Backups, clones, and snapshots look identical to Cryptographic Security Platform Vault for VM Encryption. If you want both a VM and its clone running at the same time, you need to clone the VM certificate issued to the original VM and then register the clone using that certificate.

If the root drive is encrypted on a Linux or Windows VM, you must access the VM through your hypervisor and use the Entrust Debug Console as described below.

If only data drives are encrypted on the VM, there are two ways to register the certificate:

  • Standard Authentication—The most secure authentication method. You create a certificate in the Cryptographic Security Platform Vault for VM Encryption webGUI which you then copy to the target system. For details, see Registering a Cloned VM with Standard Authentication.
  • Simplified Authentication—The easiest method. It allows you to skip downloading a certificate from Cryptographic Security Platform Vault for VM Encryption webGUI, but it does require you to enter the Cryptographic Security Platform Vault for VM Encryption credentials on the command line. You should only use this method if the VM is secure. For details, see Registering a Cloned VM with Simplified Authentication.

Procedure 

  1. Power on the cloned Linux or Windows VM. The cloned VM's attempt to boot will fail because Cryptographic Security Platform Vault determines that the cloned VM has a different hardware signature than the original VM.
  2. Open console access to the cloned VM through your hypervisor and wait for the VM to display the prompt asking if you want to use the Entrust Debug Console. When it does, type y and press Enter to launch the Debug Console.
  3. From the Debug Console menu, select Advanced Access.
  4. If you are using a static IP address for the cloned VM, do the following to change the IP address. (If you are using DHCP, the system automatically assigns a new IP address to the cloned VM.) In the following examples, the original VM's IP address is 10.238.66.240 and the clone's IP address is 10.238.66.100.

    1. Add the new IP address you want to use for the cloned VM by entering the ip addr add <clone IP address>/<netmask> dev <interface name> command. For example:

      # ip addr add 10.238.66.100/24 dev eth0

    2. Delete the IP address being used by the original VM by entering the ip addr del <original VM IP address>/<netmask> dev <interface name> command. For example:

      # ip addr del 10.238.66.240/24 dev eth0

    3. If needed, add the clone IP address to the routing table with the ip route add [default] <network/netmask> [via <gateway IP address>|dev <device>] command.

  5. Update the certificate on the cloned VM by entering the command hcl updatecert -a [-u username -p password] [-e certificate expiration] command, where:

    • -a tells hcl to contact Cryptographic Security Platform Vault to get the new certificate.
    • -u is a Cryptographic Security Platform Vault user account with Cloud Admin privileges. If you do not enter a user account name you will be prompted for one.
    • -p is the password for the Cryptographic Security Platform Vault user account. If you do not enter a password you will be prompted for one.
    • -e is the certificate expiration date in the format MM/DD/YYYY. If you do not enter an expiration date, Cryptographic Security Platform Vault uses the default date set in the Certificate Expiration option for the Cloud VM Set that this VM belongs to. The default is one year from the creation date.

    For example:

    # hcl updatecert -a -u CloudAdmin -p DogDays123! -e 06/30/2022

  6. Register the cloned VM with Cryptographic Security Platform Vault by entering the following command:

    hcl register -w -a -c [-h vm-name] [-d "vm-description"] [-u username [-s password]] [-z cvm-set] [-v vault-_id] kc-hostname[:port],kc-hostname2[:port],...

    Important: For Windows systems, you must use the -w flag when registering cloned VMs.

    where:

    • -a indicates that hcl should download the VM certificate from Cryptographic Security Platform Vault and do the registration and authentication in one step.
    • -c indicates that this a cloned VM.
    • -h (optional)—The name of the clone VM that will be displayed in the Cryptographic Security Platform Vault webGUI (Default: hostname).
    • -d (optional)—A description of the clone VM that will be displayed in the Cryptographic Security Platform Vault webGUI.
    • -u is a Cryptographic Security Platform Vault user account with Cloud Admin privileges. If you do not enter a user account you will be prompted for one.
    • -s is the password for the Cryptographic Security Platform Vault user account. If you do not enter a password you will be prompted for one.
    • -z (optional)—The name of the Cloud VM Set defined in the Cryptographic Security Platform Vault cluster to which you want to assign this VM. If you do not specify this parameter, the registration prompts you for the set name.
    • -v—is the Vault ID of the Vault. This is displayed in the About section for each vault under the help icon (?) at the top right corner. If you do not enter a vault ID you will be prompted for one.
    • -w—Required for Windows only. This option generates a HWSIG that is appropriate for the Windows bootloader.
    • kc-hostname[:port],kc-hostname2[:port],... (required)—The list of IP addresses or hostnames for the Cryptographic Security Platform Vault nodes with which you want to register the VM. You must specify at least one Cryptographic Security Platform Vault node in this list. You must also specify a port if the Cryptographic Security Platform Vault nodes use anything other than the default port (443). On Windows, if you specify more than one IP address, enclose the list in double-quotes.

    For example, if the clone VM name is "hq-vm-clone", the description is "Clone of HQ Server", and you want to register it with two Cryptographic Security Platform Vault nodes at 10.238.32.74 and 10.238.32.75, you would enter:

    # hcl register -a -c -v d84243e7-d359-4179-9530-3497434e3192 -h hq-vm-clone -d "Clone of HQ Server" 10.238.32.74,10.238.32.75
    Please provide the Cryptographic Security Platform Vault login details
    username: htcloudadmin
    password:  ********
    
    Registered as hq-vm-clone with KeyControl node(s) 10.238.32.74,10.238.32.75
    
    Completing authentication for hq-vm-clone on KeyControl node(s) 10.238.32.74,10.238.32.75
    Authentication complete, machine ready to use
  7. After the VM has been registered, exit from the Advanced Access shell and let the VM finish booting. After the VM has booted, log into the clone VM as root and set the clone VM's IP address using your standard networking tools.
  8. Update the Entrust Bootloader network information with the htroot update [-c params.conf] command, where -c tells the command to run non-interactively.