When you add a VM to a Cloud VM Set, the VM inherits the settings for most of its property settings from the global defaults specified for the associated Cloud VM Set. (The only exception is the Description, which is set when you register the VM with Cryptographic Security Platform Vault.) You can override the global defaults for individual VMs as required. For details about setting the global defaults, see Creating a Cloud VM Set for the CSP Vault for VM Encryption.

  1. Log into the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
  2. In the top menu bar, click Workloads.
  3. Select the VM whose properties you want to set and click the Expand button (>) at the end of the row.
  4. On the Details tab, specify the options you want to use.

    Option

    Description

    Description

    A user-defined string identifying this VM.

    Certificate Valid Until

    The date on which the certificate for this VM will expire. To have Cryptographic Security Platform Vault automatically renew the certificate, set the Certificate Auto Renewal Period option, described below.

    Heartbeat

    The length of time between the heartbeats each VM in the set sends to the Cryptographic Security Platform Vault for VM Encryption to verify that the connection between them is functioning normally. You can specify seconds, minutes, hours, or days. The default is 5 minutes. This value should be set to a minimum of 10 seconds.

    If changes have been made to the VMs through the Cryptographic Security Platform Vault for VM Encryption webGUI, those changes are communicated to the VMs during the heartbeat. That means if the heartbeat is set to 5 minutes, then it can take up to 5 minutes for any changes made in the Cryptographic Security Platform Vault for VM Encryption webGUI to be applied to the VMs in the set.

    If a VM cannot reach the Cryptographic Security Platform Vault for VM Encryption during the heartbeat, the VM continues to run but any changes made are not picked up by the VM until the next successful heartbeat. Cryptographic Security Platform Vault for VM Encryption sets the status of the VM to Unreachable, but it takes no further action unless the heartbeat continues to fail after the Grace Period has expired.

    Grace Period

    The length of time that can pass without a successful heartbeat. The default is 1 day. You can specify the grace period in seconds, minutes, hours, or days.

    If a VM remains unresponsive past the grace period, access to the data on the VM will be unavailable until the VM is re-authenticated with Cryptographic Security Platform Vault for VM Encryption.

    OS

    The operating system running on the VM.

    Policy Agent Version

    The version of the Entrust Policy Agent running on the VM.

    Rekey Interval

    If you specify any value other than 0 (zero) for this option, Cryptographic Security Platform Vault periodically creates a rekey task for every encrypted disk in the VM. You can select any number of days, weeks, months, or years and the Cryptographic Security Platform Vault for VM Encryptionwill automatically rekey the encrypted disks on that schedule.

    To disable Auto Rekey, enter 0 in this field. By default, Auto Rekey is disabled.

    Note: For Linux VMs, Auto Rekey only works if the online encryption driver has been configured and is active on the Linux VM.

    Certificate Auto Renewal Period

    If you want Cryptographic Security Platform Vault for VM Encryption to automatically renew the certificate for a VM in this Cloud VM Set, enter an integer greater than zero in this field. Cryptographic Security Platform Vault for VM Encryption will renew the certificate that many days before the old one expires. For example, if you enter a value of 5 in this field and a VM certificate is set to expire on June 12, 2022, Cryptographic Security Platform Vault for VM Encryption will renew the license on June 7, 2022. The default is 10 days. The expiry date is always 1 year from the date the certificate was created or renewed.

    To change the renewal period, click the existing value and enter a new value in the text field, then select days/weeks/months/years from the drop-down list. When you are finished, click Save.

    If you want to disable certificate auto-renewal, enter 0 (zero) in this field.

    Note: If you have auto-renewal set, but the renewal fails, Cryptographic Security Platform Vault for VM Encryption will continue to retry until the certificate is valid. When the certificate is no longer valid, the admin password will be required.

    Mapping

    The Cluster Node Mapping associated with this VM, if any. For details, see Creating a Cluster Node Mapping.

