Skip to main content

Managing the KMIP Server

This document explains how administrators can manage and configure the Securosys KMIP Server.

The KMIP Server stores its configuration in data objects on the HSM in the Base Partition. During startup, the KMIP Server reads these data objects. Therefore, to edit the configuration, these data objects need to be modified.

The KMIP Server has no administrative interface of its own. Instead, the Securosys Key Manager provides the interface to manage the KMIP Server. The Key Manager provides a convenient UI interface to edit and write the HSM data objects in the correct format.

The Key Manager can:

  • Install the KMIP Server, as an optional part of the KMS stack (see the KMS Installation).
  • Create the KMIP clients and issue their keystore and truststore (see Manage KMIP Clients).
  • Edit the server properties, assign HSM Partitions, and read the server logs.

The CyberVault KMS deployment is therefore a prerequisite for running the KMIP Server.

info

Once configured, the KMIP Server works on its own. KMIP clients connect to it directly over mTLS, and it translates their requests to the HSM. No client traffic passes through the Key Manager.

See Multitenancy for the data objects that are stored, and for how the KMIP clients are distributed over multiple HSM Partitions.

How to Configure the KMIP Server

  1. Log in to the Key Manager UI as an administrator.
  2. Go to Add-ons > KMIP Server > Server.
  3. Change the settings as desired.
  4. Click Save.
  5. Restart the KMIP Server for the change to take effect.
danger

Do not manually modify the data objects used by the KMIP Server. Always use the Key Manager UI to edit the configuration.

Get started withCloudHSM for free.
Other questions?Ask Sales.
Feedback
Need help?