VMware Cloud Community
KelvinTangHK
Contributor
Contributor
Jump to solution

vCenter Photon OS 3.0 end of life

The Photon OS 3.0 that was installed as part of the vCenter Appliance will be reaching end of support date by Feb or Mar 2024.  Would VMware release a new update of vCenter 7.0 that would include updating Photon OS to 4 or 5?  Otherwise, are customers suppose to update the Photon OS on the VCSA server to version 4 or above by themselves? 

0 Kudos
1 Solution

Accepted Solutions
depping
Leadership
Leadership
Jump to solution

8.0 U2 has Photon 4.0, I just checked in my lab for you. And yes it will be upgraded, at least it did for me, when I went from 7.x to 8.x.

Also, VMware will provide security fixed and bug fixes for 7.x until end of life for vCenter Server, even when the underlying OS is EOL, as a customer that is not your problem. 

Hope that helps,

View solution in original post

10 Replies
mlnelson
Contributor
Contributor
Jump to solution

Since vCenter 7.0 has already reached end of availability (but not end of support) zero chance with the current patch model they would update to a later Photon OS, rather continue to patch as needed. 

It's one of the reasons for the new vCenter update model in vSphere 8 where the appliance is replaced and the data copied over vs current patch model.

Also - support is based on the vCenter Appliance not the base OS. Technically we 'don't care' what the OS is because it's an appliance. I expect VMware to support it long as I have a valid support contract. 

0 Kudos
Tibmeister
Expert
Expert
Jump to solution

vCenter 7 has not reached end of life, https://lifecycle.vmware.com/#/?advancedFilter=checkbox_sup, not until 04/02/2025 for General Support.

I have the same questions for PhotonOS 3 and VCSA 7, it's a very valid question that we don't have an answer for as of yet.  Personally, I am planning to start my vSphere 8 upgrade planning in Feb, since we have vSAN there's some added planning that goes into it all.

0 Kudos
Sachchidanand
Expert
Expert
Jump to solution

I don't think vmware will come up with vCneter 7 with photon OS higher than 3 as they are regularly providing security fixes for the affected packages for the current version. please see the link below:

https://docs.vmware.com/en/VMware-vSphere/7.0/rn/vcenter-server-appliance-photonos-security-patches....

Regards,

Sachchidanand

0 Kudos
Tibmeister
Expert
Expert
Jump to solution

As long as we are still getting security updates through the life of VCSA7 then that's fine.

0 Kudos
varun_sidana
VMware Employee
VMware Employee
Jump to solution

We recently published this KB addressing the concern.

https://kb.vmware.com/s/article/96577?lang=en_US&queryTerm=96577

0 Kudos
KelvinTangHK
Contributor
Contributor
Jump to solution

The wordings in the KB article 96577 is ambiguous.

First of all, the KB article 96577 said that “VMware will provide fixes for CVE's based on upstream package availability for Photon OS 3.x.”, but since Photon OS 3.0 is reaching end-of-life by 1-Mar-2024, is it unlikely that there will be any “upstream package availability for Photon OS 3.0” after 1-Mar-2024?  Is VMware actually implying in the above statement that after 1-Mar-2024 VMware will NOT (or may not be able to) provide CVE fixes for any new vulnerability of Photon OS 3.0 for vCenter Server customers still running Photon OS 3.0?


Secondly, the KB article 96577 said that “VMware will not release a newer Photon OS version on older releases of vCenter including 7.0 & 8.0.”, but did not say

a. whether VMware has already released or plans to release a newer Photon OS version on some newer releases of vCenter 7.0 and 8.0

b. whether VMware has already released or plans to release a newer Photon OS version on some newer patches/updates of vCenter 7.0 and 8.0

Moreover, the KB article 96577 also said that VMware advices the customers not to update the Photon OS on the VCSA server to version 4 or above by themselves.  In short, VMware is not telling their customers currently running Photon OS 3.0 on their vCenter Server what to do with the end-of-life Photon OS 3.0, leaving them worrying about not able to get any fix with any new vulnerability of the Photon OS 3.0 they are running.

In fact, recently I had implemented the “VMware vCenter Server 7.0 Update 3p” (released on 7-Dec-2023) on my vCenter Server, and found that the Photon OS is still version 3.0 after the update.  Will updating the vCenter Server version 7 to the latest version of vCenter Server 8 (VMware vCenter Server 8.0 Update 2a, released on 26-Oct-2023) automatically update the Photon OS to a version newer than 3.0?   If not, what is the proper way to update the Photon OS 3.0 running on the vCenter Server to a newer (not end-of-life) version?  Could VMware clarify that, please?

0 Kudos
depping
Leadership
Leadership
Jump to solution

8.0 U2 has Photon 4.0, I just checked in my lab for you. And yes it will be upgraded, at least it did for me, when I went from 7.x to 8.x.

Also, VMware will provide security fixed and bug fixes for 7.x until end of life for vCenter Server, even when the underlying OS is EOL, as a customer that is not your problem. 

Hope that helps,

tanjilislam
Enthusiast
Enthusiast
Jump to solution

Thank you for sharing this 🙂 


-Tanjil Islam
If my answer has resolved your problem, please mark it as resolved, or if it has only been a good help, then give me the kudos.
0 Kudos
KelvinTangHK
Contributor
Contributor
Jump to solution

From depping's reply, my understanding is that VMware will still provide CVE fixes for any new vulnerability (if found) of Photon OS 3.0 for vCenter Server 7.x customers still running Photon OS 3.0 (until the end-of-life date of vCenter Server 7.x).   If that understanding is correct, then I have no other question and this discussion could be marked as resolved.  Thanks.

0 Kudos
depping
Leadership
Leadership
Jump to solution

that is correct

0 Kudos