Jump to content

Recommended Posts

Posted

Hi Guys

 

I've searched everywhere and would like to get a definitive answer on the recommended best practises for encrypting Hyper V Hosts and VMs using Bitlocker. These will be single server Hosts with several VMs, so we cannot use Shielded VMs and to be honest we just need encryption protection at rest, as some of the servers are not physically in great locations due to the schools layouts and we are worried about theft.

 

So which is the best way to go, bearing in mind we have to think about if there is any noticeable performance Hits:

 

1. Encrypt the Host Disks using TPM

2. Encrypt the Guest VMs using vTPM

3. Encrypt both the Guest VMs and the Host Disks

 

What have you guys got in place and what are the pros and cons of each.

 

I have some information on each and potential worst case scenario pitfalls, but would like input from those that have this implemented.

 

Many Thanks

 

S

Posted (edited)

I don't know if it's changed recently, but without using vTPM/shielded VMs it was never officially supported using bitlocker on the guests as the keys would be stored unencrypted as such on the host

 

Any reason you say you can't use Shielded for what you're talking about? You can use it with a standalone host (althoughtobviously more are better) :p Otherwise you're going to run into problems with manually unlocking them every time you reboot etc

 

In terms of your actual question, we don't use any of those. It's the same principle as paperwork that's stored locked away, could still be stolen, but you've implemented many security features before that stage etc, so you're still following all guidelines etc

 

Steve

Edited by Steve21
Posted

Thanks for the reply

 

Server 2016 and 2019 allow for the Guests to be Encrypted now. I did read about the storage of keys on the host, but couldn't find any official documentation to say as such.

 

These are all single server environments. so was under the impression that the HGS service requires 2 or more servers to work properly and without intervention.

 

Some of these are businesses too, with small training academies attached, so encryption of the data at rest is essential and using the best methods but without loosing too much performance and adding potential problems with operations.

 

Be good to hear from anyone who has done any of the above.

 

Thanks

 

S

Posted

2016/2019 base it on virtualTPM, so like USB passthrough from the host etc (again assuming you have TPM on the HOST), so storing of the keys separately isn't needed as it's within the TPM as a standard laptop etc

 

Even silly things like how you RAID could affect your answer to this, it's always going to take a hit but depending on how much will depend more on the setup overall

 

Steve

Posted

Thanks,

 

I've seen these articles, they are more of a how to and not a best practises and why. I didn't think it would be so hard to find but seemingly it is. I know how to do it but want to understand any pitfalls to any of the methods...

 

Cheers

 

S

Posted
Thanks,

 

I've seen these articles, they are more of a how to and not a best practises and why. I didn't think it would be so hard to find but seemingly it is. I know how to do it but want to understand any pitfalls to any of the methods...

 

Cheers

 

S

 

Some stuff online I have seen depends on the drives and raid on them. As an example: https://www.isumsoft.com/computer/how-much-does-bitlocker-impacts-on-hard-disk-io-performance.html

Posted

Thanks.

 

What have you guys done out of the 3 options, or a 4th one if done nothing (Relying on physical security)?

 

Still haven't seen any best practises for 2016/2019 server, I would have thought it would have been easier to find on the internet that it is proving.

 

Cheers

 

S

  • 2 weeks later...
Posted
Thanks.

 

What have you guys done out of the 3 options, or a 4th one if done nothing (Relying on physical security)?

 

Still haven't seen any best practises for 2016/2019 server, I would have thought it would have been easier to find on the internet that it is proving.

 

Cheers

 

S

 

Went down the physical security line in the end as the hardware was slow as it is. We have only just upgraded.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...