Using EFS Encryption To Secure Your Virtual Domain Controllers
Tuesday, 07 March 2006 by Michel Roth
Domain Controllers are one of those roles that lend themselves nicely to Virtual Machines. The concern is what if some nasty person copies the VHD and takes it home. Now the nasty person can work on compromising your network at their leisure.

So for added security, you can implement EFS on the host operating system as well as guest operating systems that are running Windows Server 2003 operating systems. The most efficient way to implement EFS on all of the guest operating systems is to implement it on the host
operating system instead. This requires fewer system resources, and conveys the benefits to all resident guest operating systems.

Andre Keartland of Inobits Consulting has researched EFS and VHDs and has posted his results:

"Test results showed barely a 5% increase in host CPU utilization when running at peak load, by comparison to the same load where the VPC was unencrypted. Either way we couldn’t get the CPU load beyond 45-50% on average. There was no discernible increase in CPU load on the guest VPC when using EFS. Disk and memory utilization on the host increased negligibly after the VHD was encrypted. There was no noticeable degradation of host or guest performance/responsiveness after the VHD was encrypted."

"Disk utilization on the host system was heavy, as can be expected with the load described. This was probably the biggest performance constraint on performance. Place virtual machines VHDs on separate disks from the host OS, apps and page-file; use virtual SCSI controllers for VHDs. After this make sure the server has adequate RAM. CPU capacity is probably the least important factor affecting Virtual Server performance. Having separate network adapters for your virtual machine traffic is also a good idea."

"All in all, I think the performance impact was quite acceptable. Unless something comes up, e.g. Microsoft telling me this scenario is now officially unsupported, I plan to use EFS for all my DCs running on Virtual Server."

Read more at the source.

Related Items:

Improving Virtual Server Performance (27 February 2006)
VMware Player (21 October 2005)
Hardware Requirements For 64-Bit Guest Operating Systems (11 May 2006)
Third-party Guest Operating Systems That Are Supported For Use With Virtual Server 2005 R2 (6 April 2006)
Performance Optimization For VMs (20 September 2006)
Microsoft Will Start Virtual PC 2007 Public Beta Program In October (29 September 2006)
How To Build And Optimize A Virtual Machine Guest (12 July 2006)
Improving Scalability For Citrix Presentation Server In VI3 (27 December 2006)
Requirements and Limits for Virtual Machines and Hyper-V in Windows Server 2008 R2 (26 August 2009)
VMware ESX Server Guest OS Performance Tips -Part Two (15 December 2006)
Comments (0)