Key Management Operations
How keys move through their lifecycle on a DuoKey KMIP endpoint, and the KMIP operations the server supports.
KMIP operations are issued by KMIP clients over the wire (databases, storage, virtualization) — or from the built-in Client Simulator in the Cockpit's KMIP menu. You do not run key operations from a command line. In the Cockpit, open a hosted endpoint to see its Objects, Operations, and statistics.
Key lifecycle
DuoKey implements the OASIS KMIP 2.1 key state machine. A key moves through these states:
| State | Meaning |
|---|---|
PreActive | The key exists but cannot yet be used for cryptographic operations. |
Active | The key is operational — the only state in which Encrypt/Decrypt is allowed. |
Deactivated | The key is retired from active use but retained (for example, to decrypt old data). |
Compromised | The key is flagged as potentially exposed and must not be trusted. |
Destroyed | The key material has been permanently removed. |
DestroyedCompromised | A compromised key that has since been destroyed. |
Only the transitions defined by the KMIP state machine are allowed:
| From | To | Triggered by |
|---|---|---|
PreActive | Active | Activate |
PreActive | Destroyed / Compromised | Destroy / Revoke |
Active | Compromised | Revoke |
Active | Destroyed | Destroy |
Deactivated | Destroyed / Compromised | Destroy / Revoke |
Encrypt and Decrypt succeed only while a key is Active. A newly created key is PreActive until it is activated.
On this endpoint, Revoke moves an Active key straight to Compromised — it does not branch by revocation reason into a softer Deactivated outcome. Treat Revoke as an incident-response action for a key that may have been exposed.
Supported operations
The endpoint dispatches the following KMIP operations:
| Category | Operations |
|---|---|
| Lifecycle | Create, Register, Activate, Revoke, ReKey, Destroy |
| Retrieval | Get, GetAttributes, GetAttributeList, Locate, Check |
| Cryptographic | Encrypt, Decrypt |
| Discovery | Query, DiscoverVersions |
Create and Register
Creategenerates new symmetric key material — AES (128 / 192 / 256-bit, default 256) or HMAC (256-bit or larger). The key material is encrypted at rest under the platform key.Registerimports client-supplied symmetric key material (for example, a master key for database transparent data encryption).
The server generates symmetric keys. Public keys, private keys, and certificates can be registered and managed as objects, but the server does not mint RSA or EC key pairs — CreateKeyPair is not supported.
Activate
Activate moves a key from PreActive to Active, making it usable for cryptographic operations. Endpoints can be configured to auto-activate newly created keys.
Revoke (compromise)
Revoke marks an Active key Compromised — flagged as exposed and no longer trusted for new cryptographic operations. The key material is retained (for example, to decrypt data already protected by it) until it is explicitly Destroyed.
Re-key (rotation)
ReKey rolls a key: the server generates fresh material under a new identifier and links it to the previous key, so clients can rotate without losing the ability to decrypt data protected by the old key.
Retrieve and locate
Getreturns a key object (including its material for an active symmetric key, subject to policy).GetAttributes/GetAttributeListread the attributes of an object.Locatefinds objects matching attribute filters.Checkverifies usage constraints on an object.
Encrypt and Decrypt
The server performs Encrypt / Decrypt with AES-256-GCM, returning a self-contained nonce ‖ ciphertext ‖ tag blob. These operations require the key to be Active.
Destroy
Destroy permanently removes the key material. This is irreversible — the stored material is deleted.
Observing operations in the Cockpit
Open a hosted endpoint from the KMIP menu to inspect it:
Overview
Endpoint status, address, and request/error statistics.
Objects
The managed objects on the endpoint, each with its current lifecycle state.
Operations
A record of the KMIP operations the endpoint has processed.
Not supported
The following KMIP operations are not implemented and return an OperationNotSupported result:
CreateKeyPair, DeriveKey, Certify, Sign / SignatureVerify, MAC / MACVerify, and the attribute-mutation operations (AddAttribute, ModifyAttribute, DeleteAttribute). There is no archive/recover state, no key-export/import bundle format, and no built-in rotation-policy scheduler — rotation is performed per key with ReKey. An endpoint's policy can further restrict which of the supported operations are allowed.