Hi,
I have VMWare PRO 17.5 with Window 11 as host and also as guest on all my virtual machines.
I'm very concerned about TPM and encription. Windows 11 requires TMP.
If I want to enable TPM on the virtual machine, it looks it's not possible without encrypting the machine.
So, I'm forced to encrypt the machine.
When I encrypt the machine, I select the option "only the files needed to support TPM are encrypted (.nvram, .vmss, .vmem, .vmx, .vmsn)" because I don't want to encrypt virtual disk as well.
I always have disk C for operating system and software a disk D with all my precious data.
After encrypted the machine and enaled TPM, if I need to copy the virtual disk D to another virtual machine for any reason, I always get the error mesage: "cannot decrypt disk because key or password is incorrect"
So I'm now very afraid, if for any reason I cannot boot my machine, or the operating system gets corrupted, I cannot take my virtual disk D where I have all my data and attach it to a new virtual machine.
In the past with Windows 10, nothing was encrypted and I was able to move my virtual disk as I wanted and where I wanted.
Especially usefull when travelling and in case of booting problems or operating system crashes.
This is what I liked from the virtualization. Now, with this forced encryption it seems very danger.
Is it possible to enable TPM WITHOUT encrypting anything ?
If not, then is it possible to copy a virtual disk from an encrypted virtual machine to another machine (encrypted and/or not encrypted) ?
Another big problem that I have discovered: once the virtual machine is encrypted, if I create a new virtual disk, then I cannot remove it anymore.
It was a test virtual disk and I wanted to remove it, but the "Remove" button was not enable.
So I manually deleted that vmdk file hoping it was removed. Booom, no way to access my machine. No way to unencrypt my machine. Alway got an error about the missing disk (but it was not the booting disk, was the number 4 disk I have carted for couple of test and then I wanted to ermove it as I was able to do in the past when nothing was encrypted)
From my experiemnce, basically, only between not encrypted machines it's possible to move virtual hard disks.
If I want to add TPM to the virtual machine, I must encrypt the virtual machine, otherwise is not possible to add only the TPM without encrypting the virtual machine.
But if I encrypt the virtual machine, it becomes very danger if the hard disk cannot be attached to another machine in case of booting failure.
Do you have a solution ?
Thank you very much