---
name: vmwaresolutions-kmip_standalone_considerations
title: KMIP for VMware overview
description: The Key Management Interoperability Protocol (KMIP™) for VMware® service provides a highly available service to manage encryption keys that are used by VMware in IBM Cloud&reg;. This service offers runtime capability to allow customers to create, retrieve, activate, revoke, and delete the encryption keys. It also provides management capability to maintain the associations between the client credentials and the encryption keys.
last-updated: 2026-04-14
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/vmwaresolutions?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# KMIP for VMware overview
{: #kmip_standalone_considerations}

As of 17 July 2025, new automated installations of Red Hat&reg; OpenShift&reg; for VMware® are no longer available for new or existing deployments of VMware Cloud Foundation for Classic - Automated instances. You can still use or delete your existing Red Hat OpenShift for VMware automated installations until 16 July 2026. The service will no longer be available from 17 July 2026.
{: deprecated}

**End of Marketing**: As of 17 July 2025, new deployments of VMware Regulated Workloads instances are no longer available for new customers. If you are an existing customer, you can still add or delete clusters, add or delete VMware ESXi™ servers or NFS storage, and add or remove services for your existing Regulated Workloads instances. As an existing customer, you can also view or delete your Regulated Workloads instances.
{: note}

The Key Management Interoperability Protocol (KMIP™) for VMware® service provides a highly available service to manage encryption keys that are used by VMware in IBM Cloud&reg;. This service offers runtime capability to allow customers to create, retrieve, activate, revoke, and delete the encryption keys. It also provides management capability to maintain the associations between the client credentials and the encryption keys.
{: shortdesc}

The KMIP for VMware service is available as a stand-alone service without being associated to a VMware instance. Each instance of the service can serve one or more VMware Cloud Foundation for Classic - Automated or VMware Cloud Foundation for Classic - Flexible instances.

The following client applications are supported:
* VMware vCenter Server® 7 and 8
* VMware vSphere® 7

## Technical specifications for KMIP for VMware
{: #technical-specifications-for-kmip-for-vmware-on-ibm-cloud}

For more information about resource requirements and planning for KMIP for VMware, see [Planning for KMIP for VMware](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-kmip-implementation&format=markdown#kmip-implementation-planning).

The following specifications are included with the KMIP for VMware service:

* A VMware-compatible KMIP
* Two managed services - [Key Protect](https://cloud.ibm.com/catalog/services/key-protect) and [Hyper Protect Crypto Services](https://cloud.ibm.com/catalog/services/hyper-protect-crypto-services)
* Available in multiple geographic regions worldwide
* Highly available KMIP network service endpoints provided in each region

## Before you order KMIP for VMware
{: #kmip_standalone_considerations-install}

KMIP for VMware uses either the IBM Key Protect service or the IBM Hyper Protect Crypto Services (HPCS) service to create, encrypt, and decrypt encryption keys.

Before you install KMIP for VMware, complete the following tasks and review the following information:

1. Order a usable Key Protect or HPCS service instance in the IBM Cloud region where your KMIP for VMware instance is to be hosted. If you are using HPCS, in addition to provisioning the HPCS service, you must also initialize your crypto instance so that HPCS can provide key-related functions.

   For more information, see the following topics:
   * [Provisioning the Key Protect service](https://cloud.ibm.com/docs/key-protect?topic=key-protect-provision&format=markdown)
   * [Provisioning HPCS service instances](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-provision&format=markdown#provision)
   * [Initializing HPCS service instances using key part files](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-initialize-hsm&format=markdown#initialize-hsm)

2. If you are using Key Protect, complete the following tasks:
   1. Create an IBM Cloud service ID by following the steps in [Creating a service ID by using the console](https://cloud.ibm.com/docs/iam?topic=iam-serviceids&interface=ui&format=markdown#create_serviceid). This service ID is used to access the Key Protect instance that you created.
   2. Grant the following access levels for the service ID:
      * At the platform access level: Viewer authority to your Key Protect or HPCS service instance.
      * At the service access level: Manager authority to your Key Protect or HPCS service instance.
   3. You must have an API key for the created service ID. The API key is required when you order the service.

3. Import or create at least one customer root key (CRK) by using the GUI or API of Key Protect or HPCS.

   If you are using HPCS, the CRK must be created within the default key ring for the HPCS instance.
   {: important}

   For more information about Key Protect, see the following topics:
   * [Importing root keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-import-root-keys&format=markdown)
   * [Creating root keys](https://cloud.ibm.com/docs/key-protect?topic=key-protect-create-root-keys&format=markdown)
   * [Creating import tokens](https://cloud.ibm.com/docs/key-protect?topic=key-protect-create-import-tokens&format=markdown)
   * [IBM Key Protect API](https://cloud.ibm.com/apidocs/key-protect)

   For more information about HPCS, see the following topics:
   * [Importing root keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-import-root-keys&format=markdown)
   * [Creating root keys](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-root-keys&format=markdown)
   * [Creating import tokens](https://cloud.ibm.com/docs/hs-crypto?topic=hs-crypto-create-import-tokens&format=markdown)
   * [IBM Cloud Hyper Protect Crypto Services KMS API](https://cloud.ibm.com/apidocs/hs-crypto)

4. Ensure that your IBM Cloud infrastructure account is enabled for Virtual Routing and Forwarding (VRF) and for connectivity to service endpoints.

   For more information, see the following topics:
   * [Virtual Routing and Forwarding on IBM Cloud](https://cloud.ibm.com/docs/direct-link?topic=direct-link-overview-of-virtual-routing-and-forwarding-vrf-on-ibm-cloud&format=markdown)
   * [Enabling service endpoints](https://cloud.ibm.com/docs/account?topic=account-vrf-service-endpoint&format=markdown#service-endpoint)

Only private connection is supported. As a result, you don't need to configure firewall or SNAT rules in vCenter Server for the network connectivity from vCenter Server to the endpoint of the KMIP for VMware instance. For more information, see [KMIP for VMware solution architecture](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-kmip-overview&format=markdown).
{: note}

## Related links
{: #kmip_standalone_considerations-related}

* [Ordering KMIP for VMware instances](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-kmip_standalone_ordering&format=markdown)
* [Managing certificates for KMIP for VMware instances](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-kmip_standalone_addingdeletingcert&format=markdown)
* [Viewing KMIP for VMware instances](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-kmip_standalone_viewing&format=markdown)
* [Deleting KMIP for VMware instances](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-kmip_standalone_deleting&format=markdown)
* [Activity tracking events for VMware Solutions](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-at_events&format=markdown)
* [Getting help and support for VMware Solutions](https://cloud.ibm.com/docs/vmwaresolutions?topic=vmwaresolutions-trbl_support&format=markdown)