ã¯ã©ãŠããã¯ãããžãŒã®æ代ã«ãåãŠãŒã¶ãŒãåçãä¿åããããã®ç¬èªã®ã¯ã©ãŠããæã¡ãäŒæ¥ãã¯ã©ãŠãã³ã³ãã¥ãŒãã£ã³ã°çšã®ãµãŒããŒãã¬ã³ã¿ã«ããå Žåãä¿åãããæ å ±ã®æ©å¯æ§ã«ã€ããŠçåãçããŸãã ãŸãããŠãŒã¶ãŒãã¯ã©ãŠããä¿¡é Œããããæå·åã³ã³ãããŒã䜿çšããŠä¿åããŒã¿ãä¿è·ããããšãã§ããã°ãäŒæ¥ã®æ¥çžŸã¯æªåããŸãã ããŒã¿ãŠã§ã¢ããŠã¹ãã¯ã©ãŠãã«è»¢éãããã ãã§ãªããèšç®èªäœã転éãããããã§ãã
ä»®æ³ãã·ã³ã®ä¿è·ã¯ç¹ã«åœ±é¿ãåããŸããããã¯ããã¹ãã䟵害ãããå Žåã«VMãžã®ã¢ã¯ã»ã¹ãååŸããã®ãé£ãããªãããã§ãã æè¿ãŸã§ãVMwareãXenãHyper-Vã®ãããã®ãã€ããŒãã€ã¶ãŒããéèŠãªVMä¿è·ãã¯ãããžãŒãæäŸããŠããŸããã§ããã
ãŸããæ»æè ããµãŒããŒã«ç©ççã«ã¢ã¯ã»ã¹ã§ããããã«ãªã£ãå Žåãä¿åã§ããã®ã¯ãã£ã¹ã¯æå·åã®ã¿ã§ããããã¹ãŠã®å Žåã«ä¿åã§ããããã§ã¯ãããŸããã ãã¡ããããµãŒããŒãã¬ã³ã¿ã«ããå Žåãä¿è·å¯Ÿçã®äžéšã¯ããŒã¿ã»ã³ã¿ãŒã«ãã£ãŠè¡ãããŸãã ãã ãããã®å ŽåãããŒã¿ã»ã³ã¿ãŒç®¡çè ãä¿¡é Œããå¿ èŠããããŸãã
Windows Server 2016ã®ãªãªãŒã¹ã«ãããMicrosoftã¯ãã¹ãã»ãã¥ãªãã£ãšä»®æ³ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ããã«æ³šæãæãããšã決å®ããŸããã ããã§ãHyper-Vãã¹ã管çè ããVMãåé¢ã§ããŸãã ãŸããä»®æ³TPMã䜿çšããŠãbitlockerã䜿çšããŠVMããŒã¿ãæå·åããããšãå¯èœã«ãªããŸããã
ãããã£ãŠãæ°ãããã¯ãããžãŒã䜿çšããŠãç£èŠå¯Ÿè±¡å€ã®ãµãŒããŒãŸãã¯äŒæ¥ã®ããŒã¿ã»ã³ã¿ãŒã§ä»®æ³ãã·ã³ããã¹ãã§ããŸãããç©çã¢ã¯ã»ã¹ãšä»®æ³ã¢ã¯ã»ã¹ã®åœ¹å²ãåºå¥ããŠãã»ãã¥ãªãã£ã¬ãã«ãé«ããŸãã
䜿çšæè¡
ã·ãŒã«ããããVMã¯ãä»®æ³ãã·ã³ããã¹ãããéé¢ãããã¯ãããžãŒã§ãã ãã¹ã管çè ã«ããå¶çºçãŸãã¯æå³çãªã¢ã¯ã·ã§ã³ãæªæã®ãããœãããŠã§ã¢ããVMãä¿è·ããŸãã
ã·ãŒã«ããããVMãæ©èœããã«ã¯ãHost GuardianãµãŒãã¹ïŒHGSïŒãµãŒããŒãå¿ èŠã§ããããã¯ãVMã¢ã¯ã»ã¹ããŒãçºè¡ããHyper-Vãã¹ãã®ãã«ã¹ããã§ãã¯ããŸãã
HGSã¯2çš®é¡ã®èªèšŒããµããŒãããŠããŸãã
- TPMä¿¡é Œã®èªèšŒ-æ€èšŒã¯ãTPMèå¥åãOSããŒãã·ãŒã±ã³ã¹ãããã³ã³ãŒãæŽåæ§ããªã·ãŒã«åºã¥ããŠããŸãã ããã«ãããæ¿èªãããã³ãŒãã®ã¿ããã¹ãã§å®è¡ãããŠããããšã確èªã§ããŸãã
