6.5.1

Table Of Contents
You can find information about VMware certified KMS vendors in the VMware Compatibility Guide under
Platform and Compute. If you select Compatibility Guides, you can open the Key Management Server
(KMS) compatibility documentation. This documentation is updated frequently.
Virtual Machine Encryption Key Management Server Setup
(http://link.brightcove.com/services/player/bcpid2296383276001?
bctid=ref:video_vm_encryption_key_server_setup)
Add a KMS to vCenter Server
You add a KMS to your vCenter Server system from the vSphere Web Client or by using the public API.
vCenter Server creates a KMS cluster when you add the first KMS instance.
n
When you add the KMS, you are prompted to set this cluster as a default. You can later change the
default cluster explicitly.
n
After vCenter Server creates the first cluster, you can add KMS instances from the same vendor to
the cluster.
n
You can set up the cluster with only one KMS instance.
n
If your environment supports KMS solutions from different vendors, you can add multiple KMS
clusters.
n
If your environment includes multiple KMS clusters, and you delete the default cluster, you must set
the default explicitly. See Set the Default KMS Cluster.
Prerequisites
n
Verify that the key server is in the vSphere Compatibility Matrixes and is KMIP 1.1 compliant, and that
it can be a symmetric key foundry and server.
n
Verify that you have the required privileges: Cryptographic operations.Manage key servers.
n
Connecting to a KMS by using only an IPv6 address is not supported.
Procedure
1 Log in to the vCenter Server system with the vSphere Web Client.
2 Browse the inventory list and select the vCenter Server instance.
3 Click Configure and click Key Management Servers.
4 Click Add KMS, specify the KMS information in the wizard, and click OK.
Option Value
KMS cluster Select Create new cluster for a new cluster. If a cluster exists, you can select
that cluster.
Cluster name Name for the KMS cluster. You might need this name to connect to the KMS if
your vCenter Server instance becomes unavailable.
Server alias Alias for the KMS. You might need this alias to connect to the KMS if your
vCenter Server instance becomes unavailable.
vSphere Security
VMware, Inc. 157