If you are new to SCVMM 2012 R2, you may be wondering what this is. I will try to explain to you. It is very easy. The VMM database contains a lot of very sensitive information about virtual servers such as passwords administrator or product keys. In order to protect that information, the database is encrypted and the key to unencrypt that information is stored on the VMM management server.
Well, so far, so good! In the previous version of VMM, we didn’t have the possibility to configure the servers in a cluster (Until now we haven't had fault tolerance). But now with SCVMM 2012 R2, we can configure a cluster. Then the information in the database will need to be shared. If the information is shared and we have the key to unencrypt only in one server, what will happen in case of a failure in that server? How could the other server unencrypt the information?
In order to solve that problem, we have Distributed Key Management. It is just a container created in Active Directory to save the encryption key and to be shared between the servers in a cluster scenario.
Well, so far, so good! In the previous version of VMM, we didn’t have the possibility to configure the servers in a cluster (Until now we haven't had fault tolerance). But now with SCVMM 2012 R2, we can configure a cluster. Then the information in the database will need to be shared. If the information is shared and we have the key to unencrypt only in one server, what will happen in case of a failure in that server? How could the other server unencrypt the information?
In order to solve that problem, we have Distributed Key Management. It is just a container created in Active Directory to save the encryption key and to be shared between the servers in a cluster scenario.
If you plan to install a cluster in your environment, you will need to address some considerations and comply with some requirements to configure Distributed Key Management. In the following link, you will find all you need: https://technet.microsoft.com/en-us/library/gg697604.aspx
Enjoy!
You might find misconceptions in this blog. If so, please feel free to reach out to me and I will be more than happy to discuss about it.
No comments:
Post a Comment