Connect a vCenter Server System to a Key Provider
search cancel

Connect a vCenter Server System to a Key Provider

book

Article ID: 329104

calendar_today

Updated On:

Products

VMware vCenter Server VMware vSphere ESXi

Issue/Introduction

Before you can use vSphere Virtual Machine Encryption to perform encryption operations, you must connect your vCenter Server to a Key Provider. The exact steps depend on the process that the vendor supports, and on the vendor options.

This KB article explains how to connect to Key Provider. Because the process differs for different vendors and product versions, this article gives only an overview.

Prerequisites

Before your start this process, you have to install the Key Provider in your environment. Follow the instructions from the Key Provider vendor.



Environment

vSphere 7.0 and later

Resolution

vSphere 7.0.x

Task 1: Create the Key Provider

  1. Log in to the vCenter Server with the vSphere Web Client and select the vCenter Server in the inventory list.
  2. Click Configure and click Key Providers.
  3. Click Add Standard Key Provider, specify the following information, and click Add Key Provider.
    KMS/ Key Provider clusterSelect Create new cluster for a new cluster, or select an existing cluster.
    Cluster nameName of the Key Provider cluster that you want to create
    Server aliasUse this alias to connect to the Key Provider if your vCenter Server instance becomes unavailable.
    Server address and portIP address or FQDN of the KMS / Key Provider, and port on which vCenter Server connects to the Key Provider.
    Proxy address and portOptional proxy address and port for connecting to the Key Provider.
    Username and passwordSome Key Provider vendors allow users to isolate encryption keys that are used by different users or groups by specifying a user name and password. Specify a user name only if your Key Provider supports this functionality, and if you intend to use it.
  4. If you want to use that Key Provider as the default source of keys, click OK when prompted.
  5. Click Trust in the Trust Certificate dialog box to trust the Key Provider.

Task 2: Set up the Key Provider to Trust vCenter Server

Refer to the VMware Compatibility Guide for certified Key Provider's under Platform and Compute as well as links to partner public facing content for steps to configure a Key Provider with VMware vSphere.

Task 3: Verify or Finalize the Trust Setup

Refresh the Key Management Server screen to verify that the trust relationship is now established. The Connection Status for the Key Provider server shows Normal (green check mark).

To integrate with vendor Key Providers, please follow the certified vendor list at VMware Compatibility Guide.

 

vSphere 8.0.x

Task 1: Create the Key Provider

  1. Log in to the vCenter Server with the vSphere Web Client and select the vCenter Server in the inventory list.
  2. Click Configure and click Key Providers.
  3. Click Add and select Add Standard Key Provider, specify the following information, and click Add Key Provider
    NameName for the key provider.
    Each logical key provider, regardless of its type (Standard, Trusted, and Native Key Provider), must have a unique name across all vCenter Server systems.
    KMSAlias for the key server (KMS).
    AddressIP address or FQDN of the key server.
    PortPort on which vCenter Server connects to the key server.
    Proxy serverOptional proxy server address for connecting to the key server.
    Proxy port

    Optional proxy port for connecting to the key server.

    Some key server vendors allow users to isolate encryption keys that are used by different users or groups by specifying a user name and password.

    UsernameSpecify a user name only if your key server supports this functionality, and if you intend to use it.
    PasswordSpecify a password only if your key server supports this functionality, and if you intend to use it.
  4. Click Trust in the Trust Certificate dialog box to trust the Key Provider.

Task 2: Set up the Key Provider to Trust vCenter Server

Refer to the VMware Compatibility Guide for certified Key Provider's under Platform and Compute as well as links to partner public facing content for steps to configure a Key Provider with VMware vSphere.

Task 3: Verify or Finalize the Trust Setup

Refresh the Key Management Server screen to verify that the trust relationship is now established. The Connection Status for the Key Provider server shows Normal (green check mark).

To integrate with vendor Key Providers, please follow the certified vendor list at VMware Compatibility Guide.

Additional Information

vSphere 7 - Configuring and Managing a Standard Key Provider

vSphere 8 - Configuring and Managing a Standard Key Provider