- 管çè ãä¿¡é Œãã蚌ææž-æ€èšŒã¯ãActive Directoryã»ãã¥ãªãã£ã°ã«ãŒãã®ã¡ã³ããŒã·ããã«åºã¥ããŸãã
HGSäœæ¥ã¹ããŒã
ä»®æ³ãã·ã³ãèµ·åãããšãã»ãã¥ã¢ãã¹ãã¯èšŒææžãHGSãµãŒããŒã«æž¡ããŸããHGSãµãŒããŒã¯ãä»®æ³ãã·ã³ãžã®ã¢ã¯ã»ã¹ããŒã®è»¢éã決å®ããŸãã
管çè ããVMãžã®ã¢ã¯ã»ã¹ãåé¢ããå¿ èŠãããå Žåã¯ã管çè ãä¿¡é Œãã蚌ææžãå éšã§äœ¿çšããå¿ èŠããããŸãã
ããŒã¿ãšVMãããŒã¿ã»ã³ã¿ãŒã®åŸæ¥å¡ããåé¢ããããã«ãã¬ã³ã¿ã«ãµãŒããŒã«VMãé 眮ããå Žåã¯ãTPMä¿¡é Œã®èšŒææžã䜿çšããããšããå§ãããŸãã
HGSãµãŒããŒãšã»ãã¥ã¢ãã¹ãã¯ãhttpïŒhttpsïŒãããã³ã«ãä»ããŠéä¿¡ããŸãã HTTPSã¯å®å šãªéä¿¡ãæäŸããããã«å¿ èŠã§ã¯ãããŸããããHTTPSãæå¹ã«ããå Žåãè¿œå ã®èšŒææžãå¿ èŠã«ãªããŸãã AD蚌ææžã®å Žåãäžæ¹åãã¡ã€ã³ä¿¡é Œãè¿œå ã§æ§æããå¿ èŠããããŸãã
Virtual Secure ModeïŒVSMïŒã¯ãããOSã§ã»ãã¥ãªãã£ãéèŠãªæäœãåé¢ããä»®æ³åããŒã¹ã®ãã¯ãããžãŒã§ãã
ä»ã®2ã€ã®ãã¯ãããžãŒãVSMã§æ©èœããŸãã
- ããã€ã¹ã¬ãŒã-UEFIãã¡ãŒã ãŠã§ã¢ããŒã¿ãšã«ãŒãã«ã¢ãŒããã©ã€ããŒã®ãã§ãã¯ïŒã³ãŒãæŽåæ§å¶åŸ¡ïŒã
- Credential Guard-ãŠãŒã¶ãŒèªèšŒããã»ã¹ïŒLSAïŒã®åé¢ã
VSMã®ä»çµã¿
ã¡ã€ã³OSã¯ä»®æ³ç°å¢ã§å®è¡ãããŸãã ãŸãããã€ããŒãã€ã¶ãŒã¯ãã¹ãOSãšããŠæ©èœãããããRAMãžã®ã¢ã¯ã»ã¹ãå¶éãããŸãã ãã®çµæããã¹ãã§å®è¡ãããŠãããã«ãŠã§ã¢ã¯ã管çè æš©éããã£ãŠãVSMã¡ã¢ãªã«ã¢ã¯ã»ã¹ã§ããŸããã ãŸãããã®ãããªæ§é ã¯ãDMAããŒããžã®æ»æããä¿è·ããå¿ èŠããããŸãã
ã·ãŒã«ããããVMã«ã€ããŠ
ã·ãŒã«ããããVMã泚æããå ŽåãHyper-Vãã¹ããšHGSãµãŒããŒã¯ããŒã¿ã»ã³ã¿ãŒåŽã«ããããšãç解ãããŸãïŒMicrosoft Azureã§æŽçãããŠããŸãïŒã ãã®å Žåãã·ãŒã«ããããä»®æ³ãã·ã³ãèªåã§äœæããããæäŸãããŠãããã³ãã¬ãŒãã䜿çšããŠäœæã§ããŸãã
ã·ãŒã«ããããVMãç¬èªã«äœæãããšã顧客ã¯VMãPCã«å±éããŠæ§æããããŒã¿ã»ã³ã¿ãŒãçºè¡ããããŒã§æå·åããŸãã VMãããŒã¿ã»ã³ã¿ãŒã«è»¢éããåŸã
2çªç®ã®å Žåã顧客ã¯ãã³ãã¬ãŒãããäœæãããVMãä¿è·ããPDKãã¡ã€ã«ã®ã¿ãäœæããŸãã PDKãã¡ã€ã«ã¯ããã³ãã¬ãŒããã¡ã€ã«ãHGSãµãŒããŒã«é¢é£ä»ããŸãã ãã ãããã³ãã¬ãŒãã«ãã«ãŠã§ã¢ãå«ãŸããŠããªãããšã確èªããå¿ èŠããããŸãã
