Create a CSR for KMIP User and Sign Using ESKM

  1. Click Settings > Array Certificates.

  2. Click on the + symbol at the top right of the screen and select Create a certificate signing request.

  3. Choose ekm-client in the drop-down for the Array service.

  4. Fill out CSR details.

You must use the certificate’s Common Name (CN) as the KMIP username when creating the KMIP user.


image-20260112-074846.png


Create a CSR

  1. After the CSR is generated, the GUI will bring you back to the Array Certificates window, and click the newly created signing request.

  2. Copy the CSR from ----- BEGIN CERTIFICATE REQUEST----- to the end of -----END CERTIFICATE REQUEST----.

  3. Please refer to section Sign the Host Certificate using ESKM to sign the CSR using ESKM.

If you are using a third-party CA, send a CSR request to the CA to sign instead of signing using LocalCA in ESKM.

  1. Refer to Create a KMIP User Group and Create a KMIP User, then create a KMIP User Group and User.