6.7

Table Of Contents
4 Under System, click Security Profile.
5 Scroll down to Host Encryption Mode and click Edit.
6 Select Enabled and click OK.
Disable Host Encryption Mode
Host encryption mode is enabled automatically when you perform an encryption task. After host
encryption mode is enabled, all core dumps are encrypted to avoid the release of sensitive information to
support personnel. If you no longer use virtual machine encryption with an ESXi host, you can disable
encryption mode.
Procedure
1 Unregister all encrypted virtual machines from the host
2 Unregister the host from vCenter Server.
3 Reboot the host.
4 Register the host with vCenter Server again.
As long as you do not add encrypted virtual machines to the host, host encryption mode is disabled.
Create an Encrypted Virtual Machine
After you set up the KMS, you can create encrypted virtual machines.
This task describes how to create an encrypted virtual machine using either the vSphere Web Client or
the vSphere Client (HTML5-based client). The vSphere Client filters storage policies to those that include
virtual machine encryption, easing creation of encrypted virtual machines.
Note Creating an encrypted virtual machine is faster and uses fewer storage resources than encrypting
an existing virtual machine. If possible, encrypt virtual machine during the creation process.
Prerequisites
n
Establish a trusted connection with the KMS and select a default KMS.
n
Create an encryption storage policy, or use the bundled sample, VM Encryption Policy.
n
Ensure that the virtual machine is powered off.
n
Verify that you have the required privileges:
n
Cryptographic operations.Encrypt new
n
If the host encryption mode is not Enabled, you also need Cryptographic operations.Register
host.
Procedure
1 Connect to vCenter Server by using either the vSphere Client (HTML5-based client) or the
vSphere Web Client.
vSphere Security
VMware, Inc. 164