6.7

Table Of Contents
5
Securing Virtual Machines 126
Enable or Disable UEFI Secure Boot for a Virtual Machine 126
Limit Informational Messages From Virtual Machines to VMX Files 127
Prevent Virtual Disk Shrinking 128
Virtual Machine Security Best Practices 129
6
Virtual Machine Encryption 139
How vSphere Virtual Machine Encryption Protects Your Environment 140
vSphere Virtual Machine Encryption Components 142
Encryption Process Flow 143
Virtual Disk Encryption 145
Prerequisites and Required Privileges for Encryption Tasks 146
Encrypted vSphere vMotion 147
Encryption Best Practices, Caveats, and Interoperability 148
7
Use Encryption in Your vSphere Environment 154
Set up the Key Management Server Cluster 155
Create an Encryption Storage Policy 162
Enable Host Encryption Mode Explicitly 163
Disable Host Encryption Mode 164
Create an Encrypted Virtual Machine 164
Clone an Encrypted Virtual Machine 165
Encrypt an Existing Virtual Machine or Virtual Disk 166
Decrypt an Encrypted Virtual Machine or Virtual Disk 167
Change the Encryption Policy for Virtual Disks 169
Resolve Missing Key Issues 170
Unlock Locked Virtual Machines 172
Resolve ESXi Host Encryption Mode Issues 172
Re-Enable ESXi Host Encryption Mode 173
Set Key Management Server Certificate Expiration Threshold 174
vSphere Virtual Machine Encryption and Core Dumps 174
8
Securing Virtual Machines with Virtual Trusted Platform Module 179
Add a Virtual Trusted Platform Module to a Virtual Machine 181
Enable Virtual Trusted Platform Module for an Existing Virtual Machine 182
Remove Virtual Trusted Platform Module from a Virtual Machine 182
Identify Virtual Trusted Platform Enabled Virtual Machines 183
View vTPM Module Device Certificates 183
Export and Replace vTPM Module Device Certificates 184
vSphere Security
VMware, Inc. 4