Under certain circumstances, the ESXi host's encryption mode can become deactivated.
An ESXi host requires that host encryption mode is activated if it contains any encrypted virtual machines. If the host detects it is missing its host key, or if the key provider is unavailable, the host might fail to activate the encryption mode. vCenter Server generates an alarm when the host encryption mode cannot be activated.
Procedure
What to do next
If, after restoring connection to the key provider, or manually recovering keys to the key provider, the host's encryption mode remains deactivated, re-activate the host encryption mode. See Re-Activate ESXi Host Encryption Mode.