Focus sentinelFocus sentinel
Error
Focus sentinelFocus sentinel
Something went wrong
Focus sentinelFocus sentinel
Focus sentinelFocus sentinel
Update notification
KMIP for VMware
Specify a unique identifier for this service instance.
Overview
The KMIP for VMware service provides a 24x7 highly available service to manage encryption keys that are used by VMware in the IBM Cloud. The service not only offers runtime capability to allow customers to create, retrieve, activate, revoke, and destroy the encryption keys, but also provides management capability to maintain the association between the client credentials and those encryption keys.
KMIP for VMware serves as a standard Key Management Service (KMS) that accepts client encryption key operations required by VMware vSphere encryption and VMware vSAN encryption using the Key Management Interoperability Protocol (KMIP). Supported client applications are VMware vCenter Server 6.7, vCenter Server 7.0, VMware vSphere 6.7, and vSphere 7.0.
KMIP for VMware acts as an adapter to Key Protect and Hyper Protect Crypto Services. These services are IBM RESTful key management services that provide full-fledged encryption key management capability, including: customer root key management, data encryption key management, and customer root key-based data encryption key wrapping and unwrapping.
The management interface of KMIP for VMware allows you to configure the relationship between two components:
- Your VMware client certificate, which is used to authenticate with and access the KMIP for VMware service, and
- Your Key Protect or Hyper Protect Crypto Services instance, which is used for key management. KMIP for VMware uses a customer root key in your key management instance to protect VMware encryption keys, which allows for a unified IBM Cloud key management experience.
KMIP for VMware relies on Key Protect or Hyper Protect Crypto Services for highly available root key storage and key management services. It provides its own highly available interface using multiple network service endpoints and replicated databases in each region where the service is offered. When connected to Hyper Protect Crypto Services, the KMIP adapter runtime operates directly within the Hyper Protect service and is subject to the same protections as Hyper Protect Crypto Services noted below.
Key Protect provides a multi–tenant key management service grounded in FIPS 140–2 level 3 hardware security modules (HSMs).
Hyper Protect Crypto Services provides a dedicated single–tenant key management service grounded in FIPS 140–2 level 4 HSMs and IBM Secure Service Containers running on IBM LinuxONE servers. This option provides the highest level of security in the industry for highly sensitive and regulated data, as the data is not accessible even to IBM administrators.
Summary
KMIP for VMware
FreeFocus sentinelFocus sentinel