VMware VM Encryption
Register DuoKey as a vCenter Native Key Provider KMS cluster for VM, vTPM and vSAN datastore encryption.
Overview
vSphere's Native Key Provider lets vCenter Server encrypt VMs, virtual TPMs and vSAN datastores using keys it retrieves from an external KMIP key manager. DuoKey's VMware VM Encryption integration registers Cockpit as that KMS cluster: vCenter creates and registers an AES-256 key with Cockpit's KMIP listener — the same KMIP-based key custody model used elsewhere in DuoKey's database and infrastructure integrations, applied here to vSphere's own VM-encryption workflow.
vCenter's Native Key Provider talks directly to the Cockpit's KMIP listener as a trusted KMS cluster; the key never leaves DuoKey custody.
There is no setup wizard for this integration: you register the vCenter connection details directly, then generate a deployment bundle to hand to the vSphere administrator.
Cockpit records which vCenter's KMS cluster is bound to which key and KMIP endpoint, and generates the onboarding commands. Configuring the KMS cluster inside vCenter and applying encryption storage policies are operations the vSphere administrator runs — DuoKey does not reach into vCenter to perform them.
Configuration
| Field | Purpose |
|---|---|
| vCenter host / port | The vCenter Server endpoint. |
| Datacenter | Optional datacenter scope. |
| KMS cluster name | The name vCenter will show for this KMS cluster (for example, `dke-cockpit`). |
| Default KMS | Whether this cluster should be marked as the default KMS for new VM/vTPM/vSAN encryption. |
| Policy targets | The clusters, datastores or VMs the resulting encryption storage policy should be applied to. |
| KMIP port | The binary KMIP (TTLV/mTLS) port vCenter dials — 5696 by default. |
| Key rotation days | Optional target rotation interval for the KMS key. |
| Vault | The DuoKey vault that holds the AES-256 key. Defaults to the tenant vault when not specified. |
Onboarding a vCenter
Steps 1, 2 and 4 run the govc (or vSphere Client) commands generated by the deployment bundle; DuoKey never reaches into vCenter to run them.
Register the vCenter instance
Provide the vCenter endpoint, datacenter, KMS cluster name, and the clusters/datastores/VMs the encryption policy should target. DuoKey creates the AES-256 key in the linked vault.
Generate the deployment bundle
DuoKey returns the KMIP connection details (host, port, and the mTLS client certificate / key / CA paths vCenter needs) plus an ordered list of onboarding commands for the vSphere administrator.
Add and trust the KMS cluster in vCenter
Add DuoKey as a KMS cluster, exchange certificates so vCenter and Cockpit's KMIP listener trust each other, and — if this should be the default — mark it as the default KMS cluster.
Apply the encryption storage policy
Apply VM encryption to the configured policy targets, then verify the KMS cluster shows a trusted, active connection in vCenter.
# 1. Add DuoKey's KMIP listener as a KMS cluster
govc crypto.kms.add -name=<kms-cluster-name> -address=<kmip-host> -port=<kmip-port>
# 2. Establish mutual trust
govc crypto.kms.trust -cert=<ca-cert-path> <kms-cluster-name>
# 3. (Optional) mark as the default KMS cluster
govc crypto.kms.default <kms-cluster-name>
# 4. Verify the KMS cluster is trusted and active
govc crypto.kms.info <kms-cluster-name>The same steps are available from the vSphere Client under Configure > Key Providers > Add Standard/Native Key Provider; the commands above are the govc CLI form of the same workflow.
Health and connectivity
The instance's health check reports vCenter reachability, KMIP connectivity, whether KMS trust is established, whether the key is active, and a combined encryption-enabled indicator. A test-connection check validates the stored configuration and surfaces any configuration warnings before you generate the deployment bundle.
Health results reflect the configuration and key state stored in DuoKey. Confirm the KMS cluster's trust status in vCenter as the source of truth for whether it is actually trusted and in use.
Prerequisites
المتطلبات المسبقة
- A vSphere environment on a version that supports the Native Key Provider
- vCenter Server administrative access to configure Key Providers
- Network reachability from vCenter to DuoKey Cockpit's KMIP listener over the configured KMIP port
- A DuoKey vault to hold the AES-256 KMS key
A single DuoKey-backed KMS cluster can back the encryption policy for multiple clusters, datastores or individual VMs — list every target you plan to encrypt as a policy target rather than creating a separate integration per VM.