6.5.1

Table Of Contents
4 Click Yes.
The word default appears next to the cluster name.
Complete the Trust Setup
Unless the Add Server dialog box prompted you to trust the KMS, you must explicitly establish trust after
certificate exchange is complete.
You can complete the trust setup, that is, make vCenter Server trust the KMS, either by trusting the KMS
or by uploading a KMS certificate. You have two options:
n
Trust the certificate explicitly by using the Refresh KMS certificate option.
n
Upload a KMS leaf certificate or the KMS CA certificate to vCenter Server by using the Upload KMS
certificate option.
Note If you upload the root CA certificate or the intermediate CA certificate, vCenter Server trusts all
certificates that are signed by that CA. For strong security, upload a leaf certificate or an intermediate CA
certificate that the KMS vendor controls.
Procedure
1 Log in to the vSphere Web Client, and select a vCenter Server system.
2 Click Configure and select Key Management Servers.
3 Select the KMS instance with which you want to establish a trusted connection.
4 To establish the trust relationship, refresh or upload the KMS certificate.
Option Action
Refresh KMS certificate a Click All Actions, and select Refresh KMS certificate.
b In the dialog box that appears, click Trust.
Upload KMS certificate a Click All Actions, and select Upload KMS Certificate.
b In the dialog box that appears, click Upload file, upload a certificate file, and
click OK.
Set up Separate KMS Clusters for Dierent Users
You can set up your environment with different KMS connections for different users of the same KMS
instance. Having multiple KMS connections is helpful, for example, if you want to grant different
departments in your company access to different sets of KMS keys.
Using multiple KMS clusters allows you to use the same KMS to segregate keys. Having separate sets of
keys is essential for use cases like different BUs or different customers.
Note Not all KMS vendors support multiple users.
vSphere Security
VMware, Inc. 162