{"id":7599,"date":"2024-05-15T10:54:55","date_gmt":"2024-05-15T07:54:55","guid":{"rendered":"https:\/\/sunucucozumleri.com\/?p=7599"},"modified":"2024-09-16T20:48:35","modified_gmt":"2024-09-16T17:48:35","slug":"the-new-host-tpm-endorsement-key-doesnt-match-the-one-stored-in-the-db","status":"publish","type":"post","link":"https:\/\/sunucucozumleri.com\/blog\/the-new-host-tpm-endorsement-key-doesnt-match-the-one-stored-in-the-db\/","title":{"rendered":"The new host TPM endorsement key doesn&#8217;t match the one stored in the DB Hatas\u0131n\u0131n \u00c7\u00f6z\u00fcm\u00fc"},"content":{"rendered":"<p>Sistem kart\u0131n\u0131 TPM onayl\u0131 bir ana bilgisayarda de\u011fi\u015ftirdikten sonra vCenter&#8217;da yeni bir alarm olu\u015ftu; Google&#8217;\u0131n bana yard\u0131mc\u0131 olamayaca\u011f\u0131 bir alarm.<\/p>\n<p>&#8220;Yeni ana <a href=\"https:\/\/sunucucozumleri.com\/blog\/bilgisayar-nasil-kullanilir\/\">bilgisayar<\/a> TPM onay anahtar\u0131, veritaban\u0131nda depolananla e\u015fle\u015fmiyor&#8221;<\/p>\n<p>Bu, vCenter 6.7 ve vSphere\/vSAN 6.7 U3 ana bilgisayar\u0131ndad\u0131r. Dell R740 donan\u0131m\u0131.<\/p>\n<p>Do\u011fal olarak ilk \u00f6nce Google&#8217;a bakt\u0131m ve ikisi de \u00e7al\u0131\u015fan bir sayfa olmayan ve ikisi de VMWare KB olmayan 2 sonu\u00e7 buldu\u011fumda \u015fa\u015f\u0131rd\u0131m. \u0130\u015fte o zaman bir sonraki blog yaz\u0131m\u0131n ne hakk\u0131nda olaca\u011f\u0131n\u0131 biliyordum. \u00d6nce alarm\u0131 nas\u0131l \u00e7\u00f6zece\u011fimi bulmam gerekiyordu. Neyse ki a\u015f\u0131r\u0131 karma\u015f\u0131k de\u011fil.<\/p>\n<p>Bu noktaya kadar TPM uygulayan herkesin onaylayabilece\u011fi gibi sorun, sonradan bak\u0131ld\u0131\u011f\u0131nda olduk\u00e7a a\u00e7\u0131kt\u0131r. vCenter \u00f6nceki TPM yongas\u0131na g\u00fcveniyordu. O \u00e7ipi de\u011fi\u015ftirdin. \u015eimdi vCenter &#8220;bu d\u00fc\u015f\u00fcnd\u00fc\u011f\u00fcm <a href=\"https:\/\/sunucucozumleri.com\/blog\/frontpage\/\">sunucu<\/a> de\u011fil, burada tuhaf bir \u015feyler oluyor, kontrol etmelisin&#8221; diyor. Ancak, KB ve t\u0131klat\u0131lacak Kolay d\u00fc\u011fme olmad\u0131\u011f\u0131ndan alarm\u0131 d\u00fczeltmek i\u00e7in ne yap\u0131lmal\u0131?<\/p>\n<p>Y\u00fcksek d\u00fczeydeki \u00e7\u00f6z\u00fcm, ana bilgisayar\u0131 envanterden \u00e7\u0131karmak ve sonra geri eklemektir. Bu eski kay\u0131tlar\u0131 kald\u0131racak ve yepyeni bir cihaz gibi davran\u0131ld\u0131\u011f\u0131 i\u00e7in yeni kay\u0131tlara g\u00fcvenmeye ba\u015flayacak.<\/p>\n<p>Sistem, t\u00fcm VMKernel ba\u011flant\u0131 noktalar\u0131n\u0131n ba\u011fl\u0131 bir dvswitch&#8217;te oldu\u011fu bir vSAN k\u00fcmesinin par\u00e7as\u0131 oldu\u011fundan, benim i\u00e7in bunu s\u00f6ylemek yapmaktan daha kolayd\u0131, bu nedenle, hizmetten \u00e7\u0131kar\u0131lmaya uygun \u015fekilde haz\u0131r hale getirilmesi biraz \u00e7al\u0131\u015fma gerektirdi. Ancak bu i\u015f tamamland\u0131ktan sonra envanterden kald\u0131r\u0131l\u0131p yeni bir ana bilgisayar olarak eklendi.