Setup KMS server

The KMS server provides the interface to clients that use the KMS protocol.
Secure Sockets Layer (SSL) is required; therefore, you must specify the name of the server certificate.

To configure the KMS server, perform the following steps:

  1. Select the Device tab.

  2. In the Device Configuration menu, click KMS Server to display the KMS Server Configuration window.

  3. In the KMS Server Settings section of the window, click Edit.

  4. Configure the KMIP Server Settings.

    1. The IP address can be an IPv4 address or an IPv6 address. If support for IPv6 has been enabled, see First run.

    2. If necessary, change the Port and Connection Timeout values. Utimaco recommends the default values of 9000 for the Port and 3600 for the Connection Timeout.

    3. For Server Certificate, select the name of the certificate you created in Setting up ESKM certificate. For example, ESKM KMS Server.

    4. Enable Allow Key and Policy Configuration Operations

    5. Enable Allow Key Export

image-20250910-083217.png

KMS Server Settings

  1. Click Save.

  2. Confirm that the KMS server is started.

    1. Go to the Services List section of the Services Configuration page
      (Device -> Maintenance -> Services -> KMS Server).

    2. The status of the KMS server should be Started. If the status is Stopped, select the KMS Server, and then click Start.

To enable KMIP client certificate, perform the following steps.

  1. In the KMS Server Authentication Settings section of the window, click Edit.

image-20250908-143516.png


KMS Server Authentication Settings - Edit

  1. Click the appropriate option under User Directory, Password Authentication, and Client Certificate Authentication. Select the appropriate Trusted CA list and Username in Client Certificate and click Save.

image-20250908-143624.png


KMS Server Authentication Settings - Authentication