6.7

Table Of Contents
n
If you upgrade using the ISO the upgrade process saves the signatures of all new VIBs. This also
applies to upgrades of vSphere Update Manager that use the ISO.
If any old VIBs remain on the system the signatures of those VIBs still are not available and secure boot
is not possible.
For example, if the system uses a 3rd-party driver, and the VMware upgrade does not include a new
version of the driver VIB, then the old VIB remains on the system after the upgrade. In rare cases
VMware may drop ongoing development of a specific VIB without providing a new VIB that replaces or
obsoletes it, so the old VIB remains on the system after upgrade.
Note
UEFI secure boot also requires an up-to-date bootloader. This script does not check for an up-to-date
bootloader.
Prerequisites
n
Verify that the hardware supports UEFI secure boot.
n
Verify that all VIBs are signed with an acceptance level of at least PartnerSupported. If you include
VIBs at the CommunitySupported level, you cannot use secure boot.
Procedure
1 Upgrade the ESXi and run the following command.
/usr/lib/vmware/secureboot/bin/secureBoot.py -c
2 Check the output.
The output either includes Secure boot can be enabled or Secure boot CANNOT be enabled.
Required Free Space for System Logging
If you used Auto Deploy to install your ESXi 6.7 host, or if you set up a log directory separate from the
default location in a scratch directory on the VMFS volume, you might need to change your current log
size and rotation settings to ensure that enough space is available for system logging .
All vSphere components use this infrastructure. The default values for log capacity in this infrastructure
vary, depending on the amount of storage available and on how you have configured system logging.
Hosts that are deployed with Auto Deploy store logs on a RAM disk, which means that the amount of
space available for logs is small.
If your host is deployed with Auto Deploy, reconfigure your log storage in one of the following ways:
n
Redirect logs over the network to a remote collector.
n
Redirect logs to a NAS or NFS store.
If you redirect logs to non-default storage, such as a NAS or NFS store, you might also want to
reconfigure log sizing and rotations for hosts that are installed to disk.
VMware ESXi Upgrade
VMware, Inc. 71