<\/p>\n<h3>Di\u011fer Y\u00f6ntemler;<\/h3>\n<p>\u0130lk kurulumdan sonra ESXi ana bilgisayar\u0131n\u0131za tak\u0131lan\u00a0<a href=\"https:\/\/kb.vmware.com\/kb\/2148536\" target=\"_blank\" rel=\"noopener nofollow\">desteklenen bir G\u00fcvenilir Platform Mod\u00fcl\u00fc (TPM)<\/a>\u00a0cihaz\u0131n\u0131z varsa ve TPM yongas\u0131n\u0131 de\u011fi\u015ftirirseniz ve\/veya sistem BIOS&#8217;unda TPM anahtarlar\u0131n\u0131 s\u0131f\u0131rlarsan\u0131z, birka\u00e7 TPM alarm\u0131 bulabilirsiniz.\u00a0vCenter Sunucunuzda olu\u015fturulanlar \u015funlar\u0131 i\u00e7erir:<\/p>\n<ul>\n<li>Ana makine TPM do\u011frulama alarm\u0131<\/li>\n<li>TPM \u015eifreleme Kurtarma Anahtar\u0131 Yedekleme Alarm\u0131<\/li>\n<li>Yeni ana makine TPM onay anahtar\u0131, veritaban\u0131nda depolananla e\u015fle\u015fmiyor<\/li>\n<\/ul>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-7601\" src=\"https:\/\/sunucucozumleri.com\/wp-content\/uploads\/2024\/05\/The-new-host-TPM-endorsement-key-doesnt-match-the-one-stored-in-the-DB-1.webp\" alt=\"\" width=\"768\" height=\"526\" title=\"\" srcset=\"\/\/sunucucozumleri.com\/blog\/wp-content\/uploads\/2024\/05\/The-new-host-TPM-endorsement-key-doesnt-match-the-one-stored-in-the-DB-1.webp 768w, \/\/sunucucozumleri.com\/blog\/wp-content\/uploads\/2024\/05\/The-new-host-TPM-endorsement-key-doesnt-match-the-one-stored-in-the-DB-1-300x205.webp 300w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/><br \/>\nYak\u0131n zamanda sistem BIOS&#8217;undaki TPM anahtarlar\u0131n\u0131 temizledikten sonra bunu laboratuvar\u0131mda \u00e7\u00f6zmek zorunda kald\u0131m, bu yapt\u0131\u011f\u0131m baz\u0131 testler i\u00e7indi, ancak vCenter Server&#8217;\u0131n ESXi ana bilgisayar\u0131yla ili\u015fkili \u00f6nceki onay anahtarlar\u0131n\u0131 temizlemesini nas\u0131l sa\u011flayaca\u011f\u0131m\u0131 \u00e7\u00f6zemedim. .<\/p>\n<p>Biraz ara\u015ft\u0131rd\u0131ktan sonra, TPM yongas\u0131n\u0131n yerini alan bu TPM alarmlar\u0131n\u0131 g\u00f6rebilece\u011finiz yukar\u0131da bahsetti\u011fim senaryolardan birine \u00e7\u00f6z\u00fcm sunan bu\u00a0<a href=\"https:\/\/kb.vmware.com\/kb\/81446\" target=\"_blank\" rel=\"noopener nofollow\">VMware KB 81446<\/a>\u00a0ile kar\u015f\u0131la\u015ft\u0131m , ancak i\u015f ak\u0131\u015f\u0131n\u0131n da ayn\u0131 oldu\u011funu \u00f6\u011frendim. TPM anahtarlar\u0131n\u0131 temizlediyseniz ve ESXi&#8217;yi yeniden y\u00fcklemeden \u00f6nce yeni anahtarlar olu\u015fturulduysa ge\u00e7erlidir. KB&#8217;de, geri bildirimde zaten payla\u015ft\u0131\u011f\u0131m baz\u0131 ayr\u0131nt\u0131lar eksikti ve a\u015fa\u011f\u0131da payla\u015ft\u0131\u011f\u0131m daha ak\u0131c\u0131 bir y\u00f6ntem oldu\u011funu d\u00fc\u015f\u00fcn\u00fcyorum.