6.7

Table Of Contents
n
OVF Export is not supported for an encrypted virtual machine.
n
Using the VMware Host Client to register an encrypted virtual machine is not supported.
Virtual Machine Locked State
If the virtual machine key or one or more of the virtual disk keys are missing, the virtual machine enters a
locked state. In a locked state, you cannot perform virtual machine operations.
n
When you encrypt both a virtual machine and its disks from the vSphere Client, the same key is used
for both.
n
When you perform the encryption using the API, you can use different encryption keys for the virtual
machine and for disks. In that case, if you attempt to power on a virtual machine, and one of the disk
keys is missing, the power on operation fails. If you remove the virtual disk, you can power on the
virtual machine.
See Resolve Missing Key Issues for troubleshooting suggestions.
Virtual Machine Encryption Interoperability
vSphere Virtual Machine Encryption has some limitations regarding devices and features that it can
interoperate with in vSphere 6.5 and later releases.
You cannot perform certain tasks on an encrypted virtual machine.
n
For most virtual machine encryption operations, the virtual machine must be powered off. You can
clone an encrypted virtual machine and you can perform a shallow recrypt while the virtual machine is
powered on.
n
You cannot encrypt a virtual machine that has existing snapshots. Consolidate all existing snapshots
before you perform the encryption.
Starting with vSphere 6.7, you can resume from a suspended state of an encrypted virtual machine, or
revert to a memory snapshot of an encrypted machine. You can migrate an encrypted virtual machine
with memory snapshot and suspended state between ESXi hosts.
You can use vSphere Virtual Machine Encryption with pure IPv6 mode or in mixed mode. You can
configure the KMS with IPv6 addresses. Both vCenter Server and the KMS can be configured with only
IPv6 addresses.
Certain features do not work with vSphere Virtual Machine Encryption.
n
vSphere Fault Tolerance
n
Cloning is supported conditionally.
n
Full clones are supported. The clone inherits the parent encryption state including keys. You can
re-encrypt full clone to use new keys or decrypt the full clone.
Linked clones are supported and clone inherits the parent encryption state including keys. You
cannot decrypt the linked clone or re-encrypt a linked clone with different keys.
n
vSphere ESXi Dump Collector
vSphere Security
VMware, Inc. 152