Skip to content
View in the app

A better way to browse. Learn more.

Unraid

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Virtualizing Windows 11 and TPM 2.0 requirement

Featured Replies

7 hours ago, TCMapes said:

Does it matter where i put this in my VM xml?  Is there a certain location i should put these?

 

 

the 1st 2 lines are replacements, loader ... nvram ....

 

the tpm part, shouldnt really matter, just somewhere inside devices part.

 

but still, i d recommend to wait ...

On 10/26/2021 at 8:08 PM, Skitals said:

 

Nasty patches? It's a few prebuilt binaries and prebuilt ovmf file. If someone can't edit their own xml file I wouldn't suggest they use a test verion of unraid.

 

For me it is a lil bit of nastynes cuz Unraid will when upgraded to stable 6.10 maybe remove the patched / updated files.

So why I should do it myself, when already a update will come which add the wanted "features"? I mostly like to use a system like it is (system as is). Just for better error findings and so on. 🙂

I wont say that the "new prebuilt binaries" are bad or something near like this. It is nice that someone found a way to do it for earlier unraid builds but as I said, if some new errors or problems can come through such doings no one can really help if they happen or I will say it will just be harder to find solutions then.

On 9/18/2021 at 1:28 AM, okkies said:

I got TPM and secure boot working trough this guide

https://www.linkedin.com/pulse/swtpm-unraid-zoltan-repasi/msinfo32_INzmdSm6Ja.thumb.png.2e44516fa9731369eff9a8e3c9ae25a9.png

Could you please help me with this? I can't find the boot/extra folder on the Unraid USB drive. Where is that folder located? Found another post from you where you showed that you have to create the folder. 

 

Anyway, I am now at this part: 

If you don't have the "User scripts" plugin install, you need to install it at this stage and create a script which runs at the startup of the array. You should add the following content to the script (startup_script). Im not going into too much details of the script, the key thing is the last line. When you first startup the virtual machine during the runtime it will create a folder under /var/lib/libvirt/swtpm/ something like this /var/lib/libvirt/swtpm/141d5517-bb66-23b3-6373-c4288xxxxxx, you need to make sure that you copy this whole folder into the VM storage area and symlink it back on the next boot as /var/lib/libvirt/swtpm/ is not persistent.

 

I am stuck there. I created the script and ran it manually. I thought that if I started a VM then it would create a folder somewhere. It should create a folder under the path given in the manual but where can I find the /var/lib folder? And how do I create a symlink? 

 

Any help with pictures would be greatly appreciated as this is not easy for me. 

Edited by workermaster

47 minutes ago, workermaster said:

Could you please help me with this? I can't find the boot/extra folder on the Unraid USB drive. Where is that folder located? Found another post from you where you showed that you have to create the folder. 

 

Anyway, I am now at this part: 

If you don't have the "User scripts" plugin install, you need to install it at this stage and create a script which runs at the startup of the array. You should add the following content to the script (startup_script). Im not going into too much details of the script, the key thing is the last line. When you first startup the virtual machine during the runtime it will create a folder under /var/lib/libvirt/swtpm/ something like this /var/lib/libvirt/swtpm/141d5517-bb66-23b3-6373-c4288xxxxxx, you need to make sure that you copy this whole folder into the VM storage area and symlink it back on the next boot as /var/lib/libvirt/swtpm/ is not persistent.

 

I am stuck there. I created the script and ran it manually. I thought that if I started a VM then it would create a folder somewhere. It should create a folder under the path given in the manual but where can I find the /var/lib folder? And how do I create a symlink? 

 

Any help with pictures would be greatly appreciated as this is not easy for me. 

 

Dont use this anymore. just update to RC2. it works much better. 

18 minutes ago, okkies said:

 

Dont use this anymore. just update to RC2. it works much better. 

RC2 isn't out yet. Any news on when we can expect it?

