When you first install the Policy Agent on a VM, you register the VM with Cryptographic Security Platform Vault using a certificate created by Cryptographic Security Platform Vault for VM Encryption for that VM. If the certificate is about to expire, you need to re-authenticate the VM with a new certificate. If you do not re-authenticate the VM and the certificate expires, Cryptographic Security Platform Vault for VM Encryption waits for a given amount of time and then detaches the encrypted drives from the VM so that they can no longer be accessed. The drives will remain detached until the certificate is renewed.
Note: The amount of time Cryptographic Security Platform Vault for VM Encryption waits before detaching the drives is determined by the Grace Period set for the VM. For details, see Changing the Properties for a Specific VM.
By default, Cryptographic Security Platform Vault for VM Encryption automatically renews the certificate for a VM based on the setting of the Certificate Auto Renewal Period option on both the Cloud VM Set and the VM itself. For details, see Creating a Cloud VM Set for the CSP Vault for VM Encryption and Changing the Properties for a Specific VM.
If you have elected to disable auto-renewal, you need to reauthenticate the VM with a new certificate through the webGUI or hicli before the old certificate expires in order to avoid an interruption in service. For details, see Renewing a VM Certificate.
Cryptographic Security Platform Vault for VM Encryption generates alerts with increasing frequency when the certificate expiration date nears. If the certificate expiration date is:
- More than three months away, no alert is generated.
- Three months away, Cryptographic Security Platform Vault for VM Encryption generates one alert.
- Two months away, Cryptographic Security Platform Vault for VM Encryption generates one alert.
- Between four weeks to one week, Cryptographic Security Platform Vault for VM Encryption generates an alert once a week.
- In the final week and for the next week after expiration, Cryptographic Security Platform Vault for VM Encryption generates an alert every day.
- After the first week, Cryptographic Security Platform Vault for VM Encryption generated an alert every week for the next month.
- For the second and third months after expiration, Cryptographic Security Platform Vault for VM Encryption generates one alert each month.
- After the third month, no alert is generated.
This section includes: