Before You Begin
Installing a custom certificate requires that you have at least your SSL certificate and CA certificate.
Note:
When you use Cryptographic Security Platform Vault to create a CSR, and then use that CSR to generate an SSL certificate from the external CA you want to use, you will need to upload the CA certificate and the SSL certificate.
If you create the CSR outside of Cryptographic Security Platform Vault, you will need to upload the CA certificate, the SSL certificate, and the matching private key file for the SSL certificate. If the private key file is encrypted, you will also need to enter the password used to decrypt the private key.
Procedure
Log into the Cryptographic Security Platform Vault Management webGUI using an account with Domain Admin privileges.
Click Settings.
Under KMIP Vault Settings section, select Enabled to make changes.
In the Certificate Types field, select the Custom radio button.
In the SSL Certificate field, click Browse, select your SSL certificate, and then click Open.
In the CA Certificate field, click Browse, select your CA certificate, and then click Open.
Choose whether or not to use this CA certificate to verify your KMIP client certificate.
Note: If you select Yes, then all existing KMIP client certificates in the individual KMIP vaults will no longer work. Vault Administrators will be required to upload a new KMIP client certificate, signed by this CA certificate, within their respective KMIP vaults. Until the Vault Administrators upload the new certificate, their vaults will not be able to communicate with the Cryptographic Security Platform Vault KMIP server.
Important: If you change this value to Yes, the only way to set this back to No is to reset the KMIP server.
In the Private Key field, click Browse, select your private key, and then click Open.
Note: This is only required if you created your SSL certificate outside of Cryptographic Security Platform Vault.
In the Password field, enter the password to decrypt your private key.
Note: This is only required if you created your SSL certificate outside of Cryptographic Security Platform Vault, and the private key is encrypted.
Click Apply to overwrite the KMIP Server settings.