Skip to main content

2026년 9월 4일

Configure Instant Clones with vSphere Virtual Machine Encryption

You can configure instant clones to use the vSphere Virtual Machine Encryption feature so that instant-clone desktops have the same encryption keys.

Prerequisites

  • Verify that you are running vSphere 7.0 or later.
  • Create the Key Management Server (KMS) cluster with key management servers.
  • To create a trust between KMS and vCenter Server, accept the self-signed certificate or create a certificate signed by a Certificate Authority (CA).
  • In vSphere Client, create the VMcrypt/VMEncryption storage profile.

Note: For details about the Virtual Machine Encryption feature in vSphere, see the vSphere Security document in the vSphere documentation within the Broadcom site at techdocs.broadcom.com.

Procedure

  1. To configure instant clones that use the same encryption keys, use vSphere Client to create a golden image virtual machine (VM) with the vmencrypt storage policy.

    The vmencrypt storage policy applies only when the golden image VM does not have any snapshots. The clone inherits the golden image encryption state, including keys.

  2. Take a snapshot of the golden image VM with the vmencrypt storage policy applied.

  3. Create instant-clone desktops that point to the golden image VM with the vmencrypt storage policy applied so that all desktops have the same encryption keys.

    Note: VM Encryption and Content Based Read Cache (CBRC) are not compatible. To use VM Encryption, you must disable CBRC globally by disabling View Storage Accelerator in Horizon Console by navigating to Settings > Servers.

이 페이지가 도움이 되었나요?

이 항목에 대한 피드백 보내기

이 항목이 도움이 되었나요?

개인정보나 기밀정보는 입력하지 마세요.

링크를 생성하는 중…