As Broadcom updated their article https://knowledge.broadcom.com/external ... s-and.html about handling the secure boot certificate change for VMware VMs.
Starting with ESXi 8.0 U3j the VMs will have the platform key included. But the KEK and DB needs to be done by the guest OS or customer.
Customer's Responsibility:
- For PK updates: Customers should execute PK update based on VMware guidance.
- For KEK and DB updates: Customers should follow their respective OS vendor's guidance to update them natively from within the guest OS.
Can you provide any guidance how to handle this in Veeam Appliances like Hardened Repository or Infrastructure Appliance?
Is this handled through Veeam Updates, or do we have to do it ourselves?
Do you see expired certificates on you VSA appliances? Did you perform the actions suggested in the article?
All keys, if expired, are to be updated on ESXi v U3j (P09) or later, as per the guidance in the article you quoted.
It's a semi-automated process; I see nothing needs to be done from inside the guest.