Client Certificate Creation

This certificate functions as the client certificate used to authenticate and securely connect to the ESKM system. It is essential for establishing mutual TLS communication, where both the client and server verify each other’s identities. The client certificate must be uploaded and registered in Veeam Backup & Replication to enable secure access and enforce identity-based access control.

The following steps outline the process for generating the client certificate:

  1. Go to the Security tab.

  2. Click on the Certificates option listed under Certificates & CAs.

  3. Scroll down to the Create Certificate section.

  4. Enter a Certificate Name and Common Name (e.g., KMIPClientVeeamBR).

  5. Enter your organization’s details.

  6. Enter a Subject Alternative Name.

  7. Select the Algorithm (e.g., RSA-2048).

  8. Choose the Creation Type as Certificate Signed by Local CA. Select the CA name you created in Local CA Creation (e.g., ESKMCAVeeamBR).

  9. Select the Certificate Purpose as Client.

  10. Click Create.

client certificate creation-20260420-034052.png


Client Certificate Creation

  1. Open the created client certificate and export it by providing a password.

client certificate export-20260420-035446.png


Exporting Client Certificate

  1. The certificate will be downloaded in p12 format.

  2. Click the Download button to save the certificate content for local user creation.

image-20260508-094319.png


Downloading Client Certificate