As part of your regular key rotation plans, you can use PowerCLI to update a vSphere Native Key Provider.
If you have a policy for key rotation, you can update the vSphere Native Key Provider and rekey the virtual machines that you encrypted with that key provider. You must use PowerCLI to update the vSphere Native Key Provider. You can also rekey the encrypted virtual machines without updating the key provider. In this case, only the virtual machine keys are changed. To rekey a virtual machine, see Rekey an Encrypted Virtual Machine Using the vSphere Client.
Prerequisites
- Required privilege:
- PowerCLI 12.3.0
Procedure
Results
When a key provider is updated, its status changes to Not Backed Up. After you back up the key provider, its status changes to Active.