1 | <?xml version='1.0' encoding='UTF-8'?>
|
---|
2 | <!DOCTYPE topic PUBLIC "-//OASIS//DTD DITA Topic//EN" "topic.dtd">
|
---|
3 | <topic xml:lang="en-us" id="diskencryption-encryption">
|
---|
4 | <title>Encrypting Disk Images</title>
|
---|
5 |
|
---|
6 | <body>
|
---|
7 | <p>Encrypting disk images can be done either using <ph conkeyref="vbox-conkeyref-phrases/vbox-mgr"/> or the
|
---|
8 | <userinput>VBoxManage</userinput>. While <ph conkeyref="vbox-conkeyref-phrases/vbox-mgr"/> is easier to use, it
|
---|
9 | works on a per VM basis and encrypts all disk images attached to the specific VM. With
|
---|
10 | <userinput>VBoxManage</userinput> one can encrypt individual images, including all differencing images. To
|
---|
11 | encrypt an unencrypted medium with <userinput>VBoxManage</userinput>, use: </p>
|
---|
12 | <pre xml:space="preserve">VBoxManage encryptmedium <varname>uuid</varname>|<varname>filename</varname> \
|
---|
13 | --newpassword <varname>filename</varname>|- --cipher <varname>cipher-ID</varname> --newpasswordid "<varname>ID</varname>
|
---|
14 | </pre>
|
---|
15 | <p>To supply the encryption password point <userinput>VBoxManage</userinput> to the file where the password is
|
---|
16 | stored or specify <codeph>-</codeph> to let <userinput>VBoxManage</userinput> ask you for the password on the
|
---|
17 | command line. </p>
|
---|
18 | <p>The cipher parameter specifies the cipher to use for encryption and can be either
|
---|
19 | <codeph>AES-XTS128-PLAIN64</codeph> or <codeph>AES-XTS256-PLAIN64</codeph>. The specified password identifier
|
---|
20 | can be freely chosen by the user and is used for correct identification when supplying multiple passwords during
|
---|
21 | VM startup. </p>
|
---|
22 | <p>If the user uses the same password when encrypting multiple images and also the same password identifier, the
|
---|
23 | user needs to supply the password only once during VM startup. </p>
|
---|
24 | </body>
|
---|
25 |
|
---|
26 | </topic>
|
---|