6.5.1

Table Of Contents
3 Right-click the object, select New Virtual Machine > New Virtual Machine, and follow the prompts to
create an encrypted virtual machine.
Option Action
Select a creation type Create a virtual machine.
Select a name and folder Specify a name and target location.
Select a compute resource Specify an object for which you have privileges to create encrypted virtual
machines. See Prerequisites and Required Privileges for Encryption Tasks.
Select storage In the VM storage policy, select the encryption storage policy. Select a compatible
datastore.
Select compatibility Select the compatibility. You can migrate an encrypted virtual machine only to
hosts with compatibility ESXi 6.5 and later.
Select a guest OS Select a guest OS that you plan to install on the virtual machine later.
Customize hardware Customize the hardware, for example, by changing disk size or CPU.
Any New Hard disk that you created is encrypted. You can change the storage
policy for individual hard disks later.
Ready to complete Review the information and click Finish.
Clone an Encrypted Virtual Machine
When you clone an encrypted virtual machine, the clone is encrypted with the same keys. To change
keys for the clone, power off the clone and perform a shallow recrypt of the clone using the API. See the
vSphere Web Services SDK Programming Guide.
You do not have to power off the virtual machine to clone it.
Prerequisites
n
Establish a trusted connection with the KMS and select a default KMS.
n
Create an encryption storage policy.
n
Required privileges:
n
Cryptographic operations.Clone
n
If the host encryption mode is not Enabled, you also must have Cryptographic
operations.Register host privileges.
Procedure
1 Connect to vCenter Server by using the vSphere Web Client.
2 Select an object in the inventory that is a valid parent object of a virtual machine, for example, an
ESXi host or a cluster.
vSphere Security
VMware, Inc. 166