{"id":107727,"date":"2023-02-17T12:11:21","date_gmt":"2023-02-17T03:11:21","guid":{"rendered":"https:\/\/softantenna.com\/blog\/?p=107727"},"modified":"2023-02-17T12:11:21","modified_gmt":"2023-02-17T03:11:21","slug":"patch-tuesday-breaks-vmware-secure-boot","status":"publish","type":"post","link":"https:\/\/softantenna.com\/blog\/patch-tuesday-breaks-vmware-secure-boot\/","title":{"rendered":"\u6708\u4f8b\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u3067\u3055\u3089\u306b\u30c8\u30e9\u30d6\u30eb\u3002VMware\u306e\u30bb\u30ad\u30e5\u30a2\u30d6\u30fc\u30c8\u304c\u58ca\u308c\u3066\u8d77\u52d5\u4e0d\u53ef\u80fd\u306b\u306a\u308b\u554f\u984c\u304c\u5831\u544a"},"content":{"rendered":"<p><img decoding=\"async\" style=\"display:block; margin-left:auto; margin-right:auto;\" src=\"https:\/\/softantenna.com\/blog\/wp-content\/uploads\/2023\/02\/s_20230217_115733.jpg\" alt=\"S 20230217 115733\" title=\"s_20230217_115733.jpg\" border=\"0\" width=\"1155\" height=\"743\" \/><\/p>\n<p>\u5148\u65e5\u516c\u958b\u3055\u308c\u305f2\u6708\u306e\u6708\u4f8b\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0<a href=\"https:\/\/support.microsoft.com\/en-us\/topic\/february-14-2023-kb5022842-os-build-20348-1547-be155955-29f7-47c4-855c-34bd43895940\">KB5022842<\/a>\u3092\u3001\u7279\u5b9a\u306e\u74b0\u5883\u3067\u5b9f\u884c\u3057\u3066\u3044\u308b\u4eee\u60f3Windows Server 2022\u306b\u9069\u7528\u3059\u308b\u3068\u3001\u4eee\u60f3\u30de\u30b7\u30f3\u304c\u8d77\u52d5\u3057\u306a\u304f\u306a\u308b\u3068\u3044\u3046\u554f\u984c\u304c\u767a\u751f\u3057\u3066\u3044\u308b\u4e8b\u304c\u308f\u304b\u308a\u307e\u3057\u305f(<a href=\"https:\/\/www.neowin.net\/news\/more-patch-tuesday-troubles-ensue-as-secure-boot-breaks-on-vmware-leading-to-boot-fails\/\">Neowin<\/a>)\u3002<\/p>\n<p>\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u306e\u30b5\u30dd\u30fc\u30c8\u30da\u30fc\u30b8\u306b\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u60c5\u5831\u304c\u63b2\u8f09\u3055\u308c\u3066\u3044\u307e\u3059\u3002vSphere ESXi 7.0\u4ee5\u4e0b\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u5b9f\u884c\u3057\u3066\u3044\u308bSecure Boot \u304c\u6709\u52b9\u306a Windows Server 2022\u306eVM \u306b\u306e\u307f\u5f71\u97ff\u3059\u308b\u305d\u3046\u3067\u3059\u3002<\/p>\n<blockquote><p>\nAfter installing this update on guest virtual machines (VMs) running Windows Server 2022 on some versions of VMware ESXi, Windows Server 2022 might not start up. Only Windows Server 2022 VMs with Secure Boot enabled are affected by this issue. Affected versions of VMware ESXi are versions vSphere ESXi 7.0.x and below.<\/p>\n<p>\u3053\u306e\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0\u3092 VMware ESXi\u306e\u4e00\u90e8\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3067 Windows Server 2022 \u3092\u5b9f\u884c\u3057\u3066\u3044\u308b\u30b2\u30b9\u30c8\u4eee\u60f3\u30de\u30b7\u30f3(VM)\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3059\u308b\u3068\u3001Windows Server 2022 \u304c\u8d77\u52d5\u3057\u306a\u304f\u306a\u308b\u3053\u3068\u304c\u3042\u308a\u307e\u3059\u3002\u3053\u306e\u554f\u984c\u306f\u3001Secure Boot \u304c\u6709\u52b9\u306a Windows Server 2022\u306eVM \u306b\u306e\u307f\u5f71\u97ff\u3057\u307e\u3059\u3002VMware ESXi\u306e\u5f71\u97ff\u3092\u53d7\u3051\u308b\u30d0\u30fc\u30b8\u30e7\u30f3\u306f\u3001vSphere ESXi 7.0.x\u304a\u3088\u3073\u305d\u308c\u4ee5\u4e0b\u306e\u30d0\u30fc\u30b8\u30e7\u30f3\u3067\u3059\u3002\n<\/p><\/blockquote>\n<p>VMware\u306f<a href=\"https:\/\/kb.vmware.com\/s\/article\/90947\">\u30a2\u30c9\u30d0\u30a4\u30b6\u30ea<\/a>\u3067\u3001\u3053\u306e\u554f\u984c\u306e\u75c7\u72b6\u3084\u7279\u5b9a\u65b9\u6cd5\u3092\u8a73\u3057\u304f\u8aac\u660e\u3057\u3066\u3044\u307e\u3059\u3002<\/p>\n<blockquote>\n<p><strong>Symptoms<\/strong><\/p>\n<p>After installing Windows Server 2022 update KB5022842 (OS Build 20348.1547), guest OS can not boot up when virtual machine(s) configured with secure boot enabled running on vSphere ESXi 6.7 U2\/U3 or vSphere ESXi 7.0.x.<\/p>\n<p>In VM vmware.log, there is \u2018Image DENIED\u2019 info like the below:<\/p>\n<pre><code class=\"hljs language-yaml\"><span class=\"hljs-number\">2023-02-15T05:34:31.379Z<\/span> <span class=\"hljs-string\">In(05)<\/span> <span class=\"hljs-string\">vcpu-0<\/span> <span class=\"hljs-string\">-<\/span>&nbsp;<span class=\"hljs-attr\">SECUREBOOT: Signature:<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">in<\/span> <span class=\"hljs-string\">db,<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">in<\/span> <span class=\"hljs-string\">dbx,<\/span>&nbsp;<span class=\"hljs-number\">1<\/span> <span class=\"hljs-string\">unrecognized,<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">unsupported<\/span> <span class=\"hljs-string\">alg.<\/span>\n<span class=\"hljs-number\">2023-02-15T05:34:31.379Z<\/span> <span class=\"hljs-string\">In(05)<\/span> <span class=\"hljs-attr\">vcpu-0 - Hash:<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">in<\/span> <span class=\"hljs-string\">db,<\/span> <span class=\"hljs-number\">0<\/span> <span class=\"hljs-string\">in<\/span> <span class=\"hljs-string\">dbx.<\/span>\n<span class=\"hljs-number\">2023-02-15T05:34:31.379Z<\/span> <span class=\"hljs-string\">In(05)<\/span> <span class=\"hljs-string\">vcpu-0<\/span> <span class=\"hljs-string\">-<\/span>&nbsp;<span class=\"hljs-string\">SECUREBOOT:<\/span>&nbsp;<span class=\"hljs-string\">Image<\/span> <span class=\"hljs-string\">DENIED.<\/span><\/code><\/pre>\n<p>To identify the location of vmware.log files:<\/p>\n<ol>\n<li>Establish an SSH session to your host. For ESXi hosts<\/li>\n<li>Log in to the ESXi Host CLI using root account.<\/li>\n<li>To list the locations of the configuration files for the virtual machines registered on the host, run the below command:\n<pre><code class=\"hljs language-shell\"><span class=\"hljs-meta prompt_\">#<\/span><span class=\"language-bash\">vim-cmd vmsvc\/getallvms | grep -i <span class=\"hljs-string\">\"VM_Name\"<\/span><\/span><\/code><\/pre>\n<\/p>\n<\/li>\n<li>The vmware.log file is located in virtual machine folder along with the vmx file.