VMããŒã¿ãã¡ã€ã«ã¯æå·åããã圢åŒã§ãã¹ãã«å°éãããããæåã®æ¹æ³ã¯ããå®å šã«èŠããŸãã ãããã®å Žåã§ããVMãžã®ã¢ã¯ã»ã¹ããŒã¯ãããŒã¿ã»ã³ã¿ãŒã®ç®¡çè ã«å¹³æã§å±ããŸããã
æ»æãåããããå¯äžã®å Žæã¯HGSãµãŒããŒã§ããã 以æ¥ïŒ
- HGS管çè ã¯ãã»ãã¥ãªãã£ããªã·ãŒèŠä»¶ãäžããããšãã§ããŸãã
- 管çè æš©éãååŸããæ»æè ã¯ãã¢ã¯ã»ã¹ããŒãååŸããããšããå¯èœæ§ããããŸãã
- HGSãæ©èœããã«ã¯ãADãå¿ èŠã§ãããTPMãå¿ é ã§ããå¿ èŠã¯ãããŸããããããã£ãŠãã»ãšãã©ã®å ŽåãããŒã¯å¹³æã§ä¿åãããŸãã
ããã«åºã¥ããŠãHGSãµãŒããŒãã€ã³ãã©ã¹ãã©ã¯ãã£ã«é 眮ãããŠããæ¡ä»¶äžã§ãã·ãŒã«ããããVMãåäœããå¯èœæ§ããã¹ããããšããã¢ã€ãã¢ãçãŸããŸããã ããã«ãããä»®æ³ãã·ã³ãããã«ä¿è·ãããŸãã ãŸãããã®æ¹æ³ã¯ãããŒã¿ã»ã³ã¿ãŒãã·ãŒã«ããããVMãµãŒãã¹ãæäŸããªãå Žåã«ã䜿çšã§ããŸãã ãã®ã¢ãããŒãã®æ¬ ç¹ã¯ããã®æ§é ãèªåã§ç®¡çããå¿ èŠãããããšã§ãã
HGSãµãŒããŒããã€ããŒãã€ã¶ãŒã®ç®¡çè ã«çœ®ãæããããšã«ã€ããŠè³ªåããããããããŸãããããã«ã¯ãæ°ããã¢ãã¬ã¹ãæå®ããã ãã§ãã ããã«å¯Ÿããä¿è·ã¯éåžžã«ç°¡åã«å®è£ ãããäœæãããVMã¯HGSãµãŒããŒã®å ¬éããŒã䜿çšããŠæå·åããããããå¥ã®HGSãµãŒããŒã¯èµ·åã®ããã«ããŒãçºè¡ã§ããŸããã
ãŸããã·ãŒã«ãVMãã¯ãããžãŒã¯ä»®æ³ãã·ã³æ§æãã¡ã€ã«ã®ã¿ãæå·åããããšãç解ããããšã䟡å€ããããŸãã VHDXãã¡ã€ã«ã¯æå·åãããŸããã æå·åããã«ã¯ãvTPMãæå¹ã«ãããã©ã€ãããããããã«ãŒã§æå·åããå¿ èŠããããŸãã
æ°ãããã¯ãããžãŒã®çµã¿åããã«ãããä¿¡é Œæ§ã®é«ãä¿è·ãæäŸãããŸãã
- 人çèŠå ãæé€ãããŸãã
- ããŒã¯æå·åããã圢åŒã§éä¿¡ãããŸãã
- ãµãŒããŒã¯ãã³ãŒãã®æŽåæ§ãã§ãã¯ãæäŸããæ°ãããã¯ãããžãŒã«ãã£ãŠä¿è·ãããŠããŸãã
- èš±å¯ãããã¢ããªã±ãŒã·ã§ã³ã®ãã¯ã€ããªã¹ãã
- VMããã¹ãããåé¢ããŸãã
ããã¯ãã¹ãŠãHyper-Vãã¹ããæšçãšãããã«ãŠã§ã¢ããéåžžã«ããä¿è·ãããææè ã®ã¿ã«VMãžã®ã¢ã¯ã»ã¹ãæäŸãã管çè ãŸãã¯ç®¡çè æš©éãååŸãã人ã®ã¢ã¯ã·ã§ã³ããä¿è·ããŸãã
Hyper-Vããã³HGSãµãŒããŒã®èŠä»¶
TPMèªå®ã䜿çšããããã®èŠä»¶ãââ瀺ãããŠããŸãã ADèªå®ã¯ããã»ã©å³ãããããŸããããã¯ããã«å°ãªãä¿è·ãæäŸããŸãã
HGSïŒ
- Windows Server 2016
Hyper-VïŒ
- Windows Server 2016 Datacenter Edition
- UEFIã»ãã¥ã¢ããŒã
- TPM v2
- IOMMUïŒVT-dïŒ
èšå®æ¹æ³
ããšãã°ããªãã·ã§ã³ãæ€èšããŸããå°çšãµãŒããŒãã¬ã³ã¿ã«ãããããä¿è·ãããå Žåã TPMèªèšŒã䜿çšãããŸãã ãã¹ããšHGSéã®æ¥ç¶ã¯ãhttpãããã³ã«ãä»ããŠè¡ãããŸãã HGSãµãŒããŒã«çœãIPããªãå Žåã80çªç®ã®ããŒãã転éãããããªããŒã¹ãããã·ã䜿çšããå¿ èŠããããŸãã
ãµãŒããŒã§ã®HGSããŒã«ã®è¿œå ãšæ§æ
HGSãµãŒããŒã®ã€ã³ã¹ããŒã«ãšãã¡ã€ã³ã®äœæ
Install-WindowsFeature -Name HostGuardianServiceRole -IncludeManagementTools -Restart
HGSãæ©èœããã«ã¯ãã¡ã€ã³ãå¿ èŠã§ãã æ¢åã®ãã¡ã€ã³ã«æ¥ç¶ã§ããŸãããã»ãã¥ãªãã£ã匷åããããã«å¥ã®ãã¡ã€ã³ãäœæããããšããå§ãããŸãã 次ã®ã³ãã³ããå®è¡ããåã«ãã³ã³ãã¥ãŒã¿ãŒããã¡ã€ã³ã«æ¥ç¶ãããŠããªãããšã確èªããŠãã ããã
$adminPassword = ConvertTo-SecureString -AsPlainText '<password>' -Force Install-HgsServer -HgsDomainName 'relecloud.com' -SafeModeAdministratorPassword $adminPassword -Restart
èªå·±çœ²å蚌ææžãäœæãã
ãã¹ãçšã«èªå·±çœ²å蚌ææžãäœæãããŸããããå®éã®ç°å¢ã«ã¯PKIã®æ¹ãé©ããŠããŸãã
$certificatePassword = ConvertTo-SecureString -AsPlainText '<password>' -Force $signingCert = New-SelfSignedCertificate -DnsName "signing.relecloud.com" Export-PfxCertificate -Cert $signingCert -Password $certificatePassword -FilePath 'C:\signingCert.pfx' $encryptionCert = New-SelfSignedCertificate -DnsName "encryption.relecloud.com" Export-PfxCertificate -Cert $encryptionCert -Password $certificatePassword -FilePath 'C:\encryptionCert.pfx'
HGSãµãŒããŒã®åæå
æå·åããã³çœ²å蚌ææžãæå®ããŸãã èªèšŒæ¹æ³ãéžæããŸãã
