6.7

Table Of Contents
Prerequisites and Required Privileges for Encryption
Tasks
Encryption tasks are possibly only in environments that include vCenter Server. In addition, the ESXi host
must have encryption mode enabled for most encryption tasks. The user who performs the task must
have the appropriate privileges. A set of Cryptographic Operations privileges allows fine-grained
control. If virtual machine encryption tasks require a change to the host encryption mode, additional
privileges are required.
Cryptography Privileges and Roles
By default, the user with the vCenter Server Administrator role has all privileges. The No cryptography
administrator role does not have the following privileges that are required for cryptographic operations.
n
Add Cryptographic Operations privileges.
n
Global.Diagnostics
n
Host.Inventory.Add host to cluster
n
Host.Inventory.Add standalone host
n
Host.Local operations.Manage user groups
You can assign the No cryptography administrator role to vCenter Server administrators that do not
need Cryptographic Operations privileges.
To further limit what users can do, you can clone the No cryptography administrator role and create a
custom role with only some of the Cryptographic Operations privileges. For example, you can create a
role that allows users to encrypt but not to decrypt virtual machines. See Using Roles to Assign
Privileges.
Host Encryption Mode
You can encrypt virtual machines only if host encryption mode is enabled for the ESXi host. Host
encryption mode is often enabled automatically, but it can be enabled explicitly. You can check and
explicitly set the current host encryption mode from the vSphere Web Client or by using the vSphere API.
For instructions, see Enable Host Encryption Mode Explicitly.
After Host encryption mode is enabled, it cannot be disabled easily. See Disable Host Encryption Mode.
Automatic changes occur when encryption operations attempt to enable host encryption mode. For
example, assume that you add an encrypted virtual machine to a standalone host. Host encryption mode
is not enabled. If you have the required privileges on the host, encryption mode changes to enabled
automatically.
vSphere Security
VMware, Inc. 146