39 minutes ago, okkies said:

@workermaster

its litterly 3 posts above this: 

Revert all the steps you done, so delete boot/extra stop the userscript

then go to plugins 
install plugin and use this URL
https://s3.amazonaws.com/dnld.lime-technology.com/test/unRAIDServer.plg

I saw that post but that isn't the official release right? That is a test build. I can't find it through the update tab in Unraid. 

I have now just installed W10 and will wait until I can find the RC2 through the update tab. 

3 minutes ago, workermaster said:

I saw that post but that isn't the official release right? That is a test build. I can't find it through the update tab in Unraid. 

I have now just installed W10 and will wait until I can find the RC2 through the update tab. 

no disrespect, but you seem like a novice, are you sure you want to use beta software in order to get TPM working? 

read the URL, its hosted on the amazon servers of Limetech, aka unraid. 

again: 
Revert all the steps you done, so delete boot/extra stop the userscript

then go to plugins tab in unraid
install plugin and use this URL
https://s3.amazonaws.com/dnld.lime-technology.com/test/unRAIDServer.plg

K2eYMcC.png

18 minutes ago, okkies said:

no disrespect, but you seem like a novice, are you sure you want to use beta software in order to get TPM working? 

read the URL, its hosted on the amazon servers of Limetech, aka unraid. 

again: 
Revert all the steps you done, so delete boot/extra stop the userscript

then go to plugins tab in unraid
install plugin and use this URL
https://s3.amazonaws.com/dnld.lime-technology.com/test/unRAIDServer.plg

K2eYMcC.png

I am indeed a novice. When it comes to anything Linux, pretty much the biggest novice in the universe. So thanks for trying to help me. 

 

All steps have already been reverted. 

 

I am confident that I can get the plugin way to work but am wondering what the difference is between the plugin version that I can install, or the update tab. Am I correct in thinking that the update I can install with the plugin way, is a nightly type of build and the one that will be rolled out on the update tab will be a more stable version of the RC2 build?

Edited by workermaster

22 minutes ago, workermaster said:

I am indeed a novice. When it comes to anything Linux, pretty much the biggest novice in the universe. So thanks for trying to help me. 

 

All steps have already been reverted. 

 

I am confident that I can get the plugin way to work but am wondering what the difference is between the plugin version that I can install, or the update tab. Am I correct in thinking that the update I can install with the plugin way, is a nightly type of build and the one that will be rolled out on the update tab will be a more stable version of the RC2 build?

dont know why an RC2 isnt public.
the nighly type also came to mind to me aswell. but as you can see by the steps to install the update, its a manual job. unraid doesnst have automatic updates for its OS. its a manual Handle. 

anyways, i got curios, seems were all fine. u can roll back to any version.
klvgZRC.png
now stop being a pussy and update 

22 hours ago, okkies said:

dont know why an RC2 isnt public.
the nighly type also came to mind to me aswell. but as you can see by the steps to install the update, its a manual job. unraid doesnst have automatic updates for its OS. its a manual Handle. 

anyways, i got curios, seems were all fine. u can roll back to any version.
klvgZRC.png
now stop being a pussy and update 

Took your advice, stopped being a pussy and updated. My virtual machines are still saying that they do not have TPM. Do I still need to follow the steps on the LinkedIn tutorial, except for the first few? Or are there any other handy fixes that I should know of?

6 minutes ago, workermaster said:

My virtual machines are still saying that they do not have TPM

Did you choose ovmf tpm bios?And did you add the tpm to your vm?

Edited by ghost82

14 minutes ago, ghost82 said:

Did you choose ovmf tpm bios?And did you add the tpm to your vm?

I have now switched the BIOS to the TPM one. Will read through the manual on LinkedIn again to figure out how I have to add the TPM to the VM.

 

EDIT: I only had to switch the BIOS  to the TPM one. I did not have to add anything to the XML file to get it to work. The Windows 11 tool now says that I can run Windows 11. I have been running W11 for a few months now but wanted to be able to update it. 

