Skip to main content
Applies to:
DuoKey Cockpit v2KMIP server endpoint

What is KMIP?​

The Key Management Interoperability Protocol (KMIP) is an OASIS standard that defines how cryptographically-enabled applications — databases, storage systems, backup appliances — talk to a central key manager. It standardizes the full key lifecycle (create, retrieve, activate, revoke, destroy) so a single key manager can serve many different products without custom integrations.

How DuoKey implements KMIP​

DuoKey Cockpit v2 runs a KMIP server endpoint. Compliant clients connect to it over TLS and issue KMIP operations; DuoKey generates the key material, protects it, and returns it (or performs encrypt/decrypt) according to the endpoint policy.

KMIP clientsdatabases · backupstorage · appsTTLV / TLSport 5696DuoKey KMIP serverOASIS KMIP 2.x — no SDKKeysvault / HSM custody
Standard KMIP clients consume keys directly over the wire — no DuoKey SDK — while the key material stays in the vault or HSM.
One generation

The KMIP server is a Cockpit v2 (Rust/React) capability, provisioned as a PKI service endpoint. It is unrelated to the Cockpit v1 (.NET/Angular) configuration model.

Protocol support​

CapabilityDetails
KMIP versionsNegotiates 2.1, 2.0, 1.4, 1.3, 1.2, 1.1, 1.0. Default advertised profile is KMIP 2.1.
TransportsBinary TTLV over TLS, and a JSON-over-HTTPS profile.
Default TLS port5696 (the IANA-assigned KMIP port).
EncodingCanonical KMIP 2.x attributes; 1.x TemplateAttribute requests are normalized in and adapted back out for pre-2.0 clients.

Supported operations​

The endpoint dispatches the following KMIP operations:

OperationPurpose
CreateGenerate a new managed key.
RegisterImport client-supplied key material.
GetRetrieve a key object.
GetAttributesRead attributes of an object.
GetAttributeListList the attribute names on an object.
LocateFind objects matching attribute filters.
ActivateMove a key to the active state.
RevokeRevoke a key (marks it Compromised).
DestroyPermanently remove key material.
NaNServer-side cryptographic operations.
ReKeyRoll a key to fresh material under a new identifier.
CheckVerify usage constraints on an object.
QueryDiscover server capabilities.
DiscoverVersionsNegotiate the KMIP protocol version.
Not implemented

Asymmetric-generation and signing operations — CreateKeyPair, DeriveKey, Certify, Sign, MAC, and the attribute-mutation operations — are not supported and return an OperationNotSupported result. The endpoint policy can further restrict the allowed operations per deployment.

Objects and algorithms​

ItemSupport
Managed object typesSymmetric keys, public keys, private keys, certificates, and secret data.
Key generationSymmetric material only: AES (128 / 192 / 256-bit, default 256) and HMAC (256-bit or larger).
Server-side cryptoAES-256-GCM for Encrypt / Decrypt, returning a self-contained nonce ‖ ciphertext ‖ tag blob.
Symmetric key generation

DuoKey generates and stores symmetric key material (AES, HMAC). Asymmetric object types and certificates can be registered and managed as objects, but the server does not mint RSA or EC key pairs itself.

How keys are protected​

Generated key material is encrypted at rest with AES-256-GCM under the platform encryption key — the same envelope used for vault credentials and identity-provider secrets — and stored in the DuoKey database. Keys survive restarts and never live only in process memory. Destroy hard-deletes the stored material.

Positioning

For KMIP, keys are protected by envelope encryption under the platform key, not by MPC. MPC-based key protection applies to other DuoKey key-management flows, not to the KMIP server backend described here.

Client authentication​

Client authentication is optional mutual TLS (mTLS): a presented client certificate's CommonName becomes the audited client identity. The per-endpoint policy (allowed_auth_methods, require_client_cert) decides which methods are accepted:

MethodHow it works
mTLSClient presents an X.509 certificate; its CommonName is the identity.
Credential in messageA KMIP Username/Password credential carried in the request header.
AnonymousAllowed only when the endpoint policy explicitly permits it.

To trust mTLS identities, point the listener at a PEM bundle of trusted client CAs:

Enforce validated mTLSBASH
# PEM bundle of trusted client-CA certificates
KMIP_CLIENT_CA_BUNDLE=/etc/duokey/kmip/client-ca-bundle.pem
Production requires a CA bundle

When no client-CA bundle is configured, presented client certificates are accepted without CA validation and their identity must not be trusted for authorization. In production the listener fails closed and refuses to start until a bundle is set.

Client compatibility​

Any OASIS KMIP 1.x or 2.x client can connect over the binary TLS transport on port 5696. Interoperability is exercised end-to-end with the PyKMIP reference client (Query → Create → Activate → Get → Encrypt/Decrypt → Locate → Revoke → Destroy).

Integration targets for KMIP-based encryption include:

Percona Server

MongoDB and MySQL data-at-rest encryption.

VMware vSphere

vSphere and vSAN standard key provider.

NetApp ONTAP

External key manager for storage encryption.

Provisioning​

A KMIP server endpoint is created from the DuoKey Cockpit's KMIP menu: open the Server tab and click Deploy KMIP endpoint. The wizard collects the endpoint name, the key vault, allowed authentication methods, transport (binary TLS or JSON/HTTPS) and TLS port, the default algorithm and key size, the allowed object types and operations, and audit settings — then deploys and starts the endpoint.