Waethorn on Nostr: If you ever use Hyper-V to host Windows 11 VM's (or any VM using vTPM support), be ...
If you ever use Hyper-V to host Windows 11 VM's (or any VM using vTPM support), be sure to backup the server certificates - if you ever need to move the VM's to another system, the vTPM (a requirement for Win11) uses the certs in the server system cert store for encryption. You can back up the VM and port it over, but you'd have to disable the vTPM in the VM settings because the new system (or install of Windows, etc.) won't have the same cert, so you can't re-enable TPM support for it. New builds of Windows (like 24H2 coming soon) will likely fail the TPM check as a result. Luckily, you only have to do this once for a server machine as the certificates won't change over the lifespan of the host OS install. They don't tell you this when you do a VM backup through the Hyper-V mgmt console. I'm not sure, but I don't believe Windows Server Backup (part of RSAT) does automatic cert backups either.
Published at
2024-08-26 00:42:50Event JSON
{
"id": "d6029fa2c3d318e69604f6b3e8d56b6f3edd8215782b10777f67ee448a2f9a72",
"pubkey": "eddb5732903f27038c28ca47bc2fa3045990afa771ccf3eaedb86d55d94bc7fc",
"created_at": 1724632970,
"kind": 1,
"tags": [],
"content": "If you ever use Hyper-V to host Windows 11 VM's (or any VM using vTPM support), be sure to backup the server certificates - if you ever need to move the VM's to another system, the vTPM (a requirement for Win11) uses the certs in the server system cert store for encryption. You can back up the VM and port it over, but you'd have to disable the vTPM in the VM settings because the new system (or install of Windows, etc.) won't have the same cert, so you can't re-enable TPM support for it. New builds of Windows (like 24H2 coming soon) will likely fail the TPM check as a result. Luckily, you only have to do this once for a server machine as the certificates won't change over the lifespan of the host OS install. They don't tell you this when you do a VM backup through the Hyper-V mgmt console. I'm not sure, but I don't believe Windows Server Backup (part of RSAT) does automatic cert backups either.",
"sig": "4711607e9aa71c71da0ecae76e483c701fbda9ad76f04b793b4768f1e3f4cf8f46ccf49e60b08d7c3f1c40543dfcc0c15ef256971ceb122c74865a121d0eae1d"
}