6.7

Table Of Contents
5 In the dialog box, copy the full certificate in the text box to the clipboard or download it as a file, and
click OK.
Use the Generate new CSR button in the dialog box only if you explicitly want to generate a CSR.
Using that option makes any signed certificates that are based on the old CSR invalid.
6 Follow the instructions from your KMS vendor to submit the CSR.
7 When you receive the signed certificate from the KMS vendor, click Key Management Servers
again, and select New Certificate Signing Request again.
8 Paste the signed certificate into the bottom text box or click Upload File and upload the file, and click
OK.
What to do next
Finalize the trust relationship. See Complete the Trust Setup.
Use the Upload Certificate and Private Key Option to Establish a Trusted
Connection
Some KMS vendors such as HyTrust require that you upload the KMS server certificate and private key to
the vCenter Server system.
Some KMS vendors generate a certificate and private key for the connection and make them available to
you. After you upload the files, the KMS trusts your vCenter Server instance.
Prerequisites
n
Request a certificate and private key from the KMS vendor. The files are X509 files in PEM format.
Procedure
1 Log in to the vSphere Web Client, and select a vCenter Server system.
2 Click Configure and select Key Management Servers.
3 Select the KMS instance with which you want to establish a trusted connection.
4 Select Upload certificate and private key and click OK.
5 Paste the certificate that you received from the KMS vendor into the top text box or click Upload File
to upload the certificate file.
6 Paste the key file into the bottom text box or click Upload File to upload the key file.
7 Click OK.
What to do next
Finalize the trust relationship. See Complete the Trust Setup.
Set the Default KMS Cluster
You must set the default KMS cluster if you do not make the first cluster the default cluster, or if your
environment uses multiple clusters and you remove the default cluster.
vSphere Security
VMware, Inc. 160