7.5 ESXi Host Configuration: Time, Services, Product Locker & Boot Options

Key Takeaways

  • An ESXi host's clock can be set manually or synchronized with NTP or with the Precision Time Protocol (PTP), which supports software and hardware timestamping for higher accuracy.

  • Host services such as SSH, the ESXi Shell, NTP, and PTP each have a startup policy (start and stop with the host, manually, or with port usage) under Configure > System > Services.

  • The Product Locker holds VMware Tools ISO images; pointing UserVars.ProductLockerLocation on every host at one shared-datastore directory centralizes VMware Tools updates.

  • Quick Boot is enabled in the vSphere Lifecycle Manager remediation settings and restarts ESXi without a full hardware reboot on compatible platforms.

  • To boot ESXi securely, enable UEFI Secure Boot in the server firmware after checking the host with /usr/lib/vmware/secureboot/bin/secureBoot.py -c, and use a TPM 2.0 for attestation.

Last updated: September 2026

7.5 ESXi Host Configuration: Time, Services, Product Locker & Boot Options

Objective 4.19 lists five ESXi setup tasks: time, services, Product Locker, lockdown mode, and the firewall. Lockdown mode and the firewall are covered in Section 6.4. This section covers the rest, plus the boot options in objective 4.17.

Time Configuration (4.19.1)

Accurate time underpins everything in vSphere. SSO tokens, Kerberos and LDAPS authentication, certificate validity, vSAN and HA coordination, and log correlation all depend on it. Configure time under Host > Configure > System > Time Configuration:

MethodWhen to Use It
ManualLabs only; the clock drifts
NTP (Network Time Protocol)The standard choice: list one or more NTP servers and set the NTP service to start and stop with the host
PTP (Precision Time Protocol)Workloads that need sub-millisecond accuracy; supports software or hardware timestamping on a PTP-capable NIC for highly accurate synchronization

Good practice:

  • Point ESXi hosts, vCenter Server (configured in the VAMI), and your domain controllers or identity provider at the same time source. Use the same mechanism across the environment so authentication and logs line up.
  • From the command line, ESXi 7.0 and later can configure NTP with esxcli system ntp set --server=<ntp-fqdn> --enabled=true.
  • Host Profiles can enforce the same NTP settings across a cluster (Section 7.3).

Service Configuration (4.19.2)

Under Host > Configure > System > Services, each service can be started, stopped, or restarted, and has a startup policy:

Startup PolicyBehavior
Start and stop with hostAlways running (typical for NTP)
Start and stop manuallyRuns only when an admin starts it (recommended for SSH and ESXi Shell)
Start and stop with port usageStarts when its firewall ruleset's ports are opened

Security-relevant services include SSH (TSM-SSH), the ESXi Shell (TSM), the CIM server, SNMP, NTP, and PTP. Keep SSH and the ESXi Shell stopped unless you are troubleshooting, and pair them with the shell timeouts described in Section 6.4.

Product Locker (4.19.3)

The Product Locker is the location on each host that holds the VMware Tools ISO images (and floppy images) that VMs mount when you install or upgrade Tools. By default it lives in the host's ESX-OSData volume (/productLocker). With many hosts, that means many copies to keep current.

Centralize it:

  1. Create a dedicated directory on a shared datastore that is used only for the Tools repository, for example /vmfs/volumes/<shared-datastore>/productLocker.
  2. Copy the vmtools and floppies content into it, or the newer Tools packages you want to standardize on.
  3. On every host, set the advanced setting UserVars.ProductLockerLocation to that path (Configure > System > Advanced System Settings).
  4. Reboot the host, or refresh the location through the API, so the /productLocker link points to the shared path.

Benefits: one place to update VMware Tools for the whole environment, a consistent Tools version across hosts, and less data on each host. Auto Deploy hosts provisioned with an image profile that has no Tools rely on a shared Product Locker.

ESXi Boot Options (4.17)

Firmware Boot Mode

ESXi 8.0 boots with UEFI; support for legacy BIOS boot is limited, so use UEFI on new installations. UEFI is also required for Secure Boot.

Quick Boot (4.17.1)

Quick Boot restarts ESXi without a full hardware reboot, skipping firmware POST and device initialization (Section 7.1):

  • Check compatibility with /usr/lib/vmware/loadesx/bin/loadESXCheck.py. Broadcom KB 52477, one of the exam guide's references, explains the requirements.
  • Enable Quick Boot in Lifecycle Manager > Settings > Host Remediation (for images and baselines).
  • If a host or its drivers are not compatible, vLCM falls back to a normal reboot.

Securely Booting ESXi (4.17.2)

  1. UEFI Secure Boot: the firmware verifies the ESXi boot loader, which verifies the kernel, which verifies every VIB signature. Run /usr/lib/vmware/secureboot/bin/secureBoot.py -c before enabling it on an upgraded host, because a CommunitySupported VIB would stop the host from booting.
  2. TPM 2.0: with a TPM enabled in the firmware, vCenter can remotely attest the host's boot measurements, and vSphere Trust Authority can gate keys on attestation (Section 6.4).
  3. Secure ESXi configuration (vSphere 7.0 Update 2 and later): on hosts with a TPM, ESXi protects its configuration encryption key with the TPM. You can also require Secure Boot enforcement and allow only installed binaries to execute (esxcli system settings encryption set). Record the recovery key.

Other Boot Paths

  • Auto Deploy PXE-boots hosts and applies host profiles (Section 7.3).
  • Boot from SAN (FC, FCoE hardware adapters, or iSCSI) lets hosts boot from a LUN instead of local media.
  • Installer boot options (press Shift+O at the installer's boot prompt) include systemMediaSize to size ESX-OSData (Section 1.1).

Exam Traps

  • Same source everywhere. When SSO logins or AD joins fail intermittently, check that ESXi, vCenter, and the identity provider use the same time source before chasing certificates.
  • Product Locker changes apply per host. Setting the path on one host does not change the others; use a script, PowerCLI, or Host Profiles for consistency.
  • Quick Boot is a remediation setting, not a BIOS option you enable on each server.
Test Your Knowledge

An administrator wants every ESXi host in a 40-host environment to use one centrally maintained set of VMware Tools images. What should be configured?

A

Copy the Tools images to a dedicated directory on a shared datastore and set UserVars.ProductLockerLocation on each host to that path

B

Upload the Tools ISO to every host's local datastore and mount it on each VM

C

Enable open-vm-tools on each ESXi host

D

Configure a vSphere Lifecycle Manager baseline that deletes /productLocker

Test Your Knowledge

A trading platform requires highly accurate time on its ESXi hosts, using hardware timestamping on supported NICs. Which time configuration should be used?

A

Manual time configuration synchronized weekly

B

NTP pointed at a public pool

C

Guest time synchronization through VMware Tools

D

Precision Time Protocol (PTP)

Test Your Knowledge

An administrator plans to enable UEFI Secure Boot on ESXi hosts that were upgraded from older releases. What should be done first to avoid a host failing to boot?

A

Set vpxd.certmgmt.mode to thumbprint

B

Enable Quick Boot in the vLCM remediation settings

C

Run /usr/lib/vmware/secureboot/bin/secureBoot.py -c on each host to confirm it can boot securely

D

Enable Strict Lockdown Mode

Sections you finish are checked off in the contents.