Managing the Cluster Node Mapping on a VM
You can associate a Cluster Node Mapping with a VM at any time. The same procedure can also be used to change the Node Mapping currently associated with a VM. This can be done either through the Cryptographic Security Platform Vault for VM Encryption webGUI or through the CLI or Policy Agent GUI on the VM itself.
If you use the Cryptographic Security Platform Vault for VM Encryption webGUI, you can also use the Multi-Select option to set the Node Mapping for multiple VMs at the same time.
- Log into the Cryptographic Security Platform Vault for VM Encryption using an account with Cloud Admin privileges.
- In the top menu bar, click Workloads.
-
Click on the VM whose Node Mapping you want to set and select Actions > Set Mapping.
Tip: If you want to set the same Node Mapping for multiple VMs, enable the Multi-Select option and then click on each of the VMs whose Node Mapping you want to set.
-
Select the Node Mapping you want to use from the drop-down list, then click Set Mapping.
Cryptographic Security Platform Vault for VM Encryption automatically communicates the new Node Mapping information to the VM. After that, the VM will connect to Cryptographic Security Platform Vault for VM Encryption using the first node in the Node Mapping. If that node is unavailable, the VM will automatically fail over to the next node in the Node Mapping. For details, see High Availability Between a VM and the Cryptographic Security Platform Vault Cluster.
You can view the progress of the Node Mapping assignment on the User Tasks tab for the VM. You can also view the currently-assigned Node Mapping on the VM's Details tab in the Mapping field.
Log into each VM you want to associate with the Cluster Node Mapping and enter the command hcl updatekc –a [-u username [-s password]], where:
-uis a Cryptographic Security Platform Vault for VM Encryption user account with Cloud Admin privileges. If you do not enter a user account name you will be prompted for one.-sis the password for the Cryptographic Security Platform Vault for VM Encryption user account. If you do not enter a password you will be prompted for one.
The Policy Agent then queries Cryptographic Security Platform Vault for VM Encryption for the list of available Cluster Node Mappings. Type the number corresponding to the Node Mapping you want to use and press Enter. For example:
# hcl updatekc -a Getting Mapping information Please provide the login details username: cloudadmin password: ******** This VM can be added to one of the following Mappings --------------------------------------------------- 1 : San Francisco Datacenter 2 : AWS VMs --------------------------------------------------- Please select Mapping (0 to skip): 1 Mapping server description KC-1, ip 192.168.140.151, port 443 server description KC-2, ip 192.168.140.152, port 443 Updated list with nodes 192.168.140.151:443,192.168.140.152:443
Note: If you select 0, no changes are made to the current IP addresses or Cluster Node Mapping associated with the VM.
- Log into the Windows system using an account with Administrator privileges.
- Select Start > All Programs > Entrust > Entrust DataControl or start Windows PowerShell and enter the
hclGUIcommand. - Click the Update Mapping button.
- In the Mapping window, update the Mapping Name, Vault User, and the Password.
- Click Update Mapping.
- When the status update window appears, click OK.
- Click the Refresh button to refresh the window and see the changes.