Note: Changes to the Cloud VM Set properties are applied to any new VMs that are registered with the Cloud VM Set. If you want to change the properties for an existing VM, see Changing the Properties for a Specific VM.
- Log into the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
- In the top menu bar, click Workloads.
- On the VM Sets tab, select the Cloud VM Set whose properties you want to change. The Cryptographic Security Platform Vault webGUI displays the Cloud VM Set properties below the list of Cloud VM Sets.
On the Details tab, you can change any of the following options by clicking the entry in the field, setting the new value, and then clicking Save. You must click Save after each change or your changes will be lost when you select a different field.
Option
Description
Name
The name of the Cloud VM Set.
Description
A user-defined description of the Cloud VM Set.
Group
The Cloud Admin group to which this Cloud VM Set belongs.
VMs
The number of VMs registered to this set. Click the link in this field to view details about the individual VMs.
Heartbeat
The length of time between the heartbeats each VM in the set sends to the Cryptographic Security Platform Vault for VM Encryption to verify that the connection between them is functioning normally. You can specify seconds, minutes, hours, or days. The default is 5 minutes. This value should be set to a minimum of 10 seconds.
If changes have been made to the VMs through the Cryptographic Security Platform Vault for VM Encryption webGUI, those changes are communicated to the VMs during the heartbeat. That means if the heartbeat is set to 5 minutes, then it can take up to 5 minutes for any changes made in the Cryptographic Security Platform Vault for VM Encryption webGUI to be applied to the VMs in the set.
If a VM cannot reach the Cryptographic Security Platform Vault for VM Encryption during the heartbeat, the VM continues to run but any changes made are not picked up by the VM until the next successful heartbeat. Cryptographic Security Platform Vault for VM Encryption sets the status of the VM to Unreachable, but it takes no further action unless the heartbeat continues to fail after the Grace Period has expired.
Grace Period
The length of time that can pass without a successful heartbeat. The default is 1 day. You can specify the grace period in seconds, minutes, hours, or days.
If a VM remains unresponsive past the grace period, access to the data on the VM will be unavailable until the VM is re-authenticated with Cryptographic Security Platform Vault for VM Encryption.
Max Parallel Rekey Operations
The number of concurrent Auto Rekey operations that can be performed for VMs in the Cloud VM Set. The default is 1.
Rekey Interval
If you specify any value other than 0 (zero) for this option, Cryptographic Security Platform Vault periodically creates a rekey task for every encrypted disk in every VM that is registered with this Cloud VM Set. You can select any number of days, weeks, months, or years and the Cryptographic Security Platform Vault for VM Encryptionwill automatically rekey the encrypted disks on that schedule.
To disable Auto Rekey, enter 0 in this field. By default, Auto Rekey is disabled.
Certificate Auto Renewal Period
If you want Cryptographic Security Platform Vault for VM Encryption to automatically renew the certificate for a VM in this Cloud VM Set, enter an integer greater than zero in this field. Cryptographic Security Platform Vault for VM Encryption will renew the certificate that many days before the old one expires. For example, if you enter a value of 5 in this field and a VM certificate is set to expire on June 12, 2022, Cryptographic Security Platform Vault for VM Encryption will renew the license on June 7, 2022. The default is 10 days. The expiry date is always 1 year from the date the certificate was created or renewed.
To change the renewal period, click the existing value and enter a new value in the text field, then select days/weeks/months/years from the drop-down list. When you are finished, click Save.
If you want to disable certificate auto-renewal, enter 0 (zero) in this field.
Note: If you have auto-renewal set, but the renewal fails, Cryptographic Security Platform Vault for VM Encryption will continue to retry until the certificate is valid. When the certificate is no longer valid, the admin password will be required.
Certificate Expiration
The length of time for which a VM certificate will be valid when it is first registered with Cryptographic Security Platform Vault for VM Encryption or when it is auto-renewed by Cryptographic Security Platform Vault for VM Encryption. The default is 1 year.
To change the expiation, click the existing value and enter a new value in the text field, then select days/weeks/months/years from the drop-down list. When you are finished, click Save.
Note: If you change this value for an existing Cloud VM Set, the certificate expiration date is not changed for any of the VMs that are currently part of the set. This value only takes effect for new VMs or when the certificates for the existing VMs are renewed.
Single Encryption Key State
Whether the VMs in this Cloud VM Set are encrypted with the same Single Encryption Key (SEK) key. For information about changing the SEK properties, see Changing SEK Properties. For details about SEK usage with Cryptographic Security Platform Vault for VM Encryption, see Data Deduplication with Cloud VM Sets.