Edited by workermaster

18 hours ago, workermaster said:

I have now switched the BIOS to the TPM one. Will read through the manual on LinkedIn again to figure out how I have to add the TPM to the VM.

 

EDIT: I only had to switch the BIOS  to the TPM one. I did not have to add anything to the XML file to get it to work. The Windows 11 tool now says that I can run Windows 11. I have been running W11 for a few months now but wanted to be able to update it. 

the linkdin manual isnt required anymore. everything is baked in. 
i was lazy, i just made a new windows 11 VM within unraid. assigned the new bios and chipset(machine is chipset, right?)  and used the same drives and components. 
ofc i had to update all the drivers on first boot. but its working like a charm. 

Have fun with Windows 11!

  • 2 weeks later...

yesterday I made a snapshot of one of my unactivated Win 10 VMs, updated to the latest

 

Then I used this tool to upgrade to Win 11

 

https://github.com/coofcookie/Windows11Upgrade

 

No errors, went smoothly. Now playing around with it a bit and have not yet found any bugs

 

I dont have any TPM, nor an emulated one, nor a supported Win 11 CPU

 

Edited by unrateable

  • 4 months later...
On 11/8/2021 at 8:00 PM, unrateable said:

I dont have any TPM, nor an emulated one, nor a supported Win 11 CPU

You know that since Unraid 6.10.0-rc2 TPM is now available in Unraid and you can Windows 11 as usual.

 

You even can change your VM to use the emulated TPM as long as you are using OVMF as BIOS type without any scripts,...: Click

  • 3 years later...
On 3/17/2022 at 3:47 AM, ich777 said:

You know that since Unraid 6.10.0-rc2 TPM is now available in Unraid and you can Windows 11 as usual.

 

You even can change your VM to use the emulated TPM as long as you are using OVMF as BIOS type without any scripts,...: Click

Hey @ich777

I'm having trouble with my Win11 VM using TPM. see my thread below. is there a better way to setup my WIn11 VM (i'm trying to reset my libvirt.img due to crashing) so that i don't run into unncessarily complex backups of .fd files in etc/ folder when my VM goes caput next time? i'm running 7.1.1, wondering if the new unraid after 6.10 built in the TPM type security needed to run windows updates.

20 hours ago, Linguafoeda said:

I'm having trouble with my Win11 VM using TPM. see my thread below. is there a better way to setup my WIn11 VM (i'm trying to reset my libvirt.img due to crashing) so that i don't run into unncessarily complex backups of .fd files in etc/ folder when my VM goes caput next time? i'm running 7.1.1, wondering if the new unraid after 6.10 built in the TPM type security needed to run windows updates.

I'm not sure if I'm following.

If you want to backup your TPM states you have to backup your state dir which lives in the libvirt.img but I would not recommend doing that since this is a really manual process and many things can go wrong.

I would rather recommend that you simply disable Bitlocker in Windows, then recreate the VM with a new TPM, start the VM, it then should complain that your hardware has changed an your PIN is not working any more, you have to login with your password and recreate the pin.

1 hour ago, ich777 said:

I'm not sure if I'm following.

If you want to backup your TPM states you have to backup your state dir which lives in the libvirt.img but I would not recommend doing that since this is a really manual process and many things can go wrong.

I would rather recommend that you simply disable Bitlocker in Windows, then recreate the VM with a new TPM, start the VM, it then should complain that your hardware has changed an your PIN is not working any more, you have to login with your password and recreate the pin.

hmm i see. so if i don't backup the .fd files living in the /etc folder, i can just recreate the TPM and all i would have to do is reset my pin? can i store the tpm-related files in the ISO folder where the vdisk lives to keep it simple in the future for backing up?

7 hours ago, Linguafoeda said:

hmm i see. so if i don't backup the .fd files living in the /etc folder, i can just recreate the TPM and all i would have to do is reset my pin?

yes, and like described in the other thread, bitlocker !!!

