Creating the Master VM
The first step is to create a Master VM that is registered with, and encrypted by, KeyControl. Once you have the Master VM you can clone it and then register the clones with KeyControl.
If you already have such a VM, you can skip this procedure.
- Set up a Master VM with all the software and configuration according to the VDI requirement.
- Install the latest HyTrust DataControl Policy Agent on the Master VM and register it with KeyControl as described in Linux Policy Agent Installation.
- Encrypt the required data disks as described in Encrypting a Windows Disk Using the HyTrust Policy Agent GUI or Encrypting a Disk Using the CLI.
- If required, encrypt the root / system drive as described in Linux Root, Swap, and System Device Encryption or Windows Boot Drive Encryption.
- As a precaution, take a snapshot of the Master VM at this point.
What to Do Next
Designate this VM as a template and prepare the clones for deployment as described in Registering Clone Addresses in KeyControl Before Deployment.