6.5.1

Table Of Contents
4 (Optional) If you prefer, you can encrypt virtual disks from the Edit Settings menu.
a Right-click the virtual machine and select Edit Settings
b Leave Virtual Hardware selected.
c Open the virtual disk for which you want to change the storage policy and make a selection from
the VM Storage Policy pull-down menu.
d Click OK.
Decrypt an Encrypted Virtual Machine or Virtual Disk
You can decrypt a virtual machine by changing its storage policy.
All encrypted virtual machines require encrypted vMotion. During virtual machine decryption, the
Encrypted vMotion setting remains. To change this setting so that Encrypted VMotion is no longer used,
change the setting explicitly.
This task explains how to perform decryption using storage policies. For virtual disks, you can also
perform decryption using the Edit Settings menu.
Prerequisites
n
The virtual machine must be encrypted.
n
The virtual machine must be powered off or in maintenance mode.
n
Required privileges: Cryptographic operations.Decrypt
Procedure
1 Connect to vCenter Server by using the vSphere Web Client.
2 Right-click the virtual machine that you want to change and select VM Policies > Edit VM Storage
Policies..
You can set the storage policy for the virtual machine files, represented by VM home, and the storage
policy for virtual disks.
3 Select a storage policy from the drop-down menu.
n
To decrypt the virtual machine and its hard disks, click Apply to all.
n
To decrypt a virtual disk but not the virtual machine, select a storage policy for the virtual disk
from the drop-down menu in the table. Do not change the policy for VM Home.
You cannot decrypt the virtual machine and leave the disk encrypted.
4 Click OK.
5 (Optional) You can now change the Encrypted VMotion setting.
a Right-click the virtual machine and click Edit Settings.
b Click VM Options, and open Encryption.
c Set the Encrypted vMotion value.
vSphere Security
VMware, Inc. 168