Create an identity and role on the KMES Series 3 for vCenter Server
This section shows you how to create on the a user with the permissions that vCenter requires to generate keys that you can use for various encryption tasks within vSphere.
Perform the following steps to create a new PKI Identity Provider (IdP), assign a TLS authentication mechanism, and add it to an identity as a credential. This enables vSphere to authenticate with the by using its TLS certificate.
Go to Identity Management > Identity Providers.
Right-click anywhere in the window and select Add > Provider > PKI.
On the Info tab of the Identity Provider Editor window, specify a name for the IdP and uncheck Enforce Dual Factor.
On the PKI Options tab, select [ Select ]. In the Certificate Selector window, expand the certificate tree you created for this integration for TLS and select the CA certificate that signed the vSphere and KMIP connection pair certificates. Then, select [ OK ].
Select [ OK ] to finish creating the PKI IdP.
Right-click the IdP you just created and select Add > Mechanism > TLS.
On the Info tab, specify a name for the authentication mechanism.
On the PKI tab, leave all fields set to the default values.
Select [ OK ] to save.
Go to Identity Management > Roles and select [ Add ] at the bottom of the page.
In the Info tab of the Role Editor window, set the Type to Application, the Name to vCenter, and Logins Required to 1.
On the Permissions tab, enable all of the Keys permissions for the role.
On the Advanced tab, set Allowed Ports to KMIP only.
Select [ OK ] to finish creating the role.
Go to Identity Management > Identities, right-click anywhere in the window, and select Add > Client Application.
On the Info tab of the Identity Editor window, select Application for the storage location and specify a name for the identity.
Under Assigned Roles, select the role you created for vCenter.
Under Authentication, remove the default API Key mechanism and select [ Add ]. In the Configure Credential window, select TLS Certificate in the Type drop-down menu, and select the Provider and Mechanism you created for this integration. Select [ OK ] to finish configuring the credential.
Select [ OK ] to finish creating the identity.