Establish Trust

  1. Click TRUST in the “Make vCenter Trust KMS” window and click on “MAKE KMS TRUST VCENTER”.

image-20260203-122454.png


Make vCenter Trust KMS

image-20260203-122604.png


Make KMS Trust vCenter

  1. Navigate to Choose a method, Select “New Certificate Signing Request (CSR)” and click NEXT.

image-20260203-122702.png


Choose a Method

  1. In “Submit CSR to KMS”, click on COPY to copy the certificate. Alternatively, click on DOWNLOAD to download the certificate.

image-20260203-122749.png


Submit CSR to KMS

  1. Click on DONE.

image-20260203-122858.png


Click 'Done'

  1. Go to ESKM and click on Security > Certificates & CAs > Local CAs.

  2. Select the CA, and then click Sign Request.

image-20260203-122952.png


Local Certificate Authority List

  1. Set “Certificate Purpose” to Client.

  2. Paste the certificate request generated by the client application into the certificate request field.

  3. Click Sign Request.

image-20260203-123034.png


Sign Certificate Request

image-20260203-123150.png


CA Certificate Information

  1. Please note down the Common Name (CN) from the certificate information page and download the certificate.

  2. Open the Management Console of the ESKM and navigate to Security > Local Users & Groups > Local Users.

  3. At the bottom of the list, click Add.

  4. The Create Local User window appears.

  5. Create a KMIP local user in ESKM and provide the signed certificate content.

The “Username” must match with the noted “Common Name (CN)”.

image-20260203-123314.png


Create Local User

image-20260203-123354.png


Selected Local User

  1. Go to vCenter and click on “Upload Signed Certificate”. 

image-20260203-123433.png


Upload Signed Certificate

  1. Click UPLOAD A FILE and select the downloaded certificate from ESKM.

image-20260203-123531.png


Upload Signed CSR Certificate

  1. Click on UPLOAD and confirm trust.

  2. Confirm that the ESKM server is accessible.

image-20260203-123633.png


Server1

  1. Click on ADD again to add another ESKM server to the existing cluster and allow failover.

  2. Enter the details to add a Key Management Server (ESKM).

image-20260203-123718.png


Add KMS

  1. Review the input information and click ADD.

  2. Click TRUST to make the vCenter trust KMS.

image-20260203-123823.png


Make vCenter Trust KMS

  1. Confirm both the ESKM servers are accessible.

image-20260203-123943.png


Server1 and Server 2

ESKM will be successfully integrated with VMware by following the procedure described above. Please follow the VMware policy guidelines to encrypt the VMs/ VSAN.