Creating a Cloud VM Set for the KeyControl Vault for Databases

A VM must be part of a Cloud VM Set before it can be used for Transparent Data Encryption (TDE) in a database.

Before You Begin 

Procedure 

  1. Log into the KeyControl Vault for Databases using an account with Cloud Admin privileges.
  2. In the top menu bar, click Workloads.
  3. Select Actions > Create New Cloud VM Set.
  4. On the VM Set tab:
    1. Enter a name for the Cloud VM Set.
    2. Select the group to which this set should belong, or accept the default.
    3. Optionally enter a description for the set.
  5. If you want to specify additional options, click the Additional Properties tab specify the options you want to use.

  6. If you want to specify when the VMs in the Cloud VM Set need to be re-authenticated, click the Reauthentication Settings tab and specify the options you want to use.

  7. If you want to specify a key encryption key (KEK), click the Key Encryption Key tab, choose the type of Key Encryption Key Association, and then specify the required information.

    A KEK provides an extra layer of security by encrypting the individual data encryption keys on the VMs associated with this Cloud VM Set. It also controls the expiration and revocation of those data encryption keys. To protect the KEK, KeyControl requires that the KEK be stored in the hardware security module (HSM) associated with this KeyControl cluster. For more information, see KEKs with Cloud VM Sets.

    You can add the KEK during Cloud VM Set creation or at a later time.

    1. Determine whether KeyControl Vault for VM Encryption creates a KEK for this Cloud VM Set. To use a KEK, select Use KEK from the drop-down list and click Save to view the KEK properties.

      If you do not make a selection, then the default value is No KEK Association is used, and the tab is not populated. If you decide you want to use a KEK, you can add the KEK to the Cloud VM Set later.

    2. Complete the required information for your choice: 

  8. When you have finished specifying the Cloud VM Set options, click Create.
  9. When you see the Cloud VM Set Successfully Created message, click Close.

What to Do Next 

Install the Policy Agent on the VM(s) where you want to use TDE and register it with KeyControl.