I currently use WSE 2012R2 for my home server. I have full disk encryption with a TPM on the boot drive as well as my storage array.
To consolidate systems I want to move to an all-in-one and virtualize the WSE on ESXI. My research indicates that I can not pass thru the TPM. This leads me to believe that my security options if I virtualize are as follows:
1. Go without encryption.
2. Use unencrypted virtual machines and vm storage but encrypt the storage array (will be passed through to the WSE vm) and manually re-enter the unlock code every time I reboot.
3. Create a virtual floppy for the WSE vm and store the unlock codes for WSE as well as the storage array there.
I have two questions:
1. Are there any other options I am missing? I want to be able to lock this entire system (vm storage and hypervisor as well as the vm's) up tight as the server contains sensitive info (personal as well as work related). I don't mind paying but it wont be worth it if the cost to protect is more that just keeping separate machines like now.
2. How does one protect their vm's and the associated data? Is there any way to encrypt the ESXI hypervisor (and datastores) like I am currently doing with my WSE and full disk encryption?
Thanks for taking the time to read this.
To consolidate systems I want to move to an all-in-one and virtualize the WSE on ESXI. My research indicates that I can not pass thru the TPM. This leads me to believe that my security options if I virtualize are as follows:
1. Go without encryption.
2. Use unencrypted virtual machines and vm storage but encrypt the storage array (will be passed through to the WSE vm) and manually re-enter the unlock code every time I reboot.
3. Create a virtual floppy for the WSE vm and store the unlock codes for WSE as well as the storage array there.
I have two questions:
1. Are there any other options I am missing? I want to be able to lock this entire system (vm storage and hypervisor as well as the vm's) up tight as the server contains sensitive info (personal as well as work related). I don't mind paying but it wont be worth it if the cost to protect is more that just keeping separate machines like now.
2. How does one protect their vm's and the associated data? Is there any way to encrypt the ESXI hypervisor (and datastores) like I am currently doing with my WSE and full disk encryption?
Thanks for taking the time to read this.