Skip to main content

Vcenter server encryption configuration using HyTrust KMS key Provider

 Steps:

1.Download HYTRust Keyprovider OVA from:

https://www.entrust.com/digital-security/key-management/keycontrol

They give 60 day trail free deployment.

2.Deploy the KMS server.

3.Once Installation completes. Login to Entrust server using IP and login with user/password you provided while install.

4.Go to "KMIP" ->Basic ,mark state=Enabled ,vesion=1.1






5.From KMIP ->client certificates->Actions ->Create client certificate (Don't give any passwords)
6.Select the created certificate and download ZIP file and extract.

7.Go to Vcenter server-> Configure ->Security->Key providers
     Add Standard key Provider
     provide KMS name (certificate name)
      IP of the Entrust server
      Port:5696
8.Select the KMS server and select the keys and "Establish Trust"
    Select the zip folder and choose <KMS>.PEM that we created
    use the same file for certificate and key upload path.


Now choose existing VM->Power off -> VM Policies ->Select "Encryption policy"
it takes nearly 10 minutes to configure the VM .

Now you can check VM Summary have :
     VM hardware have "Encryption details" and Hard disk(encrypted)








Comments

Popular posts from this blog

Deploy OVF fails Issues detected with selected template. Details: VALUE_ILLEGAL: No supported hardware versions among [virtualbox-2.2]; supported: [vmx-04, vmx-07, vmx-08, vmx-09, vmx-10, vmx-11, vmx-12, vmx-13, vmx-14, vmx-15, vmx-16, vmx-17, vmx-18, vmx-19].

 Error: While deploy using OVF file ,getting error as : Issues detected with selected template. Details: - -1:-1:VALUE_ILLEGAL: No supported hardware versions among [virtualbox-2.2]; supported: [vmx-04, vmx-07, vmx-08, vmx-09, vmx-10, vmx-11, vmx-12, vmx-13, vmx-14, vmx-15, vmx-16, vmx-17, vmx-18, vmx-19]. Solution: Open .OVF file and edit       <Info>Virtual hardware requirements for a virtual machine</Info>       <System>         <vssd:ElementName>Virtual Hardware Family</vssd:ElementName>         <vssd:InstanceID>0</vssd:InstanceID>         <vssd:VirtualSystemIdentifier>zabbix_appliance-6.2.7</vssd:VirtualSystemIdentifier>         <vssd:VirtualSystemType> virtualbox-2.2 </vssd:VirtualSystemType>       </System> to  vmx-19       <Info>Virtual hardware requireme...

How to Open KVM oVirt Virtual machine console from windows

  To open virtual machine console from ovirt manager (KVM) 1. Download and Install ovirt-viewer from the below link:     https://virt-manager.org/download 2.From browser open ovirt engine and login to administrator portal 3.Right click the virtual machine and choose "Console" 4.Console file be getting created on your windows->downloads 5.Right click the file ->Properties and change the file "Opens With:" as a new program and browse till c:\program files->ovirt-viewer-> "Remote-Viewer" type 5.Now double click on the "Console.vv" file will open the console: