49 | Dell EMC VxRail Appliance Operations Guide
© 2017 Dell Inc. or its subsidiaries.
Encryption is only supported on VxRail clusters that use customer-provided vCenter Servers.
VxRail Manager-deployed vCenters do not support encryption. A customer-provided KMIP 1.1
compliant key management technology is also required. For a full list of supported Key
Management Services, visit
https://www.vmware.com
.
vSAN encryption is very efficient. In a properly sized cluster, there should be no performance
impact. If you are considering whether to enable encryption on an existing VxRail appliance,
work with your Dell EMC representative, who can model the impact of encryption on CPU
overhead (estimated to be only 5-15%) for your configuration.
Setting up vSAN encryption on a VxRail cluster
If a system uses data-at-rest-encryption capabilities of VxRail 4.5, it is a best practice to enable
encryption immediately after the system is initialized. While it is possible to enable it at any time
and this can be done online, all existing data on the vSAN datastore must be reformatted before
the data is protected. Enabling encryption at the time the system is initialized minimizes the
overhead and time it takes to protect the system.
Note
: Encryption is only supported in VxRail environments that are configured with customer
deployed vCenter servers.
Setting up vSAN encryption on a VxRail cluster involves the following two steps:
First, configure a Key Management Service (KMS).and then establish a domain of trust
between the KMS that generates the keys, vCenter, and the ESXi hosts that encrypt the
data. The domain of trust follows the standard Public Key Infrastructure (PKI)-based
management of digital certificates. For instructions on how to setup a key management
server, see the vendor documentation.
After establishing domain of trust, enable encryption in vSphere and begin the automated
process of reformatting the disk and encrypting existing data.
Setting up a domain of trust
Use the following procedure to set up the domain of trust between the KMS and the vCenter
Server.
1. Within the vCenter web client, select the vCenter instance,
Configure
, select
Key
Management Servers
and click on the green plus sign (+). Specify the name of the KMS
cluster, the IP address and a port to use.
Summary of Contents for VxRail Appliance
Page 86: ......