6.7

Table Of Contents
Prerequisites
n
Set up the connection to the KMS.
Although you can create a VM Encryption storage policy without the KMS connection in place, you
cannot perform encryption tasks until trusted connection with the KMS server is established.
n
Required privileges: Cryptographic operations.Manage encryption policies.
Procedure
1 Log in to the vCenter Server by using the vSphere Web Client.
2 Select Home, click Policies and Profiles, and click VM Storage Policies.
3 Click Create VM Storage Policy.
4 Specify the storage policy values.
a Enter a storage policy name and optional description and click Next.
b If you are new to this wizard, review the Policy structure information, and click Next.
c Select the Use common rules in the VM storage policy check box.
d Click Add component and select Encryption > Default Encryption Properties and click Next.
The default properties are appropriate in most cases. You need a custom policy only if you want
to combine encryption with other features such as caching or replication.
e Deselect the Use rule-sets in the storage policy check box and click Next.
f On the Storage compatibility page, leave Compatible selected, choose a datastore, and click
Next.
g Review the information and click Finish.
Enable Host Encryption Mode Explicitly
Host encryption mode must be enabled if you want to perform encryption tasks, such as creating an
encrypted virtual machine, on an ESXi host. In most cases, host encryption mode is enabled
automatically when you perform an encryption task.
In some cases, turning on encryption mode explicitly is necessary. See Prerequisites and Required
Privileges for Encryption Tasks.
Prerequisites
Required privilege: Cryptographic operations.Register host
Procedure
1 To enable host encryption mode, follow these steps.
2 Connect to vCenter Server by using the vSphere Web Client.
3 Select the ESXi host and click Configure.
vSphere Security
VMware, Inc. 163