Each KMIP Client that you want to connect to the Cryptographic Security Platform Vault KMIP server must use a client certificate/key pem file and optionally a server (cacert) certificate pem file generated by the KMIP server.
Note: When the KMIP client certificate expiration date is approaching, the alert will be generated in the Cryptographic Security Platform Vault Appliance webGUI.
The client certificate can be created using one of the following:
Username and password
Certificate name
Note: You can either use the user name and password or the certificate name. Whichever name you choose is not case-sensitive and will be displayed in lowercase letters only.
You can download an existing certificate bundle at any time. One or more KMIP clients can then use the certificates in the bundle when contacting the KMIP server.
Note: If you are creating a KMIP user account to use with VMware vSphere Encryption.
Procedure
- Log in to the Cryptographic Security Platform Vault for KMIP webGUI.
- From the Cryptographic Security Platform Vault for KMIP webGUI, select Security > Client Certificates.
- Select Actions > Create Certificate.
- On the Manage Client Certificate page, click the + icon to create a new client certificate.
In the Create Client Certificate dialog box, complete the appropriate sections:
If you check the Add Authentication for Certificate checkbox, complete the following:
Field
Description
User name on Certificate
Enter the user name for the certificate. This is the user name used to authorize this certificate. The user name is not case-sensitive.
User password on the Certificate
Enter the user password for the certificate. This password authorizes this certificate.
If you do not want to use authentication, complete the following:
Field
Description
Certificate Name
Enter the user-defined name for this bundle. If you create multiple KMIP certificate bundles, make this name descriptive enough to tell the bundles apart.
The name must start and end with an alphanumeric character. The only other characters allowed are hyphens (-) and underscores (_). You cannot change the name after you create the bundle. The certificate name is not case-sensitive.
Complete the rest of the fields as necessary:
Field
Description
Certificate Expiration
The date on which the certificates in the bundle will expire. If the certificates expire, communication between the Cryptographic Security Platform Vault KMIP server and the client will be disrupted until you upload a new certificate bundle to the client.
Certificate Signing Request (CSR)
To use an external CSR, click Load File and upload the CSR you want to use. The custom CSR must:
- Be in PKCS#10 format.
- Have a non-empty Common Name.
- If keyUsage is specified, it must include 'digitalSignature'.
If you do not specify an external CSR, Cryptographic Security Platform Vault uses an internally-generated CSR to create the certificate.
Encryption Password/
Confirm Encryption Password
Check the Encrypt Certificate Bundle checkbox to encrypt the certificates in the bundle, then enter and re-enter the encryption password.
Whether the certificates need to be encrypted depends on how your security is configured and the implementation you are using. Not all third-party KMIP clients can accept encrypted certificates.
For example, if you are integrating Cryptographic Security Platform Vault with VMware vSphere Encryption, you cannot specify a certificate passphrase because of vSphere limitations.
Click Create.
On the Manage Client Certificate page, select the certificate bundle that you just created and click Download.
The webGUI downloads a bundle containing one of the following:
<username_datetimestamp>.zipThis bundle contains a user certification/key file called
username.pemand a CA certificate calledcacert.pem.<certificatename_datetimestamp>.zipThis bundle contains a user certification/key file called
certificatename.pemand a CA certificate calledcacert.pem.
You can now upload the certificates on the KMIP client. You can use standard API calls to interact with the KMIP server.
Important: You cannot renew client certificates in the Cryptographic Security Platform Vault for KMIP webGUI. If the client certificate used by a KMIP client has expired, a new client certificate has to be created, and the KMIP client needs to be reconfigured with the new certificate.