    Single Encryption Key State

    Whether the Single Encryption Key (SEK) option is enabled or disabled for the Cloud VM Set with which this VM is registered. For details, see Data Deduplication with Cloud VM Sets.

    Auto Encryption

    If this option is enabled, whenever Cryptographic Security Platform Vault for VM Encryption detects a new Windows drive or Linux device has been added to this VM, Cryptographic Security Platform Vault for VM Encryption immediately checks the Auto Encryption Policy. If the new drive or device is covered by the policy, Cryptographic Security Platform Vault for VM Encryptionautomatically tells the Policy Agent to encrypt that drive or device.

    To enable this option, click Disabled, select Enabled from the drop-down list, then click Save. When you do so, the webGUIdisplays the Encryption Policy fields:

    • Auto Encryption Policy Type. This can be:
      • Exclude—The Windows drives and Linux devices listed in the Auto Encryption Policy Path(s) field will not be automatically encrypted, although they can be encrypted manually at any time. This is the default.
      • Include—The Windows drives and Linux devices listed in the Auto Encryption Policy Path(s) field will beautomatically encrypted. All other drives or devices on the VM must be encrypted manually.
      • Encrypt All Devices—All Windows drives and Linux devices will be automatically encrypted.
    • Auto Encryption Policy Path(s)—If the policy type is Include or Exclude, enter a path that should be included or excluded. To add additional paths, click the + (Plus sign) in this field. You can enter either a Windows drive a Linux device name. For example, any of the following would be valid path names: C:, C:\data, or sdb1.

      Important: Each path must be on its own line.

      For more information, see Automatic Data Encryption.

    Decryption Allowed

    If this option is set to Yes, the drives and devices in this VM can be decrypted. If it is set to No, any decryption request will fail.

    Policy Agent Uninstallation Allowed

    If this option is set to Yes, the Policy Agent can be uninstalled on this VM. If it is set to No, the Policy Agent cannot be uninstalled.

  5. On the Reauthentication Settings tab, you can change any of the following options by clicking the entry in the field, setting the new value, and then clicking Save. You must click Save after each change or your changes will be lost when you select a different field.

    Option

    Description

    Reauthentication on IP Change

    Whether the VM must be re-authenticated when the VM's IP address changes. The default is No.

    If your system configuration uses DHCP or multiple NICs, do not set this option to Yes. If you do so, the VM may go into a reboot loop if the boot partition is encrypted and any encrypted drives may be detached.

    Reauthentication on H/W Signature Change

    Whether the VM must be re-authenticated if its MAC address or UUID changes.

    The options are:

    • Yes—If either the MAC address or the UUID changes, the VM requires reauthentication. This is the default. We recommend that you do not change this option.

    • Permissive—Both the MAC address and the UUID must change before the VM requires reauthentication.
    • No—The Cryptographic Security Platform Vault for VM Encryption does not require reauthentication if VM's MAC address or UUID changes. We strongly recommend that you do not select this option. If you do, a cloned or misconfigured VM could gain access to the keys associated with the original VM.

      If you do select this option, you must confirm the selection before you can proceed. If Cryptographic Security Platform Vault for VM Encryption detects multiple VMs with the same MAC address and UUID combination when hardware validation is off, Cryptographic Security Platform Vault for VM Encryption generates an alert every 8 hours until the cloned VMs stop heartbeating or hardware authentication is set to Yes or Permissive. In addition, Cryptographic Security Platform Vault for VM Encryption generates an alert when client operations, such as key access or device registration, occur on the cloned VMs.

    Note: If this VM is a Master vSphere VDI VM, this option should always be Yes. If it is set to No, Cryptographic Security Platform Vault for VM Encryption may not be able to tell the Master VM from its clones. For details, see Combining VMware vSphere VDI with CSP Vault.

    Reauthentication on Reboot

    Whether the VM must be re-authenticated every time it reboots. The default is No.

    Setting this value to Yes is similar to requiring a boot-time password before the VM can come up completely.