<\/li>\n<li>Record the location of the .vmx configuration file for the virtual machine you are troubleshooting. For example:\n<pre><code class=\"hljs language-bash\">\/vmfs\/volumes\/xxxxxxxx-xxxxxxx-c1d2-111122223333\/vm1\/vm1.vmx\n\/vmfs\/volumes\/xxxxxxxx-xxxxxxx-c1d2-111122223333\/vm1\/vmware.log<\/code><\/pre>\n<\/li>\n<\/ol>\n<\/blockquote>\n<p>\u6b8b\u5ff5\u306a\u304c\u3089\u3001\u3053\u306e\u554f\u984c\u306f\u73fe\u6642\u70b9\u3067\u306f\u4fee\u6b63\u3055\u308c\u3066\u3044\u307e\u305b\u3093\u304c\u3001vSphere ESXi\u3092\u30d0\u30fc\u30b8\u30e7\u30f38.0\u306b\u30a2\u30c3\u30d7\u30b0\u30ec\u30fc\u30c9\u3059\u308b\u3053\u3068\u3067\u56de\u907f\u3059\u308b\u3053\u3068\u304c\u53ef\u80fd\u3067\u3059\u3002<\/p>\n<blockquote>\n<p><strong>Resolution<\/strong><\/p>\n<p>Currently there is no resolution for virtual machines running on vSphere ESXi 6.7 U2\/U3 and vSphere ESXi 7.0.x. However the issue doesn't exist with virtual machines running on vSphere ESXi 8.0.x.<\/p>\n<p><strong>Workaround<\/strong><\/p>\n<p>There are three methods to avoid this issue<\/p>\n<ol>\n<li>Upgrade the ESXi Host where the virtual machine in question is running to vSphere ESXi 8.0<\/li>\n<li>Disable \"Secure Boot\" on the VMs.<\/li>\n<li>Do not install the KB5022842 patch on any Windows 2022 Server virtual machine until the issue is resolved.<\/li>\n<\/ol>\n<\/blockquote>\n<p>\u554f\u984c\u306e\u8a73\u7d30\u306f<a href=\"https:\/\/kb.vmware.com\/s\/article\/90947\">\u3053\u3061\u3089<\/a>\u3067\u78ba\u8a8d\u53ef\u80fd\u3067\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u5148\u65e5\u516c\u958b\u3055\u308c\u305f2\u6708\u306e\u6708\u4f8b\u66f4\u65b0\u30d7\u30ed\u30b0\u30e9\u30e0KB5022842\u3092\u3001\u7279\u5b9a\u306e\u74b0\u5883\u3067\u5b9f\u884c\u3057\u3066\u3044\u308b\u4eee\u60f3Windows Server 2022\u306b\u9069\u7528\u3059\u308b\u3068\u3001\u4eee\u60f3\u30de\u30b7\u30f3\u304c\u8d77\u52d5\u3057\u306a\u304f\u306a\u308b\u3068\u3044\u3046\u554f\u984c\u304c\u767a\u751f\u3057\u3066\u3044\u308b\u4e8b\u304c\u308f\u304b\u308a\u307e\u3057\u305f(Neowin [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":107728,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"swell_btn_cv_data":"","footnotes":""},"categories":[3],"tags":[33],"class_list":["post-107727","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-windows","tag-vmware"],"_links":{"self":[{"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/posts\/107727","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/comments?post=107727"}],"version-history":[{"count":0,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/posts\/107727\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/media\/107728"}],"wp:attachment":[{"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/media?parent=107727"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/categories?post=107727"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/softantenna.com\/blog\/wp-json\/wp\/v2\/tags?post=107727"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}