Key management
Managed Keys

Configure KMES Series 3

14min
this section starts with general configurations you must make on the kmes to enable hashicorp vault to integrate the kmes with the managed keys functionality then, it covers the necessary steps to configure tls communication between the kmes and the vault instance configure general kmes settings perform the following tasks to configure the kmes series 3 for communication with signtool create a vault role and identity with the correct assigned permissions enable host api commands the following sections show you how to complete these tasks create a role and identity for vault with the required permissions perform the following steps to create a new role and identity for vault on the kmes series 3 a later section shows you how to configure the name of this identity in the futurex pkcs #11 configuration file log in to the kmes series 3 application interface with the default admin identities go to identity management > roles and select \[ add ] in the role editor window, perform the following steps specify a name for the role set the number of logins required to 1 go to the advanced tab and allow authentication to the host api port only leave all other fields set to the default values go to the permissions tab and select the following permissions permission subpermission certificate authority add , export , upload cryptographic operations sign , verify , encrypt , decrypt keys add , export select \[ ok ] to finish creating the role go to identity management > identities , right click anywhere, and select add > client application under info in the identity editor window, select application for the storage location, and specify a name for the identity under assigned roles , select the role you created under authentication , configure the password leave all other fields set to the default values and select \[ ok ] to finish creating the identity enable host api commands for hashicorp vault operation because the futurex pkcs #11 library connects to the host api port on the kmes, you must define which host api commands to enable for the fxpkcs11 library to execute to set the enabled commands, complete the following steps log in to the kmes series 3 application interface with the default admin identities go to administration > configuration > host api options and enable the following commands command description and subcommand permissions atkg manipulate hsm trusted asymmetric key group add modify delete get attr generic attribute operations get put patch echo communication test/retrieve version rafa filter issuance policy rkcp get command permissions get modify rkgp export asymmetric hsm trusted key rkgs generate signature rkln lookup objects rklo login user rkpk pop generated key time get/set time configure tls communication between the kmes series 3 and the vault instance to configure tls communication, you need to perform the following tasks create a certificate authority generate a csr for the system/host api connection pair sign the system/host api csr export the root ca certificate export the signed system/host api certificate load the exported certificates into the system/host api connection pair issue a client certificate for vault export the vault certificate as a pkcs #12 file the following sections show you how to perform these tasks create a certificate authority log in to the kmes series 3 application interface with the default admin identities go to pki > certificate authorities and select \[ add ca ] at the bottom of the page in the certificate authority window, enter a name for the certificate container, leave all other fields set to the default values, and select \[ ok ] the certificate container you created now displays in the certificate authorities menu right click the certificate container and select add certificate > new certificate on the subject dn tab, set a common name for the certificate, such as system tls ca root on the basic info tab, leave all of the fields set to their default values on the v3 extensions tab, select the certificate authority profile, and select \[ ok ] the root ca certificate now displays under the previously created certificate container generate a csr for the system/host api connection pair go to administration > configuration > network options in the network options window, go to the tls/ssl settings tab under the system/host api connection pair, uncheck use futurex certificates , tand select \[ edit ] next to pki keys in the user certificates section in the application public keys window, select \[ generate ] when warned that ssl will not be functional until new certificates are imported, select \[ yes ] to continue in the pki parameters window, leave the fields set to their default values and select \[ ok] when notified that a pki key pair is loaded in the application public keys window, select \[ request ] on the subject dn tab, set a common name for the certificate, such as kmes on the v3 extension s tab, select the tls server certificate profile on the pkcs #10 info tab, select a save location for the csr, and select \[ ok ] when notified that the certificate signing request was successfully written to the file location that was selected, select \[ ok ] select \[ ok ] again to save the application public keys settings the main network options window now shows loaded next to pki keys for the system/host api connection pair sign the system/host api csr go to pki > certificate authorities right click the root ca certificate you created, and select add certificate > from request in the file browser, find and select the csr that you generated for the system/host api connection pair after it loads, you don't need to modify any settings for the certificate, so select \[ ok ] the signed system/host api certificate now showsunder the root ca certificate on the certificate authorities page export the root ca certificate go to pki > certificate authorities right click the system tls ca root certificate, and select export > certificate(s) in the export certificate window, change the encoding to pem , and select \[ browse ] in the file browser, go to the location where you want to save the root ca certificate specify tls ca pem as the name for the file, and select \[ open ] select \[ ok ] a message box displays that the pem file was successfully written to the location that you specified export the signed system/host api certificate go to pki > certificate authorities right click the kmes certificate, and select export > certificate(s) in the export certificate window, change the encoding to pem , and select \[ browse ] in the file browser, go to the location where you want to save the root ca certificate specify tls kmes pem as the name for the file, and select \[ open ] select \[ ok ] a message box displays that the pem file was successfully written to the location that you specified load the exported certificates into the system/host api connection pair go to administration > configuration > network options in the network options window, go to the tls/ssl settings tab select \[ edit ] next to certificates in the user certificates section right click the system/host api ssl ca x 509 certificate container, and select import select \[ add ] at the bottom of the import certificates window in the file browser, select both the root ca certificate and the signed system/host api certificate and select \[ open ] select \[ ok ] to save the changes in the network options window, the system/host api connection pair shows signed loaded next to certificates in the user certificates section issue a client certificate for vault a later section shows you how to configure this client certificate in the futurex pkcs #11 configuration file go to pki > certificate authorities right click the system tls ca root certificate and select add certificate > new certificate io the subject dn tab, set a common name for the certificate, such as vault leave all settings on the basic info tab set to their default values on the v3 extensions tab, select the tls client certificate profile and select \[ ok ] the vault certificate now shows under the system tls ca root certificate export the vault certificate as a pkcs #12 file to perform the following steps, you must go to configuration > options and enable the allow export of certificates using passwords option go to pki > certificate authorities right click the vault certificate, and select export > pkcs12 select the export selected option, specify a unique name for the export file, and select \[ next ] select \[ finish ] to initiate the export move both the vault certificate and the root ca certificate you exported to the computer that will be running the vault instance a later section shows how to configure and use them for tls communication with the kmes series 3