IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Workload: How To Encrypt the Appliance VM

Workload: How To Encrypt the Appliance VM

Environment

  • Carbon Black Cloud Workload Appliance: All Supported Versions
  • vCenter Server: All Supported Versions

Objective

To encrypt the VMware Carbon Black Workload Appliance VM

Resolution

  1. Ensure prerequisites are met:
  2. Add KMS to vCenter Server:
    1. Navigate to Configure > Security > Key Providers
    2. Click "Add Standard Key Provider" add add the server address/port number
    3. Enable trust between KMS and vCenter:
  3. Confirm ESX host has encryption mode enabled under Configure > System > Security Profile
  4. Power the Carbon Black Workload Appliance off
  5. Encrypt the VM by navigating to Configure > Policies > select "VM Encryption Policy"
  6. On the Appliance VM "Summary" tab, there should now be a lock logo next to the Linux logo
  7. Power the Appliance back on

Additional Notes

  • After encrypting the appliance VM, any attempts to migrate VM to another VC (Which does not have KMS cluster Authentication) will error. Only migrations of this VM to another ESX under same VC (or VC with same kms authentication) it will migrate.
  • To encrypt any new appliances, select "Encrypt this Virtual Machine" while deploying the OVF Template. This option will be on the "Select Storage" section.
  • If error "Storage profile is only supported when the target resource pool is backed by a cluster." is presented while creating newly encrypted appliance VM, move the ESXI host under existing cluster, or create a new cluster in VC.
  • If error "The VMware vSphere with Operation Management 6 Enterprise license for Host “1.2.3.4” does not include “Vsphere VM Encryption”. Upgrade the license." is presented, you will need to upgrade your license to resolve this.
  • For further assistance please contact VMware Support

Related Content


Labels (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎04-01-2021
Views:
856