Fortinet black logo

Administration Guide

Appendix D: vTPM for FortiPAM on VMware

Appendix D: vTPM for FortiPAM on VMware

To successfully enable vTPM, you must configure a key provider on the VMware vSphere client.

Caution

Ensure that vTPM is set up as part of the initial configuration (before powering on the FortiPAM-VM for the first time.)

To configure a key provider:
  1. Select the virtual appliance in the VMware vSphere client and go to Configure > Security > Key Providers.
  2. In Key Providers, from the Add dropdown, select Add Native Key Provider.
  3. In the Add Native Key Provider window:
    1. Enter a name for the native key provider.
    2. Deselect Use key provider only with TPM protected ESXi hosts.
    3. Select ADD KEY PROVIDER.
  4. Select the new key provider from the key providers list and then select BACK UP.

    The Back up Native Key Provider window opens.

  5. Select BACK UP KEY PROVIDER.

    The key provider is saved on your computer.

To enable vTPM for FortiPAM:
  1. Right-click the virtual appliance in the VMware vSphere client and select Edit Settings.

    Ensure that the Guest OS Version in VM Options tab is set to Other 4.x or later Linux (64-bit) or higher.

  2. In Edit Settings, click Add New Device and select Trusted Platform Module.
  3. Click OK.

Appendix D: vTPM for FortiPAM on VMware

To successfully enable vTPM, you must configure a key provider on the VMware vSphere client.

Caution

Ensure that vTPM is set up as part of the initial configuration (before powering on the FortiPAM-VM for the first time.)

To configure a key provider:
  1. Select the virtual appliance in the VMware vSphere client and go to Configure > Security > Key Providers.
  2. In Key Providers, from the Add dropdown, select Add Native Key Provider.
  3. In the Add Native Key Provider window:
    1. Enter a name for the native key provider.
    2. Deselect Use key provider only with TPM protected ESXi hosts.
    3. Select ADD KEY PROVIDER.
  4. Select the new key provider from the key providers list and then select BACK UP.

    The Back up Native Key Provider window opens.

  5. Select BACK UP KEY PROVIDER.

    The key provider is saved on your computer.

To enable vTPM for FortiPAM:
  1. Right-click the virtual appliance in the VMware vSphere client and select Edit Settings.

    Ensure that the Guest OS Version in VM Options tab is set to Other 4.x or later Linux (64-bit) or higher.

  2. In Edit Settings, click Add New Device and select Trusted Platform Module.
  3. Click OK.