6.7

Table Of Contents
Procedure
1 If the problem is the connection between the vCenter Server system and the KMS cluster, an alarm is
generated and the following message appears in the event log:
Host requires encryption mode enabled and the KMS cluster is not available.
You must manually check for the keys in the KMS cluster, and restore the connection to the KMS
cluster.
2 If keys are missing, an alarm is generated and the following message appears in the event log:
Host requires encryption mode enabled and the key is not available on the KMS
cluster.
You must manually recover the missing keys to the KMS cluster.
What to do next
If, after restoring connection to the KMS cluster, or manually recovering keys to the KMS cluster, the
host's encryption mode remains disabled, re-enable the host encryption mode. See Re-Enable ESXi Host
Encryption Mode.
Re-Enable ESXi Host Encryption Mode
Starting with vSphere 6.7, a vCenter Server alarm notifies you when an ESXi host's encryption mode has
become disabled. In vSphere 6.7, you can re-enable the host encryption mode.
Prerequisites
n
Verify that you have the required privileges: Cryptographic operations.Register host
n
Before re-enabling encryption mode, troubleshoot the cause and attempt to fix the problem manually.
Procedure
1 Connect to vCenter Server by using the vSphere Client.
2 Navigate to the ESXi host's Summary tab.
When the encryption mode is disabled, the Host Requires Encryption Mode Enabled alarm appears.
3 Decide if you want to either acknowledge the alarm, or reset the alarm to green but not re-enable the
host encryption mode now.
When you click either Acknowledge or Reset to green, the alarm goes way, but the host's
encryption mode remains disabled until you re-enable it.
4 Navigate to the ESXi host's Monitor tab and click Events to get more information on why encryption
mode is disabled.
Perform suggested troubleshooting before you re-enable the encryption mode.
5 On the Summary tab, click Enable Host Encryption Mode to re-enable host encryption.
A message appears, warning that encryption key data is transmitted to the host.
vSphere Security
VMware, Inc. 173