Encrypting VMs, registering hosts and other encryption work need these granular vCenter privileges. They are part of the Administrator role but are missing from No cryptography administrator.
Read more: Broadcom TechDocs
In the Ultra Transcenders books
Each book explains Cryptographic operations in context, with comparison tables and the common traps.
Terms in this definition
- Virtual machines
Infrastructure-as-a-service compute giving complete control of the operating system, making it a fit for lift-and-shift moves and for software relying on OS-level pieces like COM.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- vCenter
Management software for VMs, clusters and ESX hosts. Each domain in VCF gets a dedicated one.
- Role
How an actor normally or expectedly behaves, or the part a person takes in a process. A single actor may hold more than one role.
- No cryptography administrator
Built into vCenter, this role matches Administrator in every respect apart from lacking Cryptographic operations privileges, making it suitable for admins who are not meant to touch encryption keys.
Related terms
- Key Vault Crypto User
RBAC role allowing reads of key metadata plus the cryptographic operations: sign, verify, encrypt, decrypt, wrap and unwrap.
- Key Vault Reader
RBAC role limited to reading metadata about the vault and its objects; it can't see secret values or perform cryptographic operations.