The vCenter Server and KMES Series 3 must establish a mutual trust relationship by validating their respective digitally signed certificates before KMIP connections can occur. The steps you performed in the preceding sections established the vCenter trust of the KMES. The steps in this section establish the recipoical trust the KMES has of vCenter. To do this, generate a Certificate Signing Request (CSR) in the vCenter Server system with the vSphere Client, sign the CSR using the Certificate Authority (CA) created on the KMES and import the signed certificate back into the vCenter Server system with the vSphere Client. After this, vCenter Server and the KMES Series 3 can establish a TCP/IP session secured by TLS, making it possible for KMIP connections, and therefore encryption operations, to occur.Documentation Index
Fetch the complete documentation index at: https://docs.futurex.com/llms.txt
Use this file to discover all available pages before exploring further.
Generate a CSR
Perform the following steps to generate a CSR with the vSphere Client:In the dialog box, select [ Download ] to download the CSR as a file.
You must copy the CSR file needs to the storage medium configured for the KMES.
Sign the vCenter CSR
Perform the following steps to sign the vCenter CSR by using a CA on the KMES:Right-click the System TLS Root CA certificate you configured in the Configure TLS certificates for the KMIP port on the KMES Series 3 section and select Add Certificate > From Request.
On the Subject DN tab, change the Common Name value to a shorter string, such as vCenter.
The Common Name of the certificate should match the name of the user created in the next section so that vCenter can authenticate to the KMES through TLS certificate authentication.
Export the certificate
Perform the following steps to export the signed vCenter certificate:In the file browser, go to the location where you want to save the certificate. Specify a name for the file and select [ Open ].
Import the signed vCenter certificate
Perform the following steps to import the signed vCenter certificate into vCenter Server with the vSphere Client:Select the KMES KMS, select the Establish Trust drop-down menu, and select Upload Signed CSR Certificate.
Select [ Upload A File ], and find and select the signed vCenter certificate in the file browser.
The content of the certificate should display.

