![NetApp AltaVault AVA400 Administration Manual Download Page 93](http://html.mh-extra.com/html/netapp/altavault-ava400/altavault-ava400_administration-manual_1669933093.webp)
NetApp AltaVault Cloud Integrated Storage Administration Guide
93
Beta Draft
Configuring KMIP
Configuring security settings
6.
Click
Apply
to apply your changes to the running configuration.
7.
To view PEM information, under Web Certificate, select the PEM tab.
Configuring KMIP
Key Management Interoperability Protocol (KMIP) is a standard describing communication between key management
servers and their clients. AltaVault manages several important pieces of information that must be kept secure. These
pieces include the datastore encryption key that encrypts user data and cloud credentials (which allow AltaVault to
authenticate itself to the cloud provider). Without KMIP, these pieces of information are stored on a disk in an
encrypted partition of AltaVault called the Secure Vault. They can also be exported in configuration archives. It is up
to the user to keep these archives secure.
A user’s environment may be running multiple AltaVault’s as well as other appliances or services which also require
own encryption keys and other sensitive information. The need for centralized key management has led to
development of key management servers (KMS), which operates as the KMIP server.
During setup, the administrator specifies an external KMS to manage AltaVault’s keys and cloud authentication
parameters. The datastore encryption key and/or cloud authentication parameters will then be managed by the KMS.
If AltaVault uses KMIP, the KMS must be running nominally in order for AltaVault to be accessible.
AltaVault implements the following KMIP functionality:
Registering keys with a KMS
Fetching previously registered keys from a KMS
Note:
Keys retrieved from a key server are never stored on a disk, only in memory. You cannot export fetched keys from a key
server.
This section includes:
“Using the Management Console to configure KMIP”
Using the Management Console to configure KMIP
This section includes the following information:
“To add a KMIP server” on page 94
State
Specify the state. Do not abbreviate.
Country
Specify the country (2-letter code only).
Email Address
Specify the email address of the contact person.
Generate CSR
Generates the Certificate Signing Request.
Control
Description
Summary of Contents for AltaVault AVA400
Page 2: ...Beta Draft ...
Page 10: ...Beta Draft Contents ...