6.5.1

Table Of Contents
For Linux virtual machines, VMware Host-Guest Filesystem is not supported in secure boot mode.
Remove VMware Host-Guest Filesystem from VMware Tools before you enable secure boot.
Note If you turn on secure boot for a virtual machine, you can load only signed drivers into that virtual
machine.
Prerequisites
You can enable secure boot only if all prerequisites are met. If prerequisites are not met, the check box is
not visible in the vSphere Web Client.
n
Verify that the virtual machine operating system and firmware support UEFI boot.
n
EFI firmware
n
Virtual hardware version 13 or later.
n
Operating system that supports UEFI secure boot.
Note You cannot upgrade a virtual machine that uses BIOS boot to a virtual machine that uses UEFI
boot. If you upgrade a virtual machine that already uses UEFI boot to an operating system that
supports UEFI secure boot, you can enable secure boot for that virtual machine.
n
Turn off the virtual machine. If the virtual machine is running, the check box is dimmed.
You need VirtualMachine.Config.Settings privileges to enable or disable UEFI secure boot for the
virtual machine.
Procedure
1 Log in to the vSphere Web Client and select the virtual machine.
2 In the Edit Settings dialog, open Boot Options, and ensure that firmware is set to EFI.
3 Click the Enable secure boot check box and click OK.
4 If you later want to disable secure boot, you can click the check box again.
When the virtual machine boots, only components with valid signatures are allowed. The boot process
stops with an error if it encounters a component with a missing or invalid signature.
vSphere Security
VMware, Inc. 129