Verifying Your Integration
To verify the successful integration:
On the Nutanix VCP UI, go to Data at Rest Encryption settings.
Select Enable Encryption, enter ENCRYPT and select Encrypt.
Note
This step usually takes a long time, upto few hours. After completion, the key in the settings turns golden and displays the message Encryption State of Cluster: Software encryption is enabled.
After the encryption is complete, verify that the keys are created on the Ciphertrust Manager.
Test whether the keys are being retrieved from the CipherTrust Manager. To do so:
Power off the VMs running in the encrypted Nutanix cluster, Nutanix Controller VMs (CVMs), hosts, and CipherTrust Manager VMs.
A Nutanix CVM runs the Nutanix software and serves all the I/O operations for the hypervisor and VMs running on that host.
Power on the hosts and CVMs.
Power on the VMs in the encrypted Nutanix cluster.
The power on operation should succeed only when any of the configured CipherTrust Managers are running.
Check whether the stored keys are being replaced for the Rekey operation. To do so:
In the Manage Keys section, select the Rekey option.
A message Encryption State of Cluster: Encryption keys were successfully changed is displayed.
Test whether the keys can be used for decryption. To do so:
Power off the VMs running in the encrypted Nutanix cluster, CVMs, hosts, and CipherTrust Manager VMs.
Power on the hosts and CVMs.
Power on the VMs in the encrypted Nutanix cluster.
Check the CipherTrust Manager cluster logs to verify whether the keys are exported from the active CipherTrust Manager.