When using virtual Trusted Platform Module (vTPM) with technologies such as Omnissa Instant Clones or Full Clones, vCenter Server requests unique keys from the configured Key Provider for each virtual machine. In environments using a third-party Standard Key Provider (KMS), users may observe high key creation counts and notice that keys for deleted virtual machines are not automatically removed from the KMS.
vCenter Server does not include functionality to manage the deletion or lifecycle of keys stored on a third-party Standard Key Provider. vCenter requests keys for encryption and vTPM operations, but the cleanup of those keys is the responsibility of the Key Management Server (KMS).
vCenter Server does not support the automatic deletion of keys from a Standard Key Provider. To manage high key counts or remove unused keys, perform the following:
To speak with a customer representative or a Support Engineer see Contact Support. Scroll to the bottom of the page and click on your respective region.