{"id":1628,"date":"2024-09-25T20:45:54","date_gmt":"2024-09-26T01:45:54","guid":{"rendered":"https:\/\/zewwy.ca\/?p=1628"},"modified":"2024-09-25T20:45:54","modified_gmt":"2024-09-26T01:45:54","slug":"the-virtual-machine-must-be-encrypted","status":"publish","type":"post","link":"https:\/\/zewwy.ca\/index.php\/2024\/09\/25\/the-virtual-machine-must-be-encrypted\/","title":{"rendered":"The virtual machine must be encrypted"},"content":{"rendered":"<p>Sooo I lost a VM in my fray of re-organizing my server farm. Like a lost pup I figured I just rely on my good old Veeam backup sets. Recover VM, alright here we goo&#8230;.<\/p>\n<p><a href=\"https:\/\/i.imgur.com\/z0Hvgov.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter\" src=\"https:\/\/i.imgur.com\/z0Hvgov.png\" alt=\"\" width=\"342\" height=\"146\" \/><\/a><\/p>\n<p>What.. what does that mean&#8230;. Oh wait is this cause of <a href=\"https:\/\/zewwy.ca\/index.php\/2022\/11\/09\/tpm-security-on-a-esxi-vm\/\">when I blogged about adding vTPMs to VMs<\/a>?<\/p>\n<p>Re-checked <a href=\"https:\/\/docs.vmware.com\/en\/VMware-vSphere\/7.0\/com.vmware.vsphere.security.doc\/GUID-2F18E7A0-707F-4739-A0B4-9A363F1C3213.html#GUID-2F18E7A0-707F-4739-A0B4-9A363F1C3213\">the linked video from VMware<\/a>&#8230; 2 min in &#8230; &#8220;Failure to save your key backup will result in unrecoverable data loss&#8221;&#8230;. mhmmm, OK I thought all I did was add a TPM device to my VM and enabled secure boot, that&#8217;s the deal here?<\/p>\n<p>Somewhere I read that the VM config files get encrypted, but I don&#8217;t think that&#8217;s the case here either.\u00a0 Even checking the Pre-reqs from VMware I can&#8217;t see anything nothing this:<\/p>\n<p style=\"text-align: center;\"><strong>Prerequisites<\/strong><\/p>\n<p>Ensure that your vSphere environment is configured with a key provider. See the following for more information:<br \/>\nConfiguring vSphere Trust Authority<br \/>\nConfiguring and Managing a Standard Key Provider<br \/>\nConfiguring and Managing vSphere Native Key Provider<br \/>\nEnsure that host encryption mode is enabled. See Enable Host Encryption Mode Explicitly.<br \/>\nThe guest OS you use can be Windows Server 2008 and later, Windows 7 and later, or Linux.<br \/>\nThe ESXi hosts running in your environment must be ESXi 6.7 or later (Windows guest OS), or 7.0 Update 2 (Linux guest OS).<br \/>\nThe virtual machine must use EFI firmware.<br \/>\nVerify that you have the required privileges:<br \/>\nCryptographic operations.Clone<br \/>\nCryptographic operations.Encrypt<br \/>\nCryptographic operations.Encrypt new<br \/>\nCryptographic operations.Migrate<br \/>\nCryptographic operations.Register VM<\/p>\n<p>What I think is happening here is my NKP that IS a Prerequisite went poof (the vCenter server that was used to create it is shutdown and not being used), and another temp vCenter is being used.<\/p>\n<p>My first thought was maybe I could just add a new NKP and go as I figured the TPM physical module that&#8217;s installed simply needs this, and I think it&#8217;s this hardware that&#8217;s faulting the boot.<\/p>\n<p>I didn&#8217;t want to muck the with original I just recovered so I tried to clone it, but the clone failed too complaining about encryption before adding a TPM, further validating my assumption. What I don&#8217;t understand it how the VM was allowed to be created from backup in the first place if I can&#8217;t even clone it&#8230;?<\/p>\n<p>Any since I know recovery is possible (since I just did it), I guess maybe I can just remove it? Or I could also create a new VM and use vmkfstools to clone the hdd&#8230; let&#8217;s try that first&#8230;<\/p>\n<p>Go to boot VM, well got past that error but the Machine was bitlocked, I was hoping it wasn&#8217;t going to be.. go to AD server, open ADUC&#8230; no bitlocker tab&#8230; ughhhh&#8230;<\/p>\n<p><a href=\"https:\/\/answers.microsoft.com\/en-us\/windows\/forum\/all\/aduc-missing-bitlocker-recovery-tab-in-1809\/ae245c70-43ab-4a8a-9f6a-f6312f459d08\">ADUC Missing BitLocker Recovery Tab in 1809 &#8211; Microsoft Community<\/a><\/p>\n<p>Right but where is that in on a server, oh in server manager it moved&#8230;<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/i.imgur.com\/UOo5URX.png\" \/><\/p>\n<p>Yay there&#8217;s the bitlocker tab and&#8230; it&#8217;s empty.. man give me a fucking break&#8230; so now I have a bunch of backups that are useless cause I lost the bitlocker key&#8230; shiiiiiiit<\/p>\n<p>Well I don&#8217;t have anything to follow up on here but a lesson learnt to backup your bitlocker key (I don&#8217;t know why it wasn&#8217;t save to the AD computer object).<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sooo I lost a VM in my fray of re-organizing my server farm. Like a lost pup I figured I just rely on my good old Veeam backup sets. Recover VM, alright here we goo&#8230;. What.. what does that mean&#8230;. Oh wait is this cause of when I blogged about adding vTPMs to VMs? Re-checked &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/zewwy.ca\/index.php\/2024\/09\/25\/the-virtual-machine-must-be-encrypted\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;The virtual machine must be encrypted&#8221;<\/span><\/a><\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"sfsi_plus_gutenberg_text_before_share":"","sfsi_plus_gutenberg_show_text_before_share":"","sfsi_plus_gutenberg_icon_type":"","sfsi_plus_gutenberg_icon_alignemt":"","sfsi_plus_gutenburg_max_per_row":"","footnotes":""},"categories":[8],"tags":[],"class_list":["post-1628","post","type-post","status-publish","format-standard","hentry","category-server-administration"],"_links":{"self":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/1628","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/comments?post=1628"}],"version-history":[{"count":1,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/1628\/revisions"}],"predecessor-version":[{"id":1631,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/posts\/1628\/revisions\/1631"}],"wp:attachment":[{"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/media?parent=1628"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/categories?post=1628"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zewwy.ca\/index.php\/wp-json\/wp\/v2\/tags?post=1628"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}