VMware Cloud Community
richard833
Contributor
Contributor

TPM attestation error

Hi Having an issue with getting TPM to work on vsphere client 6.7.

Ran the following commands.

[root@10-124-142-233:~] /usr/lib/vmware/secureboot/bin/secureBoot.py -c

Secure boot can be enabled: All vib signatures verified. All tardisks validated. All acceptance levels validated

 

[root@10-124-142-233:~] grep tpm /var/log/vmkernel.log

2020-12-10T14:27:16.087Z cpu1:2097563)Activating Jumpstart plugin tpm.

2020-12-10T14:27:16.111Z cpu7:2098175)Loading module tpmdriver ...

2020-12-10T14:27:16.112Z cpu7:2098175)Elf: 2101: module tpmdriver has license VMware

2020-12-10T14:27:16.117Z cpu7:2098175)tpmDriver: TpmDriverFindIoMemory:332: Found TPM at base: 0xfed40000

2020-12-10T14:27:16.117Z cpu7:2098175)tpmDriver: Tpm2Init:1582: Activated locality 0

2020-12-10T14:27:16.117Z cpu7:2098175)tpmDriver: Tpm2CheckInterface:603: TPM is in FIFO mode.

2020-12-10T14:27:16.127Z cpu7:2098175)tpmDriver: Tpm2Init:1596: Initialization of TPM 2 impl done.

2020-12-10T14:27:16.138Z cpu7:2098175)tpmDriver: Tpm2LogVendor:1551: Vendor ID: NTC

2020-12-10T14:27:16.180Z cpu7:2098175)tpmDriver: Tpm2ResMgr_Init:1415: TPM 2.0 Resource manager initialized.

2020-12-10T14:27:16.222Z cpu7:2098175)Mod: 4962: Initialization of tpmdriver succeeded with module ID 96.

2020-12-10T14:27:16.222Z cpu7:2098175)tpmdriver loaded successfully.

2020-12-10T14:27:16.224Z cpu1:2097563)Jumpstart plugin tpm activated.

 

UEFI boot sequence is

AHCI Controller in Slot 1: EFI fixed boot Device 1

PXE Device 1: Embedded NIC 1 port 1Partitioin 1

Both options are enabled.

SECURE BOOT is enabled

TPM Security is On

TPM Hierarchy is Enabled.

TPM Advanced settings

TPM PPI Bypass Provision is Enabled

TPM PPI Bypass Clear is Enabled

TPM2 Algorithm Selection is SHA256

Intel TXT is OFF

 

VMware ESXi security log shows attestation "Failed" with Message "Internal Failure".

Any help is appreciated. See logs for additional details.

0 Kudos
1 Reply
scott28tt
VMware Employee
VMware Employee

@richard833 

Moderator: Moved to ESXi Discussions


-------------------------------------------------------------------------------------------------------------------------------------------------------------

Although I am a VMware employee I contribute to VMware Communities voluntarily (ie. not in any official capacity)
VMware Training & Certification blog
0 Kudos