---
name: hs-crypto-kmip-vmware
title: Configuring KMIP for key management and distribution in Hyper Protect Crypto Services Standard Plan
description: Key Management Interoperability Protocol (KMIP) is a communication protocol for the storage and maintenance of key, certificate, and secret objects. The standard is governed by the Organization for the Advancement of Structured Information Standards (OASIS). Hyper Protect Crypto Services provides a dedicated single-tenant KMIP adapter so that VMware vCenter server instances can use Hyper Protect Crypto Services as the Key Management Service (KMS) for VMware vSphere encryption and vSAN encryption.
last-updated: 2026-07-01
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/hs-crypto?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Configuring KMIP for key management and distribution in Hyper Protect Crypto Services Standard Plan
{: #tutorial-kmip-vmware}
{: toc-content-type="tutorial"}
{: toc-services="hs-crypto"}
{: toc-completion-time="2h"}

IBM Cloud&reg; Hyper Protect Crypto Services is deprecated. As of 28 March 2026, you can't create new instances, and access to free instances will be removed. Existing premium plan instances are supported until 28 March 2027. Any instances that still exist on that date will be deleted.
{: deprecated}

Key Management Interoperability Protocol (KMIP) is a communication protocol for the storage and maintenance of key, certificate, and secret objects. The standard is governed by the Organization for the Advancement of Structured Information Standards (OASIS). Hyper Protect Crypto Services provides a dedicated single-tenant KMIP adapter so that VMware vCenter server instances can use Hyper Protect Crypto Services as the Key Management Service (KMS) for VMware vSphere encryption and vSAN encryption.
{: shortdesc}

This tutorial is based on the Standard Plan instance setup only.
{: note}

The following diagram illustrates the overall workflow of how the KMIP adapter that is provided in the Hyper Protect Crypto Services instance works with a VMWare customer environment.

![KMIP workflow with VMWare customer environment](../images/kmip-vmware-workflow.svg "KMIP adapter"){: caption="KMIP workflow with VMWare customer environment" caption-side="bottom"}

The overall workflow includes the following steps:

1. Create a Hyper Protect Crypto Services Standard Plan instance and your root key.
2. Configure the VMWare Solution Service **KMIP for VMWare** with the Hyper Protect Crypto Services service instance. The **KMIP for VMware** service manages the lifecycle of the KMIP adapter and KMIP client certificates.
3. Connect your VMware vCenter server to KMIP and enable vSphere encryption or vSAN encryption.


## Objectives
{: #tutorial-kmip-objectives}

This tutorial shows how you can configure KMIP with VMWare solution in IBM Cloud.


## Before you begin
{: #tutorial-kmip-prerequisites}

To complete this tutorial, you need to meet the following prerequisites:

- [Sign up an IBM Cloud account](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-signing_required_accounts&format=markdown#signing_required_accounts-cloud).
- [Provision a Standard Plan instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-provision&interface=ui&format=markdown#provision-standard).
- [Initialize your Hyper Protect Crypto Services instance](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm&format=markdown#initialize-hsm).
- [Create your Hyper Protect Crypto Services root key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-get-started&format=markdown#create-key-standard).
- [Order a KMIP for VMware® instance](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-kmip_standalone_ordering&format=markdown).

## Task flow
{: #tutorial-kmip-steps}

To complete this solution, we'll walk through the following steps:

1. [Grant the service-to-service authorization in IAM](#tutorial-kmip-s2s).
2. [Configure KMIP for VMWare with Hyper Protect Crypto Services instance](#tutorial-vmware-configure).
3. [Configure a trusted connection between the vCenter Server and KMIP adapter](#tutorial-kmip-verify).

Let's start with the service authorization process.

## Grant the service-to-service authorization in IAM
{: #tutorial-kmip-s2s}
{: step}

1. Click **Manage>Access(IAM)** on the menu after you log in to IBM Cloud.

2. Select **Authorizations** on the left navigation pane.

3. Click the **Create** button.

4. On the **Grant a service authorization** page, fill in the following information:

   * Under the **Source service** drop-down list, select **VMWare Solutions**, and then select the KMIP for VMWare service instance ID.
   * Under the **Target service** drop-down list, select **Hyper Protect Crypto Services services**, and then select the Hyper Protect Crypto Services instance ID.
   * In the **Platform access** pane, select the **Viewer** option.
   * In the **Service Access** pane, select the **VMWare KMIP Manager** option.

