6.7

Table Of Contents
Assume that a cluster has three ESXi hosts, host A, B, and C. You add an encrypted virtual machine to
host A. What happens depends on several factors.
n
If hosts A, B, and C already have encryption enabled, you need only Cryptographic
operations.Encrypt new privileges to create the virtual machine.
n
If hosts A and B are enabled for encryption and C is not enabled, the system proceeds as follows.
n
Assume that you have both the Cryptographic operations.Encrypt new and the
Cryptographic operations.Register host privileges on each host. In that case, the virtual
machine creation process enables encryption on host C. The encryption process enables host
encryption mode on host C, and pushes the key to each host in the cluster.
For this case, you can also explicitly enable host encryption on host C.
n
Assume that you have only Cryptographic operations.Encrypt new privileges on the virtual
machine or virtual machine folder. In that case, virtual machine creation succeeds and the key
becomes available on host A and host B. Host C remains disabled for encryption and does not
have the virtual machine key.
n
If none of the hosts has encryption enabled, and you have Cryptographic operations.Register host
privileges on host A, then the virtual machine creation process enables host encryption on that host.
Otherwise, an error results.
Disk Space Requirements
When you encrypt an existing virtual machine, you need at least twice the space that the virtual machine
is currently using.
Encrypted vSphere vMotion
Starting with vSphere 6.5, vSphere vMotion always uses encryption when migrating encrypted virtual
machines. For virtual machines that are not encrypted, you can select one of the encrypted vSphere
vMotion options.
Encrypted vSphere vMotion secures confidentiality, integrity, and authenticity of data that is transferred
with vSphere vMotion.
n
For unencrypted virtual machines, all variants of encrypted vSphere vMotion are supported. Shared
storage is required for migration across vCenter Server instances.
n
For encrypted virtual machines, migration across vCenter Server instances is not supported.
What is Encrypted
For encrypted disks, the data is transmitted encrypted. For disks that are not encrypted, Storage vMotion
encryption is not supported.
For virtual machines that are encrypted, migration with vSphere vMotion always uses encrypted vSphere
vMotion. You cannot turn off encrypted vSphere vMotion for encrypted virtual machines.
vSphere Security
VMware, Inc. 147