Any KMIP client can connect to the Cryptographic Security Platform Vault KMIP server and perform all standard KMIP operations with the following restrictions:

  • The Cryptographic Security Platform Vault KMIP server supports KMIP versions 1.0, 1.1, 1.2, 1.3, 1.4, 2.0, 2.1, and 3.0. The KMIP server protocol version is configured automatically and set between 1.0 to 3.0, as requested by the client.
  • The object count (for example, keys) is limited to 1 million KMIP objects per KeyControl Vault cluster. This limit includes all of the Cryptographic Security Platform Vault for KMIP instances in that cluster. If you exceed this limit, the KMIP server will still create and maintain the objects, but the Cryptographic Security Platform Vault for KMIP webGUI may not display those objects correctly.

Cryptographic Security Platform Vault includes a component for creating a Root Certificate Authority (CA) that can generate digital certificates. When you install the first Cryptographic Security Platform Vault node, it creates a Public CA and stores it in the Cryptographic Security Platform Vault object store. 

By default, the KMIP server uses a default certificate signed by the CA inside Cryptographic Security Platform Vault. You can change this by installing a custom SSL certificate for the KMIP server. To generate a custom SSL certificate, you can use a CSR created from Cryptographic Security Platform Vault for the KMIP server, or you can use your own CSR. If you use your own CSR, you must upload a private key for that custom certificate.

For details about the standard KMIP operations and configuration settings, see

Other considerations:

  • When a KMIP client connects to the Cryptographic Security Platform Vault for KMIP server, the client must use the certificates associated with a KMIP server user account. The KMIP server does not support username/password login credentials. For details about downloading a user account certificate bundle, see Creating a KMIP Client Certificate.
  • If you are configuring a KMIP server for VMware vSphere encryption or VSAN encryption, see the Entrust KeyControl with VMware VSAN and vSphere VM Encryption guide.

  • If you are using a KMIP server with KEK enabled, please ensure that the KEK cache timeout is enabled. Set the value to anything other than 0.

To configure a new KMIP Server

  1. Log in to the Cryptographic Security Platform Vault Management webGUI.
  2. Select the Settings icon at the top right of the vault page.
  3. On the KMIP Vault Settings page, complete the following. 

  4. Click Apply and confirm your changes when prompted.

State

The KMIP server status. Enable for clients to connect to the server.

Port 

The server port number. Defaults to 5696.

Verify

Yes to verify the KMIP client identity before the server handles its request; No otherwise.

Log Level

The lowest level of log messages saved in the audit log.

Level

Logged events

All

All requests to the KMIP server and responses from the KMIP server.

Create-Modify

Object creation, object modification requests, and object deletion requests and responses. This is the default level.

Create-Get

Object creation messages, object fetch requests, and object fetch responses.

Creat

Object creation request and response messages.

Get

Object fetch and object locate requests and responses.

Off

None

TLS

The supported TLS version. For example, select TLS 1.3 for all clients to connect to the KMIP server using TLS 1.3. Defaults to supporting both TLS 1.2 and TLS 1.3.

This setting applies to the KMIP server only and affects the entire cluster.

Timeout

The number of minutes after which a client request will time out. You can:

  • Select Yes and enter 1 to 60 minutes.
  • Select NO (default value) for client requests never to time out.

KMIP Locate Operation: Maximum Items Default

The maximum number of items to be returned from the KMIP server Locate operation.

The KMIP client allows you to set an offset items value (the record number the return starts with) and a maximum items value (how many items are returned) when you run the KMIP locate operation.

The maximum number of items depends on both the choice that you set in the webGUI and the value that you set in the KMIP Client. For example:

  • If you choose the default value in the webGUI, and you DO set a max value in the KMIP Client, it returns up to 1000 UUIDs.

  • If you choose the default value in the webGUI, and you do NOT set a max value in the KMIP Client, it returns up to 100 UUIDs.

  • If you choose the maximum items value from the KMIP Client in the webGUI and DO set a max value, it returns the maximum number of UUIDs set in the KMIP Client.

  • If you choose the maximum items value from the KMIP Client in the webGUI and do NOT set a max value, it returns all UUIDs found in the locate operation.

For more information on the KMIP Locate command, see https://docs.oasis-open.org/kmip/kmip-spec/.

SSL/TSL Ciphers

Enter the SSL ciphers in a comma-separated list that you want the KMIP server to use.

The following ciphers are not supported:  DHE-DSS-AES128-256 and DHE-DSS-AES128-SHA256.

Certificate Types

The certificate type. Select:

  • Default for the KMIP server to use a default certificate.
  • Custom to use a custom SSL certificate generated from Cryptographic Security Platform Vault or from your own CSR. You will need to provide the following: 
    • SSL Certificate: Upload the SSL certificate file in Base64-encoded PEM format. It must function as a server certificate.
    • CA Certificate: Upload the certificate for the CA that signed the custom SSL certificate in Base64-encoded PEM format. If you want to use the CA certificate to verify the KMIP client certificate, select Yes and upload a KMIP client certificate for every Cryptographic Security Platform Vault for KMIP.

    • Private Key: Optionally upload the private key file in Base64-encoded PEM format. This is required if you used your own CSR and not the CSR generated on the KMIP page.
    • Password: Optionally enter the password for the custom certificate.