Backups, clones, and snapshots look identical to Cryptographic Security Platform Vault for VM Encryption. If you want both a VM and its clone running at the same time, you need to clone the VM certificate issued to the original VM and then register the clone using that certificate.
If the root drive is encrypted on the VM, you must register the certificate from the debug console or the VM console. For details, see Registering a Linux or Windows Root-Drive-Encrypted Cloned VM with Simplified Authentication.
If only data drives are encrypted on the VM, there are two ways to register the certificate:
- Standard Authentication—The most secure authentication method. You create a certificate in the Cryptographic Security Platform Vault for VM Encryption webGUI which you then copy to the target system. This method is described below.
- Simplified Authentication—The easiest method. It allows you to skip downloading a certificate from the Cryptographic Security Platform Vault for VM Encryption webGUI, but it does require you to enter the Cryptographic Security Platform Vault for VM Encryption credentials on the command line. You should only use this method if the VM is secure. For details, see Registering a Cloned VM with Simplified Authentication.
Procedure
- Log into the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
- In the top menu bar, click Workloads.
- Click the VMs tab.
- Select the VM that you want to clone from the list.
- Select Actions > Clone Certificate.
- Optionally enter a passphrase for the certificate. If you enter one here, you will be required to enter the same passphrase when you register the cloned VM.
- If you want to change the date on which the certificate expires, enter a new date in the Date field.
- When you are done, click Clone. Cryptographic Security Platform Vault creates a cloned certificate and copies it to your browser's default download location.
- Copy the certificate to the cloned VM.
Register the cloned VM using the command
hcl register -c [-h myname] [-d description] [-v vault-id]][-p certificate_password] [-o one_time_passphrase] kc_hostname[:port],kc_hostname2[:port2],... /path/to/certificate.cert, where:-cindicates that this is a cloned VM.-hspecifies the name associated with this VM. This name is visible in the webGUI and through APIs.-dis an optional description for the VM.-vis the Vault ID of the Vault. This is displayed in the About section for each vault under the help icon (?) at the top right corner. If you do not enter a vault ID you will be prompted for one.-pis the password for the certificate if one was entered when the certificate was created. If you omit this option and a password is required, you will be prompted for the password when you execute the command.-ois a one-time passphrase that will be used to authenticate the VM with the Cryptographic Security Platform Vault for VM Encryption through the webGUI. If you do not specify a passphrase, you will be prompted for one when you execute the command. The passphrase must contain at least 16 alphanumeric characters.kc-hostname[:port],kc-hostname2[:port],...(required)—The list of IP addresses or hostnames for the Cryptographic Security Platform Vault nodes with which you want to register the VM. You must specify at least one Cryptographic Security Platform Vault node in this list. You must also specify a port if the Cryptographic Security Platform Vault nodes use anything other than the default port (443). On Windows, if you specify more than one IP address, enclose the list in double-quotes.- The final option is the fully-qualified name of the certificate that you downloaded from the Cryptographic Security Platform Vault for VM Encryption webGUI.
For example:
# hcl register -c -h "ubuntu-12.10" -d "My 12.10 VM" 192.168.140.15\ -v "efe47ad3-26d7-49cf-b09d-538f0fc5db29" bbd7d0c7-*_130415215216.cert Certificate passphrase might be required Certificate successfully unpacked You need to specify a passphrase which will be used for authentication with KeyControl Enter passphrase (min 16 characters): onetimepassword16chrs Registered as ubuntu-12.10 with KeyControl(s) 192.168.140.15 Please log on to any KeyControl to complete the authentication of this node
Return to the webGUI and authenticate the VM:
- Click the Unauthenticated VMs tab.
- Select the clone VM you just registered.
- Select Actions > Authenticate.
- Enter the one-time passphrase at the prompt.
- If you want to change the Cryptographic Security Platform Vault for VM Encryption node IP addresses the clone VM will use, see Updating CSP Vault Node IP Addresses on an Individual VM. If you want to associate a Cluster Node Mapping with the clone VM, see Managing the Cluster Node Mapping on a VM.