How you increase the size of a Windows disk depends on whether the type of disk and whether or not the disk is encrypted.
If the Windows disk has not been encrypted, you can extend or shrink that disk as desired using your hypervisor tools.
- If the unencrypted disk is a Windows data disk or a GPT boot disk, you do not need to do anything in Cryptographic Security Platform Vault after you resize the disk, even if the Bootloader is already installed. Cryptographic Security Platform Vault will pick up the new disk size automatically.
- If the unencrypted disk is an MBR boot disk with the Entrust Bootloader already installed, you need to move the boot partition as described in Resizing an Encrypted Windows Data Disk or GPT Boot Disk.
- If the disk is an encrypted Windows data disk or an encrypted GPT boot disk, you can extend or shrink that disk as desired using your hypervisor tools. After you resize the disk in your hypervisor, you need to update the size in Cryptographic Security Platform Vault using the
hcl extendcommand. For details, see Resizing an Encrypted Windows Data Disk or GPT Boot Disk. - If the disk is an encrypted Windows MBR boot disk, you must resize it as described in Extending an MBR Boot Partition After Installing the Bootloader.
Important:
After you run the hcl extend operation to resize the drive, the new size may not be reflected in the Cryptographic Security Platform Vault for VM Encryption webGUI. If this happens, please execute the following commands:
hcl statushcl update_size_kc <disk #> <partition #>where the disk # and partition # are for the drive in question, as reflected when you issue the hcl status command.
hcl heartbeat -u
Once the command execution is successful, the size should be displayed properly in the Cryptographic Security Platform Vault for VM Encryption webGUI.
If the disk being extended is part of a Microsoft Failover Cluster, you must enable maintenance mode on the disk, extend the disk, and then disable maintenance mode on that disk.
Resizing an Encrypted Windows Data Disk or GPT Boot Disk
This is an online procedure, which means that the disk and its contents will remain available during the resize. However, you cannot resize a disk that is detached or that is in the process of being rekeyed.
Important: If you are using mount points instead of drive letters, you must use the Disk Management 'Change Drive letter and paths' option to temporarily assign a drive letter before you can change the size of the disk. After resizing, you can safely remove the drive letter.
Warning: If you resize the disk with Windows Disk Manager, you may be prompted to convert from a basic disk into a dynamic disk. Windows dynamic disks are not supported. If you select this option, you will not be able to access this disk through Cryptographic Security Platform Vault and all existing data will be lost.
Resize the underlying disk using your hypervisor tools.
- Log into the VM as a System Administrator and open a Command Prompt or start Windows PowerShell.
Enter the command
hcl extend diskname, wheredisknameis the drive letter or folder mount you want to resize. For example:C:\>hcl extend f: extending partition for f: extending filesystem for f:the new filesystem is 2146369536 bytes long
Tip: If the
hcl extendcommand fails with the message that there are too many partitions on the disk, see Detecting and Removing a Windows Snapshot Partition.
Extending an MBR Boot Partition After Installing the Boot loader
The Bootloader installation creates a new MBR partition labeled HTBOOTLDR immediately following the boot partition on the disk. If you want to extend the MBR boot partition at any time after you have installed the Bootloader, you need to make sure the unallocated space you want to use is immediately adjacent to the boot partition by extending the disk and then using the Entrust-provided PowerShell script that moves the HTBOOTLDR partition to the end of the disk and then extends the boot partition into the unallocated space. (For details about the Entrust Bootloader, see Windows Boot Drive Encryption.)
Important: The VM will need to be rebooted twice during this procedure.
- Extend the MBR disk containing the boot partition using your hypervisor tools.
- Log into PowerShell on the Windows VM.
- Locate the main Policy Agent installation directory. The PowerShell scripts are located in the
binfolder under this main directory. The default directory isC:\Program Files\hcs. Run the PowerShell script
MoveHTBootloader.ps1by entering the commandpowershell -File "C:\entrust-install-dir\MoveHTBootloader.ps1".The script creates a new Bootloader partition at the end of the recently extended disk and reboots the virtual machine. On reboot,
MoveHTBootloader.ps1will again be executed automatically and will delete the old Bootloader partition and then extend the boot partition to take up the available free space. The VM will be rebooted a second time to complete this process.Note: This operation changes the drive letter for the
HTBOOTLDRdrive. The original drive letter can be restored by either using thehtblconf.exeGUI utility or theChangeHTBootloaderDrive.ps1PowerShell script.- If desired, log into the Cryptographic Security Platform Vault webGUI and verify that the new boot drive size is displayed correctly. If it is not, go back to the Windows VM and enter the
hcl updateavailcommand.