Skip to main content
Applies to:
DuoKey Cockpit v2KMIP menu
KMIP is built into the Cockpit

DuoKey for KMIP is embedded in Cockpit v2 and driven entirely from the UI. There is no package or image to install and no separate KMIP database — you work from the KMIP item in the sidebar.

Prerequisites​

Prerequisites

  • A running DuoKey Cockpit v2 deployment
  • A key vault configured in the Cockpit
  • Endpoint permissions to deploy and manage a hosted KMIP endpoint (Server tab)
  • The Operations.Kmip permission to connect to external KMIP servers (Client tab)
  • Network access from your KMIP clients to the Cockpit host on the KMIP TLS port (default 5696)
  • X.509 client certificates if you will use mutual TLS (mTLS)

The KMIP menu​

Open KMIP from the sidebar. The page opens on a dashboard with four indicators — hosted Endpoints, how many are Running, connected External Servers, and active Connections — and two tabs that correspond to the two ways DuoKey uses KMIP:

TabWhat it does
ServerDuoKey hosts a KMIP endpoint. External clients (databases, storage arrays, virtualization) connect to the Cockpit as their key manager.
ClientDuoKey connects out to a third-party KMIP server to manage remote keys.

A Client Simulator button is available from either tab, so you can exercise KMIP operations against an endpoint before wiring up a real system.

Server mode — host a KMIP endpoint​

This is the common case: turn the Cockpit into a KMIP key manager that your clients connect to.

1

Open the Server tab

On the KMIP page, stay on the Server tab and click Deploy KMIP endpoint.

2

Identity

Name the endpoint (an optional slug forms its address) and select the key vault it will use.

3

Authentication

Choose the allowed authentication methods (mTLS, token, basic auth) and whether a client certificate is required.

4

Transport and keys

Select the transport (binary TLS on port 5696, or JSON over HTTPS) and set the default algorithm (AES) and key size (default 256).

5

Policy and deploy

Restrict the allowed object types and operations, enable audit logging, then deploy. The new endpoint appears in the Server tab.

Each hosted endpoint shows its status, request and error counters, and its address in the list. Use the row actions to view details or start / stop the endpoint — the binary KMIP listener serves whichever endpoint is currently Running.

Symmetric keys

Hosted endpoints generate symmetric key material (AES, HMAC). Asymmetric objects and certificates can be registered and managed, but the server does not mint RSA or EC key pairs itself.

Client mode — connect to an external KMIP server​

Switch to the Client tab to register a third-party KMIP server (for example Fortanix SDKMS or Thales CipherTrust) and manage its keys from DuoKey.

1

Add the server

On the Client tab, click Add external server and enter its host, port, and protocol.

2

Credentials

Provide the authentication method — none, token, basic auth, or a client certificate (mTLS) with the CA certificate to trust.

3

Test the connection

Save, then use the Test action on the row. A successful test reports the remote server's vendor identification.

Test with the Client Simulator​

Before pointing a production database at an endpoint, open the Client Simulator and run KMIP operations (create, activate, get, encrypt/decrypt, revoke, destroy) against it to confirm connectivity and policy behavior.

Reference client

Interoperability is also validated with the OASIS reference client, PyKMIP, which drives the same lifecycle over TLS on port 5696.

Connect your clients​

Point any OASIS KMIP 1.x / 2.x client at the Cockpit host and the KMIP TLS port, giving it its own certificate/key and trusting the Cockpit's CA.

VMware vSphere

Standard Key Provider pointing at the Cockpit host on port 5696.

NetApp ONTAP

External key manager with the client certificate and CA.

Percona (MySQL / MongoDB)

KMIP keyring/component with host, port 5696, and certificates.

Example: MongoDB with KMIP encryption at restYAML
security:
enableEncryption: true
kmip:
  serverName: cockpit.example.com
  port: 5696
  clientCertificateFile: /path/to/client-cert.pem
  serverCAFile: /path/to/ca-cert.pem

Next steps​