Skip to main content
Applies to:
DuoKey Cockpit v2KMIP server endpoint
There is no admin CLI

KMIP operations are issued by KMIP clients over the wire (databases, storage, virtualization) — or from the built-in Client Simulator in the Cockpit's KMIP menu. You do not run key operations from a command line. In the Cockpit, open a hosted endpoint to see its Objects, Operations, and statistics.

Key lifecycle​

DuoKey implements the OASIS KMIP 2.1 key state machine. A key moves through these states:

StateMeaning
PreActiveThe key exists but cannot yet be used for cryptographic operations.
ActiveThe key is operational — the only state in which Encrypt/Decrypt is allowed.
DeactivatedThe key is retired from active use but retained (for example, to decrypt old data).
CompromisedThe key is flagged as potentially exposed and must not be trusted.
DestroyedThe key material has been permanently removed.
DestroyedCompromisedA compromised key that has since been destroyed.

Only the transitions defined by the KMIP state machine are allowed:

FromToTriggered by
PreActiveActiveActivate
PreActiveDestroyed / CompromisedDestroy / Revoke
ActiveCompromisedRevoke
ActiveDestroyedDestroy
DeactivatedDestroyed / CompromisedDestroy / Revoke
Active is required for crypto

Encrypt and Decrypt succeed only while a key is Active. A newly created key is PreActive until it is activated.

Revoke always compromises

On this endpoint, Revoke moves an Active key straight to Compromised — it does not branch by revocation reason into a softer Deactivated outcome. Treat Revoke as an incident-response action for a key that may have been exposed.

Supported operations​

The endpoint dispatches the following KMIP operations:

CategoryOperations
LifecycleCreate, Register, Activate, Revoke, ReKey, Destroy
RetrievalGet, GetAttributes, GetAttributeList, Locate, Check
CryptographicEncrypt, Decrypt
DiscoveryQuery, DiscoverVersions

Create and Register​

  • Create generates new symmetric key material — AES (128 / 192 / 256-bit, default 256) or HMAC (256-bit or larger). The key material is encrypted at rest under the platform key.
  • Register imports client-supplied symmetric key material (for example, a master key for database transparent data encryption).
Symmetric only

The server generates symmetric keys. Public keys, private keys, and certificates can be registered and managed as objects, but the server does not mint RSA or EC key pairs — CreateKeyPair is not supported.

Activate​

Activate moves a key from PreActive to Active, making it usable for cryptographic operations. Endpoints can be configured to auto-activate newly created keys.

Revoke (compromise)​

Revoke marks an Active key Compromised — flagged as exposed and no longer trusted for new cryptographic operations. The key material is retained (for example, to decrypt data already protected by it) until it is explicitly Destroyed.

Re-key (rotation)​

ReKey rolls a key: the server generates fresh material under a new identifier and links it to the previous key, so clients can rotate without losing the ability to decrypt data protected by the old key.

Retrieve and locate​

  • Get returns a key object (including its material for an active symmetric key, subject to policy).
  • GetAttributes / GetAttributeList read the attributes of an object.
  • Locate finds objects matching attribute filters.
  • Check verifies usage constraints on an object.

Encrypt and Decrypt​

The server performs Encrypt / Decrypt with AES-256-GCM, returning a self-contained nonce ‖ ciphertext ‖ tag blob. These operations require the key to be Active.

Destroy​

Destroy permanently removes the key material. This is irreversible — the stored material is deleted.

Observing operations in the Cockpit​

Open a hosted endpoint from the KMIP menu to inspect it:

1

Overview

Endpoint status, address, and request/error statistics.

2

Objects

The managed objects on the endpoint, each with its current lifecycle state.

3

Operations

A record of the KMIP operations the endpoint has processed.

Not supported​

The following KMIP operations are not implemented and return an OperationNotSupported result:

Unsupported operations

CreateKeyPair, DeriveKey, Certify, Sign / SignatureVerify, MAC / MACVerify, and the attribute-mutation operations (AddAttribute, ModifyAttribute, DeleteAttribute). There is no archive/recover state, no key-export/import bundle format, and no built-in rotation-policy scheduler — rotation is performed per key with ReKey. An endpoint's policy can further restrict which of the supported operations are allowed.