Skip to main content
Configure the application’s KMIP client with the files from the endpoint download, then verify that CryptoHub accepts the client certificate and answers a KMIP request. Field names and import steps differ by application, so use this page with the application vendor’s KMIP or external key manager documentation.

Map the endpoint files to KMIP settings

Most KMIP applications ask for the same settings. Use these values from the endpoint download:

Prepare the TLS files

Run these commands on a protected administrator host with OpenSSL 3. Replace <endpoint-zip> with the path of the downloaded ZIP.
1

Extract the endpoint download

Create a private working directory and extract the ZIP into it.
The directory contains pki.p12, pki-password.txt, client-cert.pem, and ca-chain.pem.
2

Extract the client private key

Write the unencrypted client private key to client-key.pem. The command reads the PKCS #12 password from pki-password.txt, so the password does not appear in your shell history, and openssl pkey removes the PKCS #12 bag attributes from the output.
OpenSSL 3 opens pki.p12 without the -legacy option.
client-key.pem begins with a -----BEGIN PRIVATE KEY----- line.
3

Confirm that the key matches the certificate

Compare the public-key hash of the certificate with the public-key hash of the private key.
The two hashes are identical, and the certificate expiry date is in the future.
4

Convert to the format the application accepts

Use the files in the format that the application requires:
  • Separate PEM files: use client-cert.pem, client-key.pem, and ca-chain.pem.
  • Combined PEM file: run cat client-cert.pem client-key.pem > client-cert-and-key.pem.
  • PKCS #12 file: import pki.p12 directly and enter the password from pki-password.txt.
You have the client certificate, client private key, and server CA in the format that the application’s KMIP settings accept.
5

Transfer and protect the files

Copy only the files that the application needs to the application host over a protected channel. Make the private key readable only by the account that runs the application’s KMIP client, then delete the working directory from the administrator host.
The private key file on the application host is not readable by other accounts.

Configure the application

1

Open the KMIP settings

Open the application’s KMIP, external key manager, or key management server settings. Use the vendor’s documentation for the exact location.
2

Enter the server settings

Enter the CryptoHub KMIP host from info.txt and port 5696. Add the contents of ca-chain.pem as the trusted server CA.
3

Enter the client credential

Import the client certificate and private key in the format that the application accepts. Leave any KMIP username and password fields empty.
4

Save and test

Save the settings and run the application’s connection or key-server test, if it has one.
The application reports a successful connection to the key server.

Verify the connection

Run two checks before you rely on the integration: TLS 1.2 client authentication, then one authenticated KMIP operation. Run them from the application host or from a host with the same network path to CryptoHub.
1

Check TLS 1.2 client authentication

Open a TLS 1.2 connection to the KMIP port with the endpoint client certificate.
The command forces TLS 1.2 because a TLS 1.3 server can reject a client certificate after the handshake appears complete. With TLS 1.2, a rejected client certificate fails the handshake with an alert.
The output shows Verify return code: 0 (ok) and no alert line. The Acceptable client certificate CA names list includes CN=Client App TLS CA <number>, the CA whose certificate is in the endpoint download.
2

Run one authenticated KMIP operation

Run the application’s own key-server test, or use the PyKMIP client as a neutral KMIP client. To use PyKMIP, install it in a Python virtual environment:
Create pykmip.conf with the endpoint files:
Omit the username and password options. Without them, PyKMIP sends no KMIP credential and authenticates with the client certificate alone.Send a KMIP Locate request:
PyKMIP verifies the server certificate chain against ca-chain.pem. It does not compare the server certificate with the host name. With ssl_version=PROTOCOL_TLS, PyKMIP negotiates TLS 1.3 with CryptoHub.
The script prints a list of object identifiers. A new service can return an empty list, []. An error or a closed connection means the operation failed.
3

Check key retrieval (applications that retrieve keys)

If the application retrieves key material, confirm that it can create and retrieve a key. This PyKMIP example creates a test AES-256 key and retrieves it.
The example ends with a KMIP Destroy request for the test key only. Do not reuse its identifier for application keys.
Skip this step if the application uses only server-side operations. KMIP object names must be unique: if an earlier run stopped before the Destroy request, change the name value before you run the example again.
The script prints an object identifier and 256, and completes without an error.
4

Find the key in CryptoHub

In the CryptoHub web interface, open Key Management and select Keys. Select the key by name and open its History tab to see which endpoint identity created or retrieved it.KMIP secret data objects appear under Classic Tools > Key Management > GO TO SECRETS.
The key’s History tab lists the endpoint identity name under Username(s).

Troubleshooting