6.7

Table Of Contents
Procedure
1 Log in to the vCenter Server system with the vSphere Client (HTML5-based client).
2 Browse the inventory list and select the vCenter Server instance.
3 Click Configure and click Key Management Servers.
4 Click Add, specify the KMS information in the wizard, and click OK.
5 Click Trust.
The wizard displays that vCenter Server trusts the KMS with a green check mark.
6 Click Make KMS Trust vCenter.
7 Select the option appropriate for your server and complete the steps.
Option See
Root CA certificate Use the Root CA Certificate Option to Establish a Trusted Connection.
Certificate Use the Certificate Option to Establish a Trusted Connection.
New Certificate Signing Request Use the New Certificate Signing Request Option to Establish a Trusted
Connection.
Upload certificate and private key Use the Upload Certificate and Private Key Option to Establish a Trusted
Connection.
8 Click Establish Trust.
The wizard displays that the KMS trusts vCenter Server with a green check mark.
9 Set the default KMS.
a From the Actions menu, select Change Default Cluster.
b Select the KMS cluster and click Save.
The wizard displays the KMS cluster as the current default.
Add a KMS to vCenter Server in the vSphere Web Client
You add a KMS to your vCenter Server system from the vSphere Web Client or by using the public API.
vCenter Server creates a KMS cluster when you add the first KMS instance.
n
When you add the KMS, you are prompted to set this cluster as a default. You can later change the
default cluster explicitly.
n
After vCenter Server creates the first cluster, you can add KMS instances from the same vendor to
the cluster.
n
You can set up the cluster with only one KMS instance.
n
If your environment supports KMS solutions from different vendors, you can add multiple KMS
clusters.
vSphere Security
VMware, Inc. 156