Functional Testing (encryption/decryption, signing, etc.)

To validate the integration between VMware Cloud Director, VMware vCenter Server, and Utimaco ESKM, perform the following steps:

  1. Deploy a virtual machine as described in Deploying an Encrypted VM .

  2. In VMware vCenter Server, navigate to the cluster associated with the Organization VDC and locate the deployed virtual machine.

  3. Verify that the virtual machine is marked as Encrypted, that the encryption is provided by the configured ESKM Key Provider, and that it is compliant with the assigned VM storage policy.

imagen-20260407-112806.png

VMware Cloud Director VM Encrypted

imagen-20260407-115800.png

VMware Cloud Director VM Policy Compliant

To validate the integration between VMware vCenter and Utimaco ESKM, perform the following steps to encrypt a virtual machine:

  1. Log in to the vCenter Server.

  2. Navigate to Menu → VMs and Templates.

  3. Select an existing virtual machine.

  4. Right-click the virtual machine and select VM Policies → Edit VM Storage Policies

  5. In the VM Storage Policy section:

    • Select a policy that includes VM Encryption.

    • Ensure the policy is associated with the configured key provider (ESKM).

    • It can be configured for the whole VM or per disk.

  6. Click OK to apply the policy.

Captura desde 2026-03-24 11-47-11.png



Edit VM Storage Policies

  1. Monitor the task progress in the Recent Tasks panel until completion.

VM_encrypted.png

Encrypted VM

The virtual machine should display as Encrypted in its summary.


  • In ESKM, navigate to Security → KMIP Objects

  • Verify that a new Symmetric Key (AES-256) has been created.

imagen-20260324-105632.png


KMIP Objects created

  • Navigate to Device → Log Viewer → KMIP to verify the logs

imagen-20260324-105826.png

Successful Key Retrieval