Virtualization
VMware vSphere
Create an identity and role on the KMES Series 3 for vCenter Server
4min
this section shows you how to create on the {{k}} a user with the permissions that vcenter requires to generate keys that you can use for various encryption tasks within vsphere the name of the user you create needs to match exactly the common name of the vcenter tls certificate this enables vcenter to authenticate with the {{k}} through the certificate add a pki identity provider configured with the tls authentication mechanism perform the following steps to create a new pki identity provider (idp), assign a tls authentication mechanism, and add it to an identity as a credential this enables vsphere to authenticate with the {{k}} by using its tls certificate go to identity management > identity providers right click anywhere in the window and select add > provider > pki on the info tab of the identity provider editor window, specify a name for the idp and uncheck enforce dual factor on the pki options tab, select \[ select ] in the certificate selector window, expand the certificate tree you created for this integration for tls and select the ca certificate that signed the vsphere and kmip connection pair certificates then, select \[ ok ] select \[ ok ] to finish creating the pki idp right click the idp you just created and select add > mechanism > tls on the info tab, specify a name for the authentication mechanism on the pki tab, leave all fields set to the default values select \[ ok ] to save create a role log in to the {{k3}} application interface with the default admin identities go to identity management > roles and select \[ add ] at the bottom of the page in the info tab of the role editor window, set the type to application , the name to vcenter , and logins required to 1 on the permissions tab, enable all of the keys permissions for the role on the advanced tab, set allowed ports to kmip only select \[ ok ] to finish creating the role create an identity go to identity management > identities , right click anywhere in the window, and select add > client application on the info tab of the identity editor window, select application for the storage location and specify a name for the identity under assigned roles , select the role you created for vcenter under authentication , remove the default api key mechanism and select \[ add ] in the configure credential window, select tls certificate in the type drop down menu, and select the provider and mechanism you created for this integration select \[ ok ] to finish configuring the credential select \[ ok ] to finish creating the identity