If you want to backup an the Policy Agent on an encrypted disk, you need to make sure the entire disk is backed up (for example, the entire VMDK file in a VMware vSphere environment). This ensures that the Entrust GUIDs representing the keys are also backed up so the data can be decrypted if it is restored from the backup. Once the backup is reauthorized with Cryptographic Security Platform Vault, Cryptographic Security Platform Vault can use the restored GUIDs to determine which keys apply to the restored data.
To create the backup, see your hypervisor documentation. Entrust does not provide any tools for backing up a VM.
Warning: Before you back up your VM, make sure you check the expiration date for the data encryption keys on the disk. If you restore a backup with expired keys and the expiration option is set to SHRED, Cryptographic Security Platform Vault will destroy the keys immediately and the data will be inaccessible. If you set the expiration option to NO USE, the keys can be reactivated after the back up is restored. For more information, see Encrypting a Disk Using the CLI.
The Entrust Policy Agent identifies the VM on which it is running and uses this information and the certificate supplied during registration in order to authenticate the VM with Cryptographic Security Platform Vault. Cryptographic Security Platform Vault will not deliver keys to any VM that looks identical to one already in the system . While this is required from a security perspective, it presents challenges when dealing with VM snapshots and clones.
Snapshots
If you restore a VM using a snapshot, the hardware signature of the VM does not change. However, the restored VM may need to be re-authenticated with Cryptographic Security Platform Vault and should always be re-synchronized. For details, see Restoring a VM from a Snapshot.
Clones
If you want to add a clone of an existing VM while the original is still running, you must specifically register the clone VM with Cryptographic Security Platform Vault as an authorized clone of the existing VM.
For example, if you bring a clone of a VM online while the original VM is still running, the Policy Agent on the clone VM will attempt to communicate with Cryptographic Security Platform Vault on startup, but the check will fail authentication because the original VM is already registered.
If you enter the hcl status command on the clone VM, you will see messages similar to the following:
# hcl status Summary --------------------------------------------------- KeyControl: 192.168.140.151:443 KeyControl list: 192.168.140.151:443 Status: Reauth needed
For Windows, this would look like:
C:\>hcl status Summary ------------------------------------------------------------------------- KeyControl: 172.16.163.129:443 KeyControl list: 172.16.163.129:443 KeyControl Mapping: map1 Status: Reauth needed (Hardware signature verification failed)
Cryptographic Security Platform Vault does not know which VM is the original and which is the clone. In order to both VMs running at the same time, you need to register the clone as described in Registering a Cloned VM with Standard Authentication.
This section includes: