Hosting a KMS on the encrypted VxRail cluster, with Key Persistence

In my previous post (VxRail cluster encryption with the vSphere Native Key Provider) I spoke about how to encrypt your VxRail cluster with the vSphere Native Key Provider that was introduced in vSphere 7.0 U2.

It is a great feature and the post shows how easy it is to set it up and use it to encrypt your cluster. However… what if you do need more functionality, that only a Key Management Server (KMS) can offer? Oh, and I don’t want to spend more cost on an extra host (outside my cluster) to host the KMS appliance? I can’t put it on the actual cluster itself, that it is providing the encryption keys for! Or can I …?

Continue reading “Hosting a KMS on the encrypted VxRail cluster, with Key Persistence”

VxRail cluster encryption with the vSphere Native Key Provider

VMware has recently introduced the vSphere Native Key Provider (NKP). This is a way to enable data-at-rest protections straight from vSphere itself.

Before we talk about the NKP, let’s first go back one step…

Continue reading “VxRail cluster encryption with the vSphere Native Key Provider”

Blog at WordPress.com.

Up ↑

Design a site like this with WordPress.com
Get started