6.7

Table Of Contents
Set up the Key Management Server Cluster
Before you can start with virtual machine encryption tasks, you must set up the key management server
(KMS) cluster. That task includes adding the KMS and establishing trust with the KMS. When you add a
cluster, you are prompted to make it the default. You can explicitly change the default cluster.
vCenter Server provisions keys from the default cluster.
The KMS must support the Key Management Interoperability Protocol (KMIP) 1.1 standard. See the
vSphere Compatibility Matrixes for details.
You can find information about VMware certified KMS vendors in the VMware Compatibility Guide under
Platform and Compute. If you select Compatibility Guides, you can open the Key Management Server
(KMS) compatibility documentation. This documentation is updated frequently.
Virtual Machine Encryption Key Management Server Setup
(http://link.brightcove.com/services/player/bcpid2296383276001?
bctid=ref:video_vm_KMS_vsphere67)
Add a KMS to vCenter Server in the vSphere Client
You can add a Key Management Server (KMS) to your vCenter Server system from the vSphere Client
(HTML5-based client) or by using the public API.
The vSphere Client (HTML5-based client) provides a wizard to add a KMS to your vCenter Server
system, and establish trust between the KMS and vCenter Server.
vCenter Server creates a KMS cluster when you add the first KMS instance.
n
After vCenter Server creates the first cluster, you can add KMS instances from the same vendor to
the cluster.
n
You can set up the cluster with only one KMS instance.
n
If your environment supports KMS solutions from different vendors, you can add multiple KMS
clusters.
n
If your environment includes multiple KMS clusters, and you delete the default cluster, you must set
another default explicitly.
Note The following steps apply to vCenter Server Appliance. For vCenter Server on Windows, you are
prompted to first make the KMS trust vCenter Server, then make vCenter Server trust the KMS.
Prerequisites
n
Verify that the key server is in the VMware Compatibility Guide for Key Management Servers (KMS)
and is KMIP 1.1 compliant, and that it can be a symmetric key foundry and server.
n
Verify that you have the required privileges: Cryptographic operations.Manage key servers.
n
You can configure the KMS with IPv6 addresses.
n
Both vCenter Server and the KMS can be configured with only IPv6 addresses.
vSphere Security
VMware, Inc. 155