Comprehensive data protection for all workloads
Post Reply
mengl
Service Provider
Posts: 26
Liked: 18 times
Joined: Oct 19, 2018 7:02 am
Full Name: Michael Engl
Location: Germany
Contact:

Secure Boot Certificate Expiration in Veeam Appliances

Post by mengl »

Hello together,

As Broadcom updated their article https://knowledge.broadcom.com/external ... s-and.html about handling the secure boot certificate change for VMware VMs.
Starting with ESXi 8.0 U3j the VMs will have the platform key included. But the KEK and DB needs to be done by the guest OS or customer.
Customer's Responsibility:
- For PK updates: Customers should execute PK update based on VMware guidance.
- For KEK and DB updates: Customers should follow their respective OS vendor's guidance to update them natively from within the guest OS.

Can you provide any guidance how to handle this in Veeam Appliances like Hardened Repository or Infrastructure Appliance?
Is this handled through Veeam Updates, or do we have to do it ourselves?

Thanks
vnikiforov
Veeam Software
Posts: 157
Liked: 55 times
Joined: Aug 17, 2022 5:03 am
Full Name: Vladimir Nikiforov
Location: Romania
Contact:

Re: Secure Boot Certificate Expiration in Veeam Appliances

Post by vnikiforov »

Hello, Michael,

Do you see expired certificates on you VSA appliances? Did you perform the actions suggested in the article?
All keys, if expired, are to be updated on ESXi v U3j (P09) or later, as per the guidance in the article you quoted.
It's a semi-automated process; I see nothing needs to be done from inside the guest.
---
BR,
Vladimir
Veeam Software
Post Reply

Who is online

Users browsing this forum: No registered users and 388 guests