6. Click the **Authorize** button to complete the service to service authorization.

## Configure KMIP for VMWare with Hyper Protect Crypto Services instance
{: #tutorial-vmware-configure}
{: step}

1. In the **IBM Cloud for VMware Solutions** UI, click **Resources** from the left navigation pane.

2. Scroll down to the **KMIP for VMware Instances** table, click the instance that you want to configure your Hyper Protect Crypto Services instance with. The status of the KMIP for VMware instance is *Inactive* because it is not configured yet.

3. Select **Getting started** from the left navigation pane on the next page.

4. Select the **Initialize service instance** option and **Hyper Protect** as the key management type.

    - Select the Hyper Protect Crypto Services instance ID that stores your root key and key encryption key. You can click the **Retrieve** button to get a list of Hyper Protect Crypto Services instances under your IBM Cloud account.
    
        Only IDs of Hyper Protect Crypto Services instances that contain at least one root key are to be listed. Make sure to [create a root key](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-get-started&format=markdown#create-key-standard) first, but not to associate the root key with any created key rings so that it is automatically associated with the default key ring. 
        {: note}

    - Select the root key to wrap the key encryption key for your data encryption key. You can click the **Retrieve** button to get a list of root keys stored on the selected Hyper Protect Crypto Services instance.

        Make sure not to delete the root key that you select for key wrapping. Otherwise, the data encryption keys stored for VMWare solutions by the KMIP adapter cannot be accessed.
        {: note}

5. Click **Configure** to complete the configuration. Optionally, you can add client certificates if you have an existing VMWare or vCenter environment that you like to reuse.

6. Click **Refresh** and ensure that the status of the KMIP for VMware instance is *Installed*.

7. Identify the KMIP server endpoints information for the next step. For example, `<instance_ID>.kmip.private.us-south.hs-crypto.appdomain.cloud`.


## Configure a trusted connection between the vCenter Server and KMIP adapter
{: #tutorial-kmip-verify}
{: step}

1. In your vSphere client UI, complete the following steps:

    a. Add the KMS to your vCenter Server by using the KMIP server address and port information from the previous step during the configuration.

    b. Configure the appropriate trust method between the KMS instance and your vCenter Server, and download the generated certificate.

2. On the **KMIP for VMware instance** page, add the certificate from the vCenter Server.

3. Verify the connection status of the KMS for your vCenter server is **Connected**.

4. Optional: Create an encrypted virtual machine to check that the encryption key from the KMS is used.

In this tutorial, you learned how to configure VMWare with KMIP in Hyper Protect Crypto Services.

- Learn more about [KMIP](http://www.oasis-open.org/committees/tc_home.php?wg_abbrev=kmip){: external}.
- Learn more about [KMIP for VMWare service](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-kmip_standalone_considerations&format=markdown)
- Learn more about [Using Encryption in Your vSphere Environment](https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-A29066CD-8EF8-4A4E-9FC9-8628E05FC859.html?hWord=N4IghgNiBcIKoGcCWA7A5gAgKIoMYCcBPABwBckB7FDVDATQoFd8MA3AZWIAsBTfH7ClZJ8VALY8UpEAF8gA){: external}.


## What's next
{: #tutorial-kmip-next}

The following demo video is for you to better understand the process.

![Configuring KMIP in Hyper Protect Crypto Services for key management and distribution](https://www.kaltura.com/p/1773841/sp/177384100/embedIframeJs/uiconf_id/27941801/partner_id/1773841?iframeembed=true&entry_id=1_e5gk6ktn){: video output="iframe" data-script="none" id="mediacenterplayer" frameborder="0" width="560" height="315" allowfullscreen webkitallowfullscreen mozAllowFullScreen}