The following prerequisites apply to all types of Linux encryption, including data drive encryption and root, swap, or system device encryption in online or offline mode. To enable Online Encryption for the VM, see Linux Online Encryption Prerequisites and Considerations for additional prerequisites.

  • Make sure the Linux version you are using is supported. 
  • Important: Make sure that the /boot partition has at least 1GB of free space before starting root drive encryption.

  • If you intend to use this VM with a BoundaryControl-enabled Cloud VM Set, you must install a VMware-supported version of VMware Tools on the VM. For all other VMs, installing VMware Tools is recommended but not required. In all cases, we recommend keeping VMware Tools up to date.
  • If an entry for the Linux device you intend to encrypt already exists in the Filesystem Table (/etc/fstab), remove that entry until the encryption process is complete and the Entrust-created clear text path to the device is available. If you reboot the device after encryption with the /etc/fstab entry still pointing to the original device path, the system may hang because the encrypted version of the device will fail the filesystem check. For details, see Automatically Mounting Linux Filesystems.

  • We recommend partitioning the disk before encrypting it. When Cryptographic Security Platform Vault for VM Encryption encrypts a disk, it writes a private region at the start of the disk that contains information that allows it to identify which keys are associated with which partition.

    For example, let's say you have 2 non-partitioned disks, /dev/sdb and /dev/sdc, where /dev/sdc is encrypted by Cryptographic Security Platform Vault for VM Encryption. If you remove /dev/sdb and reboot the VM, /dev/sdc will be renamed /dev/sdb and the association between the keys and the disk will become invalid. At that point, you will lose access to the encrypted data.

    Now let's say you have the same setup as before, but you partition the disk /dev/sdc and then you encrypt the /dev/sdc1 partition. Cryptographic Security Platform Vault for VM Encryption adds a UUID (Universally Unique Identifier) in the private area at the start of the /dev/sdc disk that associates the /dev/sdc1 partition with its encryption keys. When you remove /dev/sdb and reboot the VM, the encrypted partition /dev/sdc1 will be renamed /dev/sdb1, but the UUID does not change. In this case, Cryptographic Security Platform Vault for VM Encryption can use the UUID to match the encryption keys to the partition and the data remains accessible even after the partition name has changed.

    Important: If you want to resize a partition after encrypting it with Cryptographic Security Platform Vault for VM Encryption, you must take additional steps. For more information, see Disk Size Management in Linux.

  • Make sure the Linux VM has access to the following Linux packages and their dependencies:

    Encryption type

    Required packages

    Note

    All Linux encryption (data drives and system devices)

    device-mapper

    OpenSSL

    Python 2.7 or Python 3


    Linux root, swap, or system device encryption


    busybox

    cryptsetup or cryptsetup-luks

    dracut (RHEL) or initramfs-tools (Ubuntu)

    dracut-network

    dropbear

    EPEL-release

    hashalot

    OpenSUSE

    If the server to be encrypted has external internet access, it will install any missing packages when you encrypt the root, swap, or system device. If the server is not connected to the internet, these packages must be fully installed before root/swap encryption begins, or the encryption request will fail.

    Linux online encryption (data drives and system devices)

    dkms

    gcc

    kernel-devel (RHEL)

    kernel-headers (RHEL)

    linux-headers-<kernel-version> (Ubuntu)


  • Cryptographic Security Platform Vault for VM Encryption supports disk encryption for disks formatted with btrfs. If the root file system or system mount (for example, /var, /usr, /etc) is btrfs and you have multiple storage disks, only the first disk can be encrypted. The first disk will have an entry in /etc/fstab. 

    We recommend creating btrfs on an MBR or GPT partition, not on a RAW device. RAW devices are vulnerable to device name changes, which will render the encrypted device unusable.

  • For a given client, you can have either online or offline encryption. You cannot mix them on the same client.