إنتقل إلى المحتوى الرئيسي
ينطبق على:
DuoKey Cockpit v2VMware vSphere Native Key ProviderKMIP external KMS cluster

Overview​

vSphere's Native Key Provider lets vCenter Server encrypt VMs, virtual TPMs and vSAN datastores using keys it retrieves from an external KMIP key manager. DuoKey's VMware VM Encryption integration registers Cockpit as that KMS cluster: vCenter creates and registers an AES-256 key with Cockpit's KMIP listener — the same KMIP-based key custody model used elsewhere in DuoKey's database and infrastructure integrations, applied here to vSphere's own VM-encryption workflow.

vCenter to the DuoKey KMIP server
vCenter ServerNative Key Provider — KMS cluster clientVM, vTPM and vSAN datastore encryption
KMIP (TTLV) over mutual TLS — port 5696
DuoKey KMIP serverCockpit's KMIP listener — Create / Register / Get / Activate
seal / unseal
Tenant vault / HSMAES-256 KMS key sealed at rest

vCenter's Native Key Provider talks directly to the Cockpit's KMIP listener as a trusted KMS cluster; the key never leaves DuoKey custody.

There is no setup wizard for this integration: you register the vCenter connection details directly, then generate a deployment bundle to hand to the vSphere administrator.

Cockpit tracks the pairing, not vCenter

Cockpit records which vCenter's KMS cluster is bound to which key and KMIP endpoint, and generates the onboarding commands. Configuring the KMS cluster inside vCenter and applying encryption storage policies are operations the vSphere administrator runs — DuoKey does not reach into vCenter to perform them.

Configuration​

FieldPurpose
vCenter host / portThe vCenter Server endpoint.
DatacenterOptional datacenter scope.
KMS cluster nameThe name vCenter will show for this KMS cluster (for example, `dke-cockpit`).
Default KMSWhether this cluster should be marked as the default KMS for new VM/vTPM/vSAN encryption.
Policy targetsThe clusters, datastores or VMs the resulting encryption storage policy should be applied to.
KMIP portThe binary KMIP (TTLV/mTLS) port vCenter dials — 5696 by default.
Key rotation daysOptional target rotation interval for the KMS key.
VaultThe DuoKey vault that holds the AES-256 key. Defaults to the tenant vault when not specified.

Onboarding a vCenter​

vCenter onboarding, at a glance
1. Add DuoKey as a KMS clustergovc crypto.kms.add — vCenter registers Cockpit's KMIP listener
certificate exchange
2. Establish mutual trustgovc crypto.kms.trust — vCenter and Cockpit's KMIP listener trust each other
KMIP Create / Register — TTLV over mutual TLS, port 5696
3. vCenter creates and registers the keyTriggered when the encryption storage policy is applied; DuoKey activates the key
seal / unseal
4. Apply VM / vTPM / vSAN encryptionPolicy targets use the DuoKey-held key from the trusted KMS cluster

Steps 1, 2 and 4 run the govc (or vSphere Client) commands generated by the deployment bundle; DuoKey never reaches into vCenter to run them.

1

Register the vCenter instance

Provide the vCenter endpoint, datacenter, KMS cluster name, and the clusters/datastores/VMs the encryption policy should target. DuoKey creates the AES-256 key in the linked vault.

2

Generate the deployment bundle

DuoKey returns the KMIP connection details (host, port, and the mTLS client certificate / key / CA paths vCenter needs) plus an ordered list of onboarding commands for the vSphere administrator.

3

Add and trust the KMS cluster in vCenter

Add DuoKey as a KMS cluster, exchange certificates so vCenter and Cockpit's KMIP listener trust each other, and — if this should be the default — mark it as the default KMS cluster.

4

Apply the encryption storage policy

Apply VM encryption to the configured policy targets, then verify the KMS cluster shows a trusted, active connection in vCenter.

Example onboarding commands (govc CLI form)BASH
# 1. Add DuoKey's KMIP listener as a KMS cluster
govc crypto.kms.add -name=<kms-cluster-name> -address=<kmip-host> -port=<kmip-port>

# 2. Establish mutual trust
govc crypto.kms.trust -cert=<ca-cert-path> <kms-cluster-name>

# 3. (Optional) mark as the default KMS cluster
govc crypto.kms.default <kms-cluster-name>

# 4. Verify the KMS cluster is trusted and active
govc crypto.kms.info <kms-cluster-name>
vSphere Client equivalent

The same steps are available from the vSphere Client under Configure > Key Providers > Add Standard/Native Key Provider; the commands above are the govc CLI form of the same workflow.

Health and connectivity​

The instance's health check reports vCenter reachability, KMIP connectivity, whether KMS trust is established, whether the key is active, and a combined encryption-enabled indicator. A test-connection check validates the stored configuration and surfaces any configuration warnings before you generate the deployment bundle.

Configuration-derived status

Health results reflect the configuration and key state stored in DuoKey. Confirm the KMS cluster's trust status in vCenter as the source of truth for whether it is actually trusted and in use.

Prerequisites​

المتطلبات المسبقة

  • A vSphere environment on a version that supports the Native Key Provider
  • vCenter Server administrative access to configure Key Providers
  • Network reachability from vCenter to DuoKey Cockpit's KMIP listener over the configured KMIP port
  • A DuoKey vault to hold the AES-256 KMS key
One KMS cluster, multiple policy targets

A single DuoKey-backed KMS cluster can back the encryption policy for multiple clusters, datastores or individual VMs — list every target you plan to encrypt as a policy target rather than creating a separate integration per VM.