$certificatePassword = ConvertTo-SecureString -AsPlainText '<password>' -Force Initialize-HgsServer -HgsServiceName '<HgsServiceName>' -SigningCertificatePath 'C:\signingCert.pfx' -SigningCertificatePassword $certificatePassword -EncryptionCertificatePath 'C:\encryptionCert.pfx' -EncryptionCertificatePassword $certificatePassword [-TrustActiveDirectory | -TrustTPM]
Hyper-Vã§ä¿è·ããããã¹ãã®è¿œå
TPM IDãååŸãã
ãã®æé ã¯ãä¿è·ããããã¹ãããšã«å®è¡ããå¿ èŠããããŸãã
(Get-PlatformIdentifier -Name '<HostName>').InnerXml | Out-file <Path><HostName>.xml -Encoding UTF8
çµæã®ãã¡ã€ã«ãHGSãµãŒããŒã«è¿œå ããŸã
Add-HgsAttestationTpmHost -Path <Path><Filename>.xml -Name <HostName> -Force
ã³ãŒãæŽåæ§ããªã·ãŒãäœæããŠé©çšããŸã
ããªã·ãŒãäœæãããšãã€ã³ã¹ããŒã«ãããŠãããã¹ãŠã®ããã°ã©ã ãã¹ãã£ã³ããããã¯ã€ããªã¹ãã«è¿œå ãããŸãã ããªã·ãŒãäœæããåã«ãã·ã¹ãã ã次ã®ããšã確èªããå¿ èŠããããŸãã
- ãŠã€ã«ã¹ããã«ãŠã§ã¢ã¯ãããŸãã
- æäœã«å¿ èŠãªãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ãããŠãããä¿¡é Œæ§ãé«ã
ããªã·ãŒãç£æ»ã¢ãŒãã§ããããšãæåã«ç¢ºèªããããšããå§ãããŸãã ãã®å Žåãããªã·ãŒã§çŠæ¢ãããŠããå®è¡å¯èœãã¡ã€ã«ããã°ã«è¡šç€ºãããŸãã
ã¹ãã£ã³ã«ã¯æéãããããŸãã
New-CIPolicy -Level FilePublisher -Fallback Hash -FilePath 'C:\temp\HW1CodeIntegrity.xml' -UserPEs ConvertFrom-CIPolicy -XmlFilePath 'C:\temp\HW1CodeIntegrity.xml' -BinaryFilePath 'C:\temp\HW1CodeIntegrity.p7b'
.p7bãã¡ã€ã«ã®ååãSIPolicy.p7bã«å€æŽãããã©ã«ããŒCïŒ\ Windows \ System32 \ CodeIntegrity \ SIPolicy.p7bã«ã³ããŒããå¿ èŠããããŸãã
ã³ã³ãã¥ãŒã¿ãŒãåèµ·åããèšç»ãããæšæºçãªè² è·ã®äžã§ã·ã¹ãã ã®åäœã確èªããŸãã ã·ã¹ãã ã®æ£åžžãªãã§ãã¯ã®åŸãç£æ»ã¢ãŒããç¡å¹ã«ããŸã
Set-RuleOption -FilePath 'C:\temp\HW1CodeIntegrity.xml' -Option 3 -Delete ConvertFrom-CIPolicy -XmlFilePath 'C:\temp\HW1CodeIntegrity.xml' -BinaryFilePath 'C:\temp\HW1CodeIntegrity_enforced.p7b' Copy-Item -Path '<Path to HW1CodeIntegrity\_enforced.p7b>' -Destination 'C:\Windows\System32\CodeIntegrity\SIPolicy.p7b' Restart-Computer
