You manage your KMIP configuration in the Cryptographic Security Platform Vault.
KMIP (Key Management Interoperability Protocol) enables the secure creation and storage of keys and other security objects on a key management server. Cryptographic Security Platform Vault includes a fully functional KMIP server that you can use to serve requests from external KMIP clients. The KMIP server is required if you want to use Cryptographic Security Platform Vault with servers encrypted by vSphere.
You can use KMIP with multiple vaults. This allows security administrators to isolate different KMIP environments for security and compliance.
Each KMIP vault has its own KMIP objects, client certificates, access policies, audit logs, Local User Accounts, Active Directory settings, and HSM root key label for KEK wrapping.
Each KMIP vault has access to its own Cryptographic Security Platform Vault for KMIP webGUI. Cryptographic Security Platform Vault-managed user accounts and Cryptographic Security Platform Vault Security Administrators do not have access to the Cryptographic Security Platform Vault for KMIP webGUI.
The KMIP vault supports Local User Authentication and Managed Authentication. If you create the vault with Local User Authentication, the Cryptographic Security Platform Vault stores all user usernames and passwords, and you can manage users in the Cryptographic Security Platform Vault for KMIP webGUI. With Managed Authentication, you can use an external authentication service such as Active Directory, OpenLDAP, or OIDC.
Note: The Cryptographic Security Platform Vault for KMIP webGUI has an automatic timeout value of 15 minutes.