A VM must be part of a Cloud VM Set before you can encrypt it. The set controls global options for the VMs it contains. It also lets you enable the BoundaryControl feature, which uses Policy Rules and constraints in Entrust CloudControl to authenticate and authorize delivery of encryption keys for data encrypted by the Entrust Policy Agent and managed by Cryptographic Security Platform Vault for VM Encryption.
Before You Begin
If you want to use a Key Encryption Key (KEK) with the Cloud VM Set, Cryptographic Security Platform Vault for VM Encryption must have access to a hardware security module (HSM) in which it can store the KEK. For more information, see KEKs with Cloud VM Sets.
Procedure
- Log in to the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
- In the top menu bar, click Workloads.
- Select Actions > Create New Cloud VM Set.
- On the VM Set tab:
- Enter a name for the Cloud VM Set.
- Select the group to which this set should belong, or accept the default.
- Optionally enter a description for the set.
To specify additional options, click the Additional Properties tab and select the options you want to use.
Option
Description
Heartbeat
The length of time between the heartbeats each VM in the set sends to the Cryptographic Security Platform Vault for VM Encryption to verify that the connection between them is functioning normally. You can specify seconds, minutes, hours, or days. The default is 5 minutes. Set this value to at least 10 seconds.
If you make changes to the VMs through the Cryptographic Security Platform Vault for VM Encryption webGUI, those changes are communicated to the VMs during the heartbeat. That means if the heartbeat is set to 5 minutes, then it can take up to 5 minutes for any changes made in the Cryptographic Security Platform Vault for VM Encryption webGUI to be applied to the VMs in the set.
If a VM cannot reach the Cryptographic Security Platform Vault for VM Encryption during the heartbeat, the VM continues to run, but it does not pick up any changes until the next successful heartbeat. Cryptographic Security Platform Vault for VM Encryption sets the VM status to Unreachable, but takes no further action unless the heartbeat continues to fail after the Grace Period has expired.
Grace Period
The length of time that can pass without a successful heartbeat. The default is 1 day. You can specify the grace period in seconds, minutes, hours, or days.
If a VM remains unresponsive past the grace period, access to the VM's data will be unavailable until the VM is re-authenticated with Cryptographic Security Platform Vault for VM Encryption.
Max Parallel Rekey Operations
The number of concurrent Auto Rekey operations that can be performed for VMs in the Cloud VM Set. The default is 1.
Rekey Interval
If you specify any value other than 0 (zero) for this option, the Cryptographic Security Platform Vault periodically creates a rekey task for every encrypted disk in every VM registered with this Cloud VM Set. You can select any number of days, weeks, months, or years, and the Cryptographic Security Platform Vault for VM Encryption will automatically rekey the encrypted disks on that schedule.
To disable Auto Rekey, enter 0 in this field. By default, Auto Rekey is disabled.
Maximum VMs allowed
The maximum number of cloud VMs allowed to register in this Cloud VM Set. The default is unlimited.
Certificate Auto Renewal Period
If you want Cryptographic Security Platform Vault for VM Encryption to automatically renew the certificate for a VM in this Cloud VM Set, enter an integer greater than zero in this field. Cryptographic Security Platform Vault for VM Encryption will renew the certificate that many days before the old one expires. For example, if you enter 5 in this field and a VM certificate is set to expire on June 12, 2022, Cryptographic Security Platform Vault for VM Encryption will renew the license on June 7, 2022. The default is 10 days. The expiry date is always 1 year from the date the certificate was created or renewed.
To change the renewal period, click the existing value and enter a new value in the text field, then select days/weeks/months/years from the drop-down list. When you are finished, click Save.
If you want to disable certificate auto-renewal, enter 0 (zero) in this field.
Note: If you have auto-renewal enabled but the renewal fails, Cryptographic Security Platform Vault for VM Encryption will keep retrying until the certificate is valid. When the certificate is no longer valid, the admin password will be required.
Certificate Expiration
The length of time for which a VM certificate will be valid when it is first registered with Cryptographic Security Platform Vault or when it is auto-renewed by Cryptographic Security Platform Vault. The default is 1 year.
