Key Lifecycle Behaviour

To validate key lifecycle behavior, remove encryption from the virtual machine:

  1. In vCenter, select the encrypted virtual machine.

  2. Right-click the virtual machine and select VM Policies → Edit VM Storage Policies

  3. In the VM Storage Policy section:

    • Select a non-encrypted (default) policy.

  4. Click OK to apply the changes.

  5. Monitor the task progress until completion.

  • The virtual machine is no longer marked as encrypted.

  • In ESKM:

    • The previously created KMIP keys remain present.

    • The keys remain in Active state.