<\/p>\n<p><strong>Ad\u0131m 1<\/strong>\u00a0&#8211; Mevcut ESXi ana bilgisayar\u0131n\u0131 vCenter Sunucu envanterinden kald\u0131rman\u0131z gerekecek<\/p>\n<p><strong>Ad\u0131m 2<\/strong>\u00a0&#8211; ESXi ana bilgisayar\u0131na SSH g\u00f6nderin ve a\u015fa\u011f\u0131daki ESXCLI komutunu kullanarak \u015fifreleme kurtarma anahtar\u0131n\u0131 (96 karakterli) al\u0131n:<\/p>\n<p class=\"terminal\">esxcli system settings encryption recovery list<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-7602\" src=\"https:\/\/sunucucozumleri.com\/wp-content\/uploads\/2024\/05\/resolving-esxi-tpm-alarms-after-replac-tpm-chip-or-resetting-tpms-keys-1.webp\" alt=\"\" width=\"768\" height=\"71\" title=\"\" srcset=\"\/\/sunucucozumleri.com\/blog\/wp-content\/uploads\/2024\/05\/resolving-esxi-tpm-alarms-after-replac-tpm-chip-or-resetting-tpms-keys-1.webp 768w, \/\/sunucucozumleri.com\/blog\/wp-content\/uploads\/2024\/05\/resolving-esxi-tpm-alarms-after-replac-tpm-chip-or-resetting-tpms-keys-1-300x28.webp 300w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/><br \/>\n<strong>Ad\u0131m 3<\/strong>\u00a0&#8211; Kullan\u0131c\u0131ya, ESXi \u00f6ny\u00fcklemesi s\u0131ras\u0131nda SHIFT+O se\u00e7ene\u011fine basarak 96 karakterlik anahtar\u0131 manuel olarak yazmas\u0131n\u0131 bildiren VMware KB&#8217;den farkl\u0131 olarak, daha basit bir y\u00f6ntem, ESXi boot.cfg dosyas\u0131n\u0131 d\u00fczenlemek ve cryptoRecoveryKey\u00a0<strong>se\u00e7ene\u011fini<\/strong>\u00a0eklemektir .\u00a0ve daha sonra, 96 karakterlik anahtar\u0131 manuel olarak yazmay\u0131 tercih etmedi\u011finiz s\u00fcrece, bir sonraki a\u00e7\u0131l\u0131\u015fta bunu kald\u0131rmak, bu da y\u00fcksek bir yaz\u0131m hatas\u0131 olas\u0131l\u0131\u011f\u0131na yol a\u00e7abilir.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-7603\" src=\"https:\/\/sunucucozumleri.com\/wp-content\/uploads\/2024\/05\/resolving-esxi-tpm-alarms-after-replac-tpm-chip-or-resetting-tpms-keys-2.webp\" alt=\"\" width=\"768\" height=\"175\" title=\"\" srcset=\"\/\/sunucucozumleri.com\/blog\/wp-content\/uploads\/2024\/05\/resolving-esxi-tpm-alarms-after-replac-tpm-chip-or-resetting-tpms-keys-2.webp 768w, \/\/sunucucozumleri.com\/blog\/wp-content\/uploads\/2024\/05\/resolving-esxi-tpm-alarms-after-replac-tpm-chip-or-resetting-tpms-keys-2-300x68.webp 300w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/><\/p>\n<p>\/bootbank\/boot.cfg dosyas\u0131n\u0131 d\u00fczenleyin ve \u00f6nceki ad\u0131mdaki\u00a0<strong>cryptoRecoveryKey=[RECOVERY_KEY] dosyas\u0131n\u0131<\/strong>\u00a0kernelopt sat\u0131r\u0131na ekleyin ve ard\u0131ndan de\u011fi\u015fikliklerinizi kaydedin.<\/p>\n<p><strong>Ad\u0131m 4<\/strong>\u00a0&#8211; Son olarak ESXi host&#8217;u yeniden ba\u015flat\u0131n ve ard\u0131ndan \/bootbank\/boot.cfg dosyas\u0131na yapt\u0131\u011f\u0131n\u0131z giri\u015fi kald\u0131r\u0131n ve ard\u0131ndan ESXi host&#8217;u vCenter Server envanterine yeniden ekleyin. TPM alarm\u0131n\u0131 yine bir kez daha g\u00f6rebilirsiniz, ancak devam edin ve alarm\u0131 temizleyin; sonraki yeniden ba\u015flatmalarda alarm art\u0131k g\u00f6r\u00fcnmeyecektir.