Skip to main content
Create a client endpoint to authorize the KMIP application to use the Generic KMIP service, and protect the downloaded bundle as a credential.
The endpoint ZIP contains the client private key and the password for its PKCS #12 file. Store it in a protected location, and do not send it through email or copy it into an image.
1

Open endpoint management

Open Services, select the Deployed Services tab, and select the Generic KMIP service that you deployed. Select ENDPOINTS.
CryptoHub displays the Manage Endpoints page for the service.
2

Add the endpoint

Select ADD NEW. In the Add Endpoint dialog, complete these fields:
  • Endpoint Identifier: a name that identifies the application host, at least 4 characters. If you leave it empty, CryptoHub generates one.
  • CryptoHub Hostname: the CryptoHub FQDN that the application uses to reach CryptoHub. CryptoHub fills in the address that your browser used, and writes this value to info.txt as the KMIP address.
  • Client Connection Type: ECC for an ECC client certificate, or RSA for an RSA client certificate. Select the type that the application requires.
The dialog shows your values in all three fields.
3

Download the endpoint

Select ADD ENDPOINT and save the downloaded ZIP in a protected administrator directory.
CryptoHub displays Endpoint created, and the browser downloads a ZIP named after the endpoint identifier.
4

Record the KMIP address

Open info.txt and record the service name and the address. Use this address in the application’s KMIP settings.
info.txt names the service that you deployed, and its address ends with :5696.

Endpoint ZIP contents

The ZIP does not contain the KMIP server certificate. The application receives it during the TLS handshake. Configure ca-chain.pem as the application’s server CA.
Each endpoint has its own identity and client certificate. Create a separate endpoint for each application host or cluster member that needs its own credential.