7 hours ago, Linguafoeda said:

can i store the tpm-related files in the ISO folder where the vdisk lives to keep it simple in the future for backing up?

no and makes no sense, the persistent storage is inside the libvirt image, usually located in ../system/libvirt/libvirt.img

loaded on boot and mounted and so on ...

when you really think your issue/s are libvirt related, test with a fresh one (backup your original one), you will have to recreate your VM/s anyway already then as the xml/s (Start Parameters) are also from there ... so if you woant to backup those files, dont forget the xml/s as the uuid of the tpm etc are also in the xml/s.

overall, better, easier and faster just to startup fresh and point to the existing vdisk image in terms needed.

bitlocker

pin

hardware activation (MS may want to reactivate your VM then due "hardware" change)

10 hours ago, Linguafoeda said:

can i store the tpm-related files in the ISO folder where the vdisk lives to keep it simple in the future for backing up?

The TPM related files are already stored in the libvirt image file and the image file is simply mounted to the libvirt directory for persistent storage, but as said, it is way easier to recreate the TPM, with all the steps that @alturismo mentioned above before recreating the VM, than to backup and restore all files because they rely on UUIDs and so on and you can definitely mess up things if a file is not in place.

That makes no sense to keep the TPM files inside the vdisk from the VM itself since this would defeat the purpose from a TPM, which it kind of does already since we are emulating the TPM in the VM.

On 7/9/2025 at 12:51 AM, alturismo said:

yes, and like described in the other thread, bitlocker !!!

no and makes no sense, the persistent storage is inside the libvirt image, usually located in ../system/libvirt/libvirt.img

loaded on boot and mounted and so on ...

when you really think your issue/s are libvirt related, test with a fresh one (backup your original one), you will have to recreate your VM/s anyway already then as the xml/s (Start Parameters) are also from there ... so if you woant to backup those files, dont forget the xml/s as the uuid of the tpm etc are also in the xml/s.

overall, better, easier and faster just to startup fresh and point to the existing vdisk image in terms needed.

bitlocker

pin

hardware activation (MS may want to reactivate your VM then due "hardware" change)

On 7/9/2025 at 3:27 AM, ich777 said:

The TPM related files are already stored in the libvirt image file and the image file is simply mounted to the libvirt directory for persistent storage, but as said, it is way easier to recreate the TPM, with all the steps that @alturismo mentioned above before recreating the VM, than to backup and restore all files because they rely on UUIDs and so on and you can definitely mess up things if a file is not in place.

That makes no sense to keep the TPM files inside the vdisk from the VM itself since this would defeat the purpose from a TPM, which it kind of does already since we are emulating the TPM in the VM.

Hey guys - thanks so much for the help. So i attempted to follow both of your steps of just trying to create a new TPM / "fresh" re-install using my old XML/vdisk location, instead of backing up and restoring the backed up .fd file from /etc/libvirt/qemu/nvram;

As soon as i restored the XML, clicked save, then re-went to edit VM -> form view -> under BIOS, I switched to "OVMF", clicked save, then re-went back to form a 3rd time, and changed it back to OVMF TPM and clicked save again, I fixed the intel GVT-g issue (step 9 in this post) and then attempted to launch but got stuck in the BIOS with the error similar to the below:

image.png

Do you know what i did wrong that caused this? I would like to know how to fix this TPM issue to fresh install in future, and i'm sure maybe someone similar to me runs into a similar issue trying to re-create TPM that might not have backed up their .fd files. For now - i just restore the .fd file and it's working, not sure if that will cause any instability but seems okay so far for last 1 hour running the VM again.

1 hour ago, Linguafoeda said:

Do you know what i did wrong that caused this?

It seems that the VM doesn't know from where to boot.

1 hour ago, Linguafoeda said:

i just restore the .fd file and it's working, not sure if that will cause any instability but seems okay so far for last 1 hour running the VM again.

No it shouldn't cause any issues.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.