è€æ°ã®åäžãã¹ããä¿è·ãããŠããå Žåãããªã·ãŒã¯1åããäœæã§ããŸããã
ããªã·ãŒãå€æŽããå¿ èŠãããå Žåã«åã¹ãã£ã³ããå¿ èŠããªãããã«ãå ã®XMLãã¡ã€ã«ãæ®ãããšããå§ãããŸãã
ããªã·ãŒãæå¹ã«ãããšãã«ãŒãã«ã¢ãŒããã©ã€ããŒãæŽæ°ãŸãã¯è¿œå ãããšãã«ãã·ã¹ãã ã®èµ·åã劚ããå¯èœæ§ãããããã泚æããå¿ èŠããããŸãã
HGSãµãŒããŒã«ããªã·ãŒãç»é²ããŸã
Add-HgsAttestationCIPolicy -Path <Path> -Name '<PolicyName>'
TPMããŒã¹ã©ã€ã³ããªã·ãŒã®äœæ
ãã®ããªã·ãŒã¯ãTPMã¢ãžã¥ãŒã«ã«ããPCRã¬ãžã¹ã¿ãŒïŒãã©ãããã©ãŒã æ§æã¬ãžã¹ã¿ãŒïŒã«åºã¥ããŠããŸãã BIOSã®ããŒãããã·ã¹ãã ã®ã·ã£ããããŠã³ãŸã§ãã·ã¹ãã ã®ã¡ããªãã¯ã®æŽåæ§ãä¿åããŸãã ã«ãŒãããããªã©ã«ãã£ãŠããŒãé åºãå€æŽãããå ŽåãPCRã¬ãžã¹ã¿ã«è¡šç€ºãããŸãã
åäžã®ããŒããŠã§ã¢ãã¹ãã®ã¯ã©ã¹ã«å¯ŸããŠããªã·ãŒãäœæãããŸãã äœæããåã«ãHyper-Vãã€ã³ã¹ããŒã«ããŠããå¿ èŠããããŸãã
Install-WindowsFeature Hyper-V, HostGuardian -IncludeManagementTools -Restart Get-HgsAttestationBaselinePolicy -Path 'HWConfig1.tcglog'
ãã®ã³ãã³ãã§ã¯ãã»ãã¥ã¢ããŒããIOMMUïŒVT-dïŒãä»®æ³åããŒã¹ã®ã»ãã¥ãªãã£ãæå¹ã«ããå¿ èŠããããŸãã
ã³ãã³ãã®å®è¡ãèš±å¯ãã-SkipValidationãã©ã°ã䜿çšã§ããŸããããšã©ãŒã¯ä¿®æ£ãããŸããã
TCGlogãã¡ã€ã«ãHGSãµãŒããŒã«è¿œå ãã
Add-HgsAttestationTpmPolicy -Path <Filename>.tcglog -Name '<PolicyName>'
HGSãµãŒããŒã®ã¹ããŒã¿ã¹ã確èªãã
ãã®æç¹ã§ãHGSãµãŒããŒã®æ§æã¯çµäºããŸãã å®è¡ãããäœæ¥ã確èªããããã«ã蚺æãå®æœããŸãã
Get-HgsTrace -RunDiagnostics
Hyper-Vãã¹ããHGSãµãŒããŒã«æ¥ç¶ããŸã
ä¿è·ããããã¹ããHGSãµãŒããŒã«æ¥ç¶ããã«ã¯ããµãŒããŒã®URLãæå®ããã ãã§ãã
Set-HgsClientConfiguration -AttestationServerUrl 'http://<FQDN>/Attestation' -KeyProtectionServerUrl 'http://<FQDN>/KeyProtection'