To change the expiration, click the existing value and enter a new value in the text field, then select days/weeks/months/years from the drop-down list. When you are finished, click Save.
Note: If you change this value for an existing Cloud VM Set, the certificate expiration date does not change for any VMs currently in the set. This value applies only to new VMs or when the certificates for existing VMs are renewed.
Auto Encryption
If this option is enabled, whenever a new VM is registered with this Cloud VM Set, Cryptographic Security Platform Vault for VM Encryption will automatically instruct the Policy Agent to encrypt one or more of the drives on that VM.
To enable this option, click Disabled, select Enabled from the drop-down list, then click Save. When you do so, the webGUI displays the Encryption Policy fields:
- Auto Encryption Policy Type. This can be:
- Exclude—The Windows drives and Linux devices listed in the Auto Encryption Policy Path(s) field will not be automatically encrypted, although they can be encrypted manually at any time. This is the default.
- Include—The Windows drives and Linux devices listed in the Auto Encryption Policy Path(s) field will be automatically encrypted. You must encrypt all other drives or devices on the VM manually.
- Encrypt All Devices—Automatically encrypts all Windows drives and Linux devices.
Auto Encryption Policy Path(s)—If the policy type is Include or Exclude, enter a path that should be included or excluded. To add additional paths, click the + (Plus sign) in this field. You can enter either a Windows drive or a Linux device name. For example, any of the following would be valid path names:
C:,C:\data, orsdb1.Important: Each path must be on its own line.
For more information, see Automatic Data Encryption.
Decryption Allowed
If this option is set to Yes, the drives and devices in the VMs registered with this Cloud VM Set can be decrypted. If it is set to No, any decryption request will fail.
Policy Agent Uninstallation Allowed
If this option is set to Yes, you can uninstall the Policy Agent on the VMs registered with this Cloud VM Set. If it is set to No, you cannot uninstall the Policy Agent.
- Auto Encryption Policy Type. This can be:
To specify when VMs in the Cloud VM Set need to be re-authenticated, click the Reauthentication Settings tab and select the options you want to use.
Option
Description
Reauthentication on IP Change
Whether a VM in the set must be re-authenticated when the VM's IP address changes. The default is No.
If your system configuration uses DHCP or multiple NICs, do not set this option to Yes. If you do, the VMs in the set may enter a reboot loop if their boot partitions are encrypted and any encrypted drives may be detached.
Reauthentication on H/W Signature Change
Whether a VM in the set must be re-authenticated if its MAC address or UUID changes.
The options are:
Yes—If either the MAC address or the UUID changes, the VM requires reauthentication. This is the default. We recommend that you do not change this option.
- Permissive—Both the MAC address and the UUID must change before the VM requires reauthentication. You can use this option if your system administrators perform maintenance on the VMs in this Cloud VM Set that requires changes to the network cards and, therefore, to the VMs' MAC addresses. We recommend you reset this value to Yes once maintenance is finished.
No—The Cryptographic Security Platform Vault for VM Encryption does not require reauthentication if a VM's MAC address or UUID changes. We strongly recommend that you do not select this option. If you do, a cloned or misconfigured VM could gain access to the keys associated with the original VM.
If you do select this option, you must confirm the selection before you can proceed. If Cryptographic Security Platform Vault for VM Encryption detects multiple VMs with the same MAC address and UUID combination when hardware validation is off, it generates an alert every 8 hours until the cloned VMs stop heartbeating or hardware authentication is set to Yes or Permissive. In addition, Cryptographic Security Platform Vault for VM Encryption generates an alert when client operations, such as key access or device registration, occur on the cloned VMs.
Reauthentication on Reboot
Whether a VM in the set must be re-authenticated every time it reboots. The default is No.
Setting this value to Yes is similar to requiring a boot-time password before the VM can fully start.
If you want to specify a key encryption key (KEK), click the Key Encryption Key tab, choose the type of Key Encryption Key Association, and then specify the required information.
A KEK provides an extra layer of security by encrypting the individual data encryption keys on the VMs associated with this Cloud VM Set. It also controls the expiration and revocation of those data encryption keys. To protect the KEK, Cryptographic Security Platform Vault requires that you store the KEK in the hardware security module (HSM) associated with this Cryptographic Security Platform Vault cluster. For more information, see KEKs with Cloud VM Sets.