<\/p>\n<p>Ayr\u0131ca vSphere Cluster&#8217;a giderek ve Monit\u00f6r-&gt;G\u00fcvenlik alt\u0131nda her \u015feyin beklendi\u011fi gibi \u00e7al\u0131\u015ft\u0131\u011f\u0131n\u0131 do\u011frulayabilirsiniz; art\u0131k ESXi ana makinenizin vCenter Server taraf\u0131ndan ba\u015far\u0131yla onayland\u0131\u011f\u0131n\u0131 ve \u00f6nceki onay anahtar\u0131n\u0131n g\u00fcncellendi\u011fini g\u00f6rmelisiniz.<\/p>\n<p><img decoding=\"async\" class=\"alignnone size-full wp-image-7604\" src=\"https:\/\/sunucucozumleri.com\/wp-content\/uploads\/2024\/05\/resolving-esxi-tpm-alarms-after-replac-tpm-chip-or-resetting-tpms-keys-3.webp\" alt=\"\" width=\"768\" height=\"388\" title=\"\" srcset=\"\/\/sunucucozumleri.com\/blog\/wp-content\/uploads\/2024\/05\/resolving-esxi-tpm-alarms-after-replac-tpm-chip-or-resetting-tpms-keys-3.webp 768w, \/\/sunucucozumleri.com\/blog\/wp-content\/uploads\/2024\/05\/resolving-esxi-tpm-alarms-after-replac-tpm-chip-or-resetting-tpms-keys-3-300x152.webp 300w\" sizes=\"(max-width: 768px) 100vw, 768px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sistem kart\u0131n\u0131 TPM onayl\u0131 bir ana bilgisayarda de\u011fi\u015ftirdikten sonra vCenter&#8217;da yeni bir alarm olu\u015ftu; Google&#8217;\u0131n bana yard\u0131mc\u0131 olamayaca\u011f\u0131 bir alarm. &#8220;Yeni ana bilgisayar TPM onay anahtar\u0131, veritaban\u0131nda depolananla e\u015fle\u015fmiyor&#8221; Bu, vCenter 6.7 ve vSphere\/vSAN 6.7 U3 ana bilgisayar\u0131ndad\u0131r. Dell R740 donan\u0131m\u0131. Do\u011fal olarak ilk \u00f6nce Google&#8217;a bakt\u0131m ve ikisi de \u00e7al\u0131\u015fan bir sayfa olmayan ve &hellip;<\/p>\n","protected":false},"author":1,"featured_media":7600,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[15],"tags":[],"class_list":["post-7599","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-esxi"],"acf":[],"_links":{"self":[{"href":"https:\/\/sunucucozumleri.com\/blog\/wp-json\/wp\/v2\/posts\/7599","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sunucucozumleri.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sunucucozumleri.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sunucucozumleri.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sunucucozumleri.com\/blog\/wp-json\/wp\/v2\/comments?post=7599"}],"version-history":[{"count":0,"href":"https:\/\/sunucucozumleri.com\/blog\/wp-json\/wp\/v2\/posts\/7599\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sunucucozumleri.com\/blog\/wp-json\/wp\/v2\/media\/7600"}],"wp:attachment":[{"href":"https:\/\/sunucucozumleri.com\/blog\/wp-json\/wp\/v2\/media?parent=7599"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sunucucozumleri.com\/blog\/wp-json\/wp\/v2\/categories?post=7599"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sunucucozumleri.com\/blog\/wp-json\/wp\/v2\/tags?post=7599"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}