Single Encryption Key Cipher
The cipher used for all SEK keys. This value cannot be changed.
Note: This field is only displayed if the SEK state is Enabled.
Single Encryption Key Version
The highest version number among the SEK keys that have been created for this Cloud VM Set. To fully enable data deduplication, you should make sure that all encrypted disks on all VMs in the Cloud VM Set are using the same version of the SEK key.
For details, see Generating a New SEK Key.
Note: This field is only displayed if the SEK state is Enabled.
Auto Encryption
If this option is enabled, whenever a new VM is registered with this Cloud VM Set, Cryptographic Security Platform Vault for VM Encryption will automatically instruct the Policy Agent to encrypt one or more of the drives on that VM.
To enable this option, click Disabled, select Enabled from the drop-down list, then click Save. When you do so, the webGUI displays the Encryption Policy fields:
- Auto Encryption Policy Type. This can be:
- Exclude—The Windows drives and Linux devices listed in the Auto Encryption Policy Path(s) field will not be automatically encrypted, although they can be encrypted manually at any time. This is the default.
- Include—The Windows drives and Linux devices listed in the Auto Encryption Policy Path(s) field will beautomatically encrypted. All other drives or devices on the VM must be encrypted manually.
- Encrypt All Devices—All Windows drives and Linux devices will be automatically encrypted.
Auto Encryption Policy Path(s)—If the policy type is Include or Exclude, enter a path that should be included or excluded. To add additional paths, click the + (Plus sign) in this field. You can enter either a Windows drive a Linux device name. For example, any of the following would be valid path names:
C:,C:\data, orsdb1.Important: Each path must be on its own line.
For more information, see Automatic Data Encryption.
Decryption Allowed
If this option is set to Yes, the drives and devices in the VMs registered with this Cloud VM Set can be decrypted. If it is set to No, any decryption request will fail.
If you change this option, you can also propagate the change to all of the VMs that are currently registered with the Cloud VM Set. If you do not propagate the change, then this setting will be inherited only by new VMs registered with the Cloud VM Set.
Policy Agent Uninstallation Allowed
If this option is set to Yes, the Policy Agent can be uninstalled on the VMs registered with this Cloud VM Set. If it is set to No, the Policy Agent cannot be uninstalled.
If you change this option, you can also propagate the change to all of the VMs that are currently registered with the Cloud VM Set. If you do not propagate the change, then this setting will be inherited only by new VMs registered with the Cloud VM Set.
- Auto Encryption Policy Type. This can be:
On the Reauthentication Settings tab, you can change any of the following options by clicking the entry in the field, setting the new value, and then clicking Save. You must click Save after each change or your changes will be lost when you select a different field.
Option
Description
Reauthentication on IP Change
Whether a VM in the set must be re-authenticated when the VM's IP address changes. The default is No.
If your system configuration uses DHCP or multiple NICs, do not set this option to Yes. If you do so, the VMs in the set may go into a reboot loop if their boot partitions are encrypted and any encrypted drives may be detached.
Reauthentication on H/W Signature Change
Whether a VM in the set must be re-authenticated if its MAC address or UUID changes.
The options are:
Yes—If either the MAC address or the UUID changes, the VM requires reauthentication. This is the default. We recommend that you do not change this option.
- Permissive—Both the MAC address and the UUID must change before the VM requires reauthentication. You can use this option if your system administrators are performing maintenance on the VMs in this Cloud VM Set that require changes to the network cards and hence to the MAC addresses of the VMs in the set. We recommend you reset this value to Yes once maintenance is finished.
No—The Cryptographic Security Platform Vault for VM Encryption does not require reauthentication if VM's MAC address or UUID changes. We strongly recommend that you do not select this option. If you do, a cloned or misconfigured VM could gain access to the keys associated with the original VM.
If you do select this option, you must confirm the selection before you can proceed. If Cryptographic Security Platform Vault for VM Encryption detects multiple VMs with the same MAC address and UUID combination when hardware validation is off, Cryptographic Security Platform Vault for VM Encryption generates an alert every 8 hours until the cloned VMs stop heartbeating or hardware authentication is set to Yes or Permissive. In addition, Cryptographic Security Platform Vault for VM Encryption generates an alert when client operations, such as key access or device registration, occur on the cloned VMs.
Reauthentication on Reboot
Whether a VM in the set must be re-authenticated every time it reboots. The default is No.
Setting this value to Yes is similar to requiring a boot-time password before the VM can come up completely.