1. Log into the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
  2. In the top menu bar, click Workloads.
  3. Click the VMs tab.
  4. To view the details for a VM, click the Expand button (>) at the end of the row.

    Cryptographic Security Platform Vault displays the details for the VM along with a VM-specific Actions button that allows you to manage the selected VM without affecting other VMs registered with Cryptographic Security Platform Vault.

VM Status Information

The VM Status can be one of the following:

  • Not registered — The Policy Agent software is installed but the VM has not yet been registered with Cryptographic Security Platform Vault.
  • Connected — The VM can communicate with the Cryptographic Security Platform Vault for VM Encryption and everything is running normally.
  • Could not connect — The Cryptographic Security Platform Vault for VM Encryption is not reachable. If this condition continues, the VM will need to be re-authenticated with the Cryptographic Security Platform Vault for VM Encryption when communication is re-established.
  • Need to update certificate — The certificate for the is VM is no longer valid and should be updated.
  • Reauth needed — The VM needs to be re-authenticated.
  • Virtual Machine not authenticated — VM permissions have been revoked from the Cryptographic Security Platform Vault for VM Encryption. To fix this issue, see Reactivating a Revoked Disk.
  • Identity verification failed — Permissions are not available because the VM heartbeat has timed out or its IP address or hardware signature has changed. This can occur if you have changed the IP address on a VM or copied the VM to a new server.
  • Unknown error from KeyControl cluster — An unknown error has occurred. Please contact support if you see this message.

VM Details Area

The VM Details area contains the following tabs:

  • Details — Shows the basic information about the VM including its certificate status, rekey interval, and the version of the Entrust Policy Agent installed on the VM.
  • Reauthentication Settings — Shows whether Cryptographic Security Platform Vault requires you to reauthenticate the VM when its IP address changes, its hardware signature changes, or it reboots.
  • Encrypted Disks — Shows the status of the VM's encrypted disks, including both regular disks and Windows folder mounts.
  • Unencrypted Disks — Shows the disks and Windows folder mounts available for encryption.
  • User Tasks — Shows the tasks that were started by a Cryptographic Security Platform Vault user. This list includes any manually-initiated disk encryption or decryption tasks and the status of any changes to the Cluster Node Mapping assigned to the VM.
  • System Tasks — Shows the tasks that were started automatically by Cryptographic Security Platform Vault. This list includes any auto encryption tasks for the VM.