1
Open endpoint management
Open Services, select the Deployed Services tab, and select the Generic KMIP service that you deployed. Select ENDPOINTS.
CryptoHub displays the Manage Endpoints page for the service.
2
Add the endpoint
Select ADD NEW. In the Add Endpoint dialog, complete these fields:
- Endpoint Identifier: a name that identifies the application host, at least 4 characters. If you leave it empty, CryptoHub generates one.
- CryptoHub Hostname: the CryptoHub FQDN that the application uses to reach CryptoHub. CryptoHub fills in the address that your browser used, and writes this value to
info.txtas the KMIP address. - Client Connection Type: ECC for an ECC client certificate, or RSA for an RSA client certificate. Select the type that the application requires.
The dialog shows your values in all three fields.
3
Download the endpoint
Select ADD ENDPOINT and save the downloaded ZIP in a protected administrator directory.
CryptoHub displays Endpoint created, and the browser downloads a ZIP named after the endpoint identifier.
4
Record the KMIP address
Open
info.txt and record the service name and the address. Use this address in the application’s KMIP settings.info.txt names the service that you deployed, and its address ends with :5696.Endpoint ZIP contents
The ZIP does not contain the KMIP server certificate. The application receives it during the TLS handshake. Configure
ca-chain.pem as the application’s server CA.
Each endpoint has its own identity and client certificate. Create a separate endpoint for each application host or cluster member that needs its own credential.

