6.5.1

Table Of Contents
Use the Upload Certificate and Private Key Option to Establish a Trusted
Connection
Some KMS vendors such as HyTrust require that you upload the KMS server certificate and private key to
the vCenter Server system.
Some KMS vendors generate a certificate and private key for the connection and make them available to
you. After you upload the files, the KMS trusts your vCenter Server instance.
Prerequisites
n
Request a certificate and private key from the KMS vendor. The files are X509 files in PEM format.
Procedure
1 Log in to the vSphere Web Client, and select a vCenter Server system.
2 Click Configure and select Key Management Servers.
3 Select the KMS instance with which you want to establish a trusted connection.
4 Select Upload certificate and private key and click OK.
5 Paste the certificate that you received from the KMS vendor into the top text box or click Upload File
to upload the certificate file.
6 Paste the key file into the bottom text box or click Upload File to upload the key file.
7 Click OK.
What to do next
Finalize the trust relationship. See Complete the Trust Setup.
Set the Default KMS Cluster
You must set the default KMS cluster if you do not make the first cluster the default cluster, or if your
environment uses multiple clusters and you remove the default cluster.
Prerequisites
As a best practice, verify that the Connection Status in the Key Management Servers tab shows Normal
and a green check mark.
Procedure
1 Log in to the vSphere Web Client and select a vCenter Server system.
2 Click the Configure tab and click Key Management Servers under More.
3 Select the cluster and click Set KMS cluster as default.
Do not select the server. The menu to set the default is available only for the cluster.
vSphere Security
VMware, Inc. 161