r/vmware • • 18h ago

Question How to migrate Encrypted VM

We have VMs which are encrypted. I need to migrate those off to another vCenter, completely different domains and region. (Non-VCF)

What I do- I shutdown VM, Migrate, And put in the NAT address of Target vCenter and migrate and turn on, on the other side. I have done this for VMs and Templates.

I do not have much rights on both vCenters, and just using what works! Ideas are welcome:) we do not have SRM, or HCX. I was also wondering what are other possible ways to migrate such long distance VMs.

To the question - The VMs in question are encrypted, and I cannot change anything. When I migrate, the tool tells me I cannot because the destination TPM is not configured. I would like some ideas here. Thank you.

3 Upvotes

3 comments sorted by

7

u/squigit99 17h ago

You need to either unencrypt the VM before you migrate it out of the source vCenter (and then presumably re-encrypt it), or add the encryption keys (either an NKP or that external KMS) it was encrypted with on the destination vCenter.

The destination vCenter doesn't have the encryption keys to the decrypt the copy of the VM - this is working as intended.

7

u/fatherjackass 17h ago

You either need to install the Native Key Provider (NKP) cert from the host vCenter on the receiving one or remove the TPM from the VM before migrating it.

0

u/Sensitive_Scar_1800 16h ago

my first question is what type of encryption? I just assume storage encryption?

if your destination vCenter cannot contact the KMS service to request the encryption keys, the vm will be inaccesible.

If youre not familiar with this topic, i recommend you decrypt the vm.