6.7

Table Of Contents
Set up Separate KMS Clusters for Dierent Users
You can set up your environment with different KMS connections for different users of the same KMS
instance. Having multiple KMS connections is helpful, for example, if you want to grant different
departments in your company access to different sets of KMS keys.
Using multiple KMS clusters allows you to use the same KMS to segregate keys. Having separate sets of
keys is essential for use cases like different BUs or different customers.
Note Not all KMS vendors support multiple users.
Figure 71. Connecting from vCenter Server to the KMS for Two Dierent Users
vCenter Server
KMS Cluster C1
KMS Cluster C2
KMS
C1 username/pwd
C2 username/pwd
C1
keys
C2
keys
Prerequisites
Set up the connection with the KMS. See Set up the Key Management Server Cluster.
Procedure
1 Create the two users with corresponding user names and passwords, for example C1 and C2, on the
KMS.
2 Log in to vCenter Server and create the first KMS cluster.
3 When prompted for a user name and password, give information that is unique to the first user.
4 Create a second KMS cluster and add the same KMS, but use the second user name and password
(C2).
The two clusters have independent connections to the KMS and use a different set of keys.
Create an Encryption Storage Policy
Before you can create encrypted virtual machines, you must create an encryption storage policy. You
create the storage policy once, and assign it each time you encrypt a virtual machine or virtual disk.
If you want to use virtual machine encryption with other I/O filters, see the vSphere Storage
documentation for details.
vSphere Security
VMware, Inc. 162