é©åã«æ§æãããšã次ã®ããã«ãªããŸãã
- IsHostGuardedïŒtrue
- AttestationStatusïŒåæ Œ
äœããæ£ããèšå®ãããŠããªãå Žåãçç±ã¯AttestationStatusã«ç€ºãããŸãã
ã·ãŒã«ããããä»®æ³ãã·ã³ã®äœæ
VMããµãŒããŒã«ãã€ã³ãããããã«å¿ èŠãªHGSãµãŒããŒèšè¿°ãã¡ã€ã«ãååŸããŸãã
Invoke-WebRequest http://<"HGSServer">FQDN>/KeyProtection/service/metadata/2014-07/metadata.xml -OutFile C:\HGSGuardian.xml
HGSã䜿çšããããã«æ§æãããŠããªãWindows Server 2016ãå®è¡ããŠããå¥ã®ãã·ã³ã§VMãäœæããå¿ èŠããããŸãã
æ°ãã第2äžä»£ã®VMãäœæãããã®äžã«OSãã€ã³ã¹ããŒã«ããRDPãæ§æããŠãã®ããã©ãŒãã³ã¹ã確èªãããããããã«ãŒã§æå·åããŸãã
VMã·ãŒã«ã
VMåãèšå®ãã
$VMName = 'SVM'
VMããªãã«ããŸã
Stop-VM âVMName $VMName
ææ暩蚌ææžãäœæãã
$Owner = New-HgsGuardian âName 'Owner' âGenerateCertificates
ãµãŒããŒèšŒææžãã€ã³ããŒããã
$Guardian = Import-HgsGuardian -Path 'C:\HGSGuardian.xml' -Name 'TestFabric' âAllowUntrustedRoot
ããŒãããã¯ã¿ãŒãäœæãã
$KP = New-HgsKeyProtector -Owner $Owner -Guardian $Guardian -AllowUntrustedRoot
ã·ãŒã«ãããªã³ã«ãã
Set-VMKeyProtector âVMName $VMName âKeyProtector $KP.RawData Set-VMSecurityPolicy -VMName $VMName -Shielded $true
ä»®æ³ãã·ã³ã§vTPMãæå¹ã«ããŸã
Enable-VMTPM -VMName $VMName
VMã§ä¿è·ãæ§æããŠæå¹ã«ããåŸãä¿è·ããããã¹ãã«ç§»åããå¿ èŠããããŸãã ãããè¡ãã«ã¯ããã·ã³ããšã¯ã¹ããŒãããåä¿¡ãããã¡ã€ã«ããã¹ãã«è»¢éããŠãHyper-Vã³ã³ãœãŒã«ã«ã€ã³ããŒãããŸãã
ãã®æ®µéã§ãæ§æãå®äºããVMãä¿è·ãããŸãã
ã·ãŒã«ããããVMã®åäœã®ç¢ºèª
Hyper-Vã³ã³ãœãŒã«ãä»ããŠVMã«æ¥ç¶ããããšãããšã次ã®ã¡ãã»ãŒãžã衚瀺ãããŸãã
ãŸããVMèšå®ã§ã¯ãä¿è·èšå®ãå€æŽã§ããªãããšã«é¢ããèŠåã衚瀺ãããŸãã
ä»®æ³ãã·ã³ããŒãã£ã·ã§ã³ã¯BitLockerã«ãã£ãŠä¿è·ãããŠããŸãã
ãã®ããã«ãã·ãŒã«ããããVMãæ§æãããä»®æ³ãã·ã³ãããé«ãã¬ãã«ã§ä¿è·ããŸãã ã質åãããã°ãã³ã¡ã³ãããŠãã ããã
ã»ã«ããã³ã«é¢ããä»ã®èšäº