KMIP objects include certificates and symmetric or asymmetric keys. External KMIP clients create them as needed, and those clients can then fetch them. You can use the Cryptographic Security Platform Vault for KMIP webGUI to view and manipulate all objects created by all KMIP users in the system.

The Cryptographic Security Platform Vault for KMIP does not support RSA keys of length 512 and 1024.

If this KMIP server is being used as a KMS for VMware, the number of KMIP objects may exceed the number of encrypted VMs because:

  • The KMIP objects created when a VM is encrypted are not removed when that VM is decrypted or deleted.
  • Cloned VMs may share the same key if they have the same UUID.
  • vCenter creates a KMIP object for each ESXi host when you enable encryption for that host.
  • Stale keys for an ESXi host are not removed unless you detach, reboot, and then reattach the ESXi host.

To manage KMIP objects

  1. Log in to the Cryptographic Security Platform Vault for KMIP webGUI.

  2. From the Cryptographic Security Platform Vault for KMIP webGUI, select the following options. 

Objects

The Objects tab shows the following information for each object:

  • UUID—The Universally Unique Identifier associated with the KMIP object.
  • Initial Date—When the object was created.
  • Last Change Date—When the object was last modified.
  • Object Type—The object type.
  • Archived—Whether the object has been archived. You can recover archived objects if needed.
  • State—The state of the KMIP object. This can be one of the following: 
    • Pre-Active—The object has been created, but it is not yet available for use.

    • Active—The object is fully operational and available for use.

    • Deactivated/Archived—The object is temporarily unavailable, but can be reactivated.

    • Compromised—The object is suspected or confirmed to be compromised.

    • Destroyed—The object has been permanently deleted and is unrecoverable.

    • Destroyed Compromised—The object was compromised before being destroyed.

To filter the object based on any of the fields:

  1. Click the text box next to the Filter tab
  2. Select Filter by
  3. Enter the filter value

Click any object in the list to view additional attributes for that object. The OASIS KMIP standard defines all attributes.

Actions

The Actions menu in the right corner allows you to perform any of the following actions on the selected object. All actions, except Rekey All Objects, follow the KMIP standard. Some actions require the object to be in a specific state. For details, see the OASIS KMIP standard.

  • Activate—By default, objects are created in the PreActive state. Click Activate to enable more transitions for the object. Note: Many KMIP clients change objects to Active state as part of the creation process.
  • Archive—Objects will no longer return keys, but they remain in the system. You can use the Recover command to return an archived object to active state and retrieve its keys.
  • Destroy—This operation will destroy the object and change the object's state to “Destroyed”. Destroyed objects cannot be retrieved, but the object metadata will continue to appear on the KMIP objects page.
  • Recover—Restores an Archived object to the active state so that its keys can be retrieved.
  • Revoke—Revocation is permanent. Objects that are revoked cannot be moved back to Active, but the client can still retrieve any key material. Revocation prompts for a revocation reason, which can be any string. Revocation also prompts for a Reason Code, which is one of the following KMIP standard codes. 
    1—Unspecified
    2—Key Compromise
    3—CA Compromise
    4—Affiliation Changed
    5—Superseded
    6—Cessation of Operation
    7—Privilege Withdrawn

     Any unrecognized value will be considered the same as "1—Unspecified."

  • Rekey KMIP Objects - This option allows you to rekey all existing KMIP objects using a new KEK if KMIP KEK wrapping is enabled. See KEK with a KMIP Vault.