You can add the KEK during Cloud VM Set creation or later.
Determine whether Cryptographic Security Platform Vault for VM Encryption creates a KEK for this Cloud VM Set. To use a KEK, select Use KEK from the drop-down list and click Save to view the KEK properties.
If you do not make a selection, then the default value is No KEK Association is used, and the tab is not populated. If you decide you want to use a KEK, you can add the KEK to the Cloud VM Set later.
If you selected USE KEK, complete the following:
Option
Description
Key Expiration Period
The length of time for which the KEK and all data encryption keys on the VMs will be valid. To indicate that the KEK should never expire, set this field to 0 (zero). This is the default.
If you change the Key Expiration Period, the new expiration period begins from the day you make the change, not from the day the Cloud VM Set was created.
When this time period expires:
- All disks on all VMs in the Cloud VM Set are automatically detached. What happens to the keys depends on the setting in the Key Expiration Action field.
- Any attempt to register a new VM with the Cloud VM Set will fail.
- Any encrypt or decrypt operation on any of the associated VMs will fail.
To change the expiration period, click the existing value and enter a new value in the text field, then select days/weeks/months/years from the drop-down list. When you are finished, click Save.
Note: If the Key Expiration Option field is set to Change, you can shorten the expiration period, but you cannot lengthen it beyond the original date.
Key Expiration Action
The options are:
- No Use—The KEK and all data encryption keys are deactivated but retained. You can reactivate the keys and extend the expiration date if the Key Expiration Option field is set to Extend. This is the default.
Shred—The KEK and all data encryption keys are destroyed and cannot be retrieved. In addition, all VMs in the set are removed from Cryptographic Security Platform Vault for VM Encryption and the Cloud VM Set itself is deleted.
Shred is a destructive action that cannot be undone. Make sure you have set the correct Key Expiration Period when using this option.
Key Expiration Option
The options are:
- No Change—You cannot change the KEK expiration options after the Cloud VM Set has been created. This is the default. Selecting this option means that once the top-level key expires, it cannot be reactivated, and all VMs will be automatically detached from Cryptographic Security Platform Vault for VM Encryption when the expiration date is reached.
- Change—You can change the KEK expiration options after the Cloud VM Set has been created, but you cannot extend the Key Expiration Period beyond the original date. This is the default.
- Extend—You can change all KEK expiration options after the Cloud VM Set has been created.
To use a Single Encryption Key (SEK) for the VMs in this Cloud VM Set, click the Single Encryption Key tab and enter the required information.
If you enable this option, all the VMs registered with the Cloud VM Set will be encrypted with the same encryption key, and the key's expiry date and expiration option will be set at the Cloud VM Set level instead of at the disk level. Using a SEK enables data deduplication because identical blocks at the same offset are encrypted with the same key and therefore remain identical after encryption. For details, see Data Deduplication with Cloud VM Sets.
Option
Description
Single Key Encryption State
This feature is Disabled by default. To enable it, click Disabled, select Enabled from the drop-down list, then click Save. After you click Save, the Cryptographic Security Platform Vault for VM Encryption webGUI displays the remaining SEK option fields.
Single Key Encryption Expiration
The date the SEK key will expire, or "Never" if it never expires. If you specify a date and the SEK key expires, access to every encrypted disk on every VM in the Cloud VM Set will be denied. What happens to the SEK key depends on the setting in the Expiration Action field.
Single Key Encryption Expiration Action
- No Use—The key is deactivated but retained. You can reactivate it by setting a future expiration date or by setting the expiration date to "Never". At that point, all access to the encrypted data will be restored. This is the default.
- Shred—The key is destroyed and cannot be retrieved. Use this option only if you are absolutely certain you will never need to access data encrypted by this key again. If you shred a key, you cannot decrypt any data encrypted with it.
- After you finish specifying the Cloud VM Set options, click Create.
- When you see the Cloud VM Set Successfully Created message, click Close.
What to Do Next
Install the Policy Agent on the VM(s) you want to encrypt and register it with Cryptographic Security Platform Vault. For details, see the installation and administration guide at: