with a new TPM in one shoot, than VMware should have booted without intervention of VMware Admin?

Or is it still necessary to use HArdware/Security Recovery keys gathered during OS Installation?

The answer of this question is very important for us, because we have some political/sales impact here.

Please drop me an email

**personal info erased**

regards

 

Heiko

thutchings
HPE Pro

Re: HPE DL380 Gen10 Plus Service Pack for Proliant TPM warning

Hello,

 

I believe the following KB would cover this type of situation:

 

https://kb.vmware.com/s/article/81446

 

Following the replacement of a system board (and new TPM), the TPM may be disabled. It is also possible secure boot is disabled. For each of these, you should go into the BIOS and ensure they are configured to be enabled. The keys should automatically be pulled in again. A worse case scenario would likely involve following the procedure in the KB related to the ESXi installer and modifying the boot options for the existing install.

 

Regards



I work at HPE
HPE Support Center offers support for your HPE services and products when and how you need it. Get started with HPE Support Center today.
[Any personal opinions expressed are mine, and not official statements on behalf of Hewlett Packard Enterprise]
Accept or Kudo