VMware on Aruba Cloud > Virtual Private Cloud > VMware vCloud Director > KMS encrypted keys: configuration and management policies

3.5 KMS encrypted keys: configuration and management policies

Requirements

Uploading the certificate and private key created using KMS

  • sign in to VMware Cloud Director;
  • in the left menu, under More select Encryption Management;
  • in the Key Providers section, click on ALL ACTIONS and select Update account;
  • select the Client certificate option and paste the certificate (in the Certificate area) and the private key (in the Private Key area);
  • tick confirm at the bottom of the page and click on UPDATE.

Choose which vDC to encrypt and which policies to apply

The items in the vDC that can be encrypted are: vApps, VMs and named Disks.
  • sign in to VMware Cloud Director;
  • in the left menu, under More select Encryption Management;
  • in the Key Providers section, click on ALL ACTIONS and select Encrypt Org vDCs;
  • Type of Key and Rotation Schedule
    • in the Key Type area, you need to choose between two options:
      • Use the same key every time: generate a single key to encrypt all items in the vDC;
        • if you choose this option, click on GENERATE KEY;
      • Generate a new key every time: generate a different, one-time key to encrypt individual items in the vDC;
    • enabling the Setup Key Rotation Schedule option allows you to set up a change of created keys on a daily, weekly or monthly basis;
    • click on NEXT;
  • Organization VDC
    • all vDCs will be listed, with the Encryption State column showing which are already protected (Encrypted);
    • select which vDCs you want to protect; if you choose one that is already key-protected, the key will be replaced by the new one;
    • click on NEXT;
  • Storage Policies
    • in the Storage Policies area, you need to choose between two options:
      • All storage policies: all encrypted storage in the vDC will be encrypted;
      • Specific storage policies: you need to choose which encrypted storage in the vDC you want to encrypt;
         
        If you want to encrypt a specific VM, you must select the associated storage.
    • click on NEXT;
  • Review
    • details of the encryption policies applied will be displayed;
    • click on SUBMIT.

Compatible services and limitations

DRaaS Zerto not compatible
DRaaS vCAv cloud-to-cloud compatible on Aruba Cloud with the same KMS service
DRaaS Veeam Cloud Connect compatible in an non-encrypted on-premises to encrypted DR in Aruba cloud scenario
Business Continuity Virtual Private Cloud 2.0 no limitations
BaaS Veeam Cloud Bare Metal Backup not compatible