You can change the name, description, or permissions list associated with an existing Access Control Policy, but you cannot change the OS Type or Cloud Administration Group for the policy.

If a VM contains one or more disks associated with the policy you are changing, Cryptographic Security Platform Vault communicates the changes at the VM's next heartbeat. If the policy is associated with disks on more than one VM, this means that policy changes may not take effect on all associated disks at the same time because the VMs may be on different heartbeat schedules.

Before You Begin 

Make sure password-based SSH login is enabled for the VM. If it is not, the process will fail and the Access Control Policy will not be updated on the VM. For details, see Access Control Requirements and Considerations.

Procedure 

  1. Log into the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
  2. In the top menu bar, click Workloads.
  3. Navigate to the Access Control Policies tab.
  4. Click on the policy you want to change. The Cryptographic Security Platform Vault webGUI displays details about the policy and its associated rules in the Details area under the Policy table.
  5. If you want to change the policy name or description, select Actions > Edit Policy. In the Edit Policy Wizard Details page, change the policy name or description if desired. You cannot change the OS Type or the Cloud Administration Group specified for the policy.
  6. To edit the existing rule, select Actions > Edit Rule and make the desired changes. Make sure that any entries you add contain a valid local VM username. Cryptographic Security Platform Vault does not support domain-qualified usernames in Linux.

  7. When you are finished, click Done. Cryptographic Security Platform Vault saves the rule changes immediately and applies them to the associated disks the next time the VMs containing those disks heartbeat with Cryptographic Security Platform Vault.

What to Do Next 

If you want to force an update on one or more VMs so that the Access Control Policy changes are applied before the next scheduled heartbeat, you can log into the VMs as an administrator and use the hcl heartbeat command.

Important: The heartbeat command may take a few minutes to complete the first time an Access Control Policy is associated with the disk. If you use this command, make sure you wait for it to complete because interrupting the policy association process may cause issues on the VM.