From 4b143c7e8db18116be4108745980648b92ce66c8 Mon Sep 17 00:00:00 2001 From: James Bayer <1139532+jbayer@users.noreply.github.com> Date: Mon, 8 Apr 2024 19:51:05 +0000 Subject: [PATCH] backport of commit d1fda882a570d34f256e61ee207a163aa4cb4072 --- website/content/docs/secrets/kmip.mdx | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/website/content/docs/secrets/kmip.mdx b/website/content/docs/secrets/kmip.mdx index d1ce62b3870f..dda13a6789b7 100644 --- a/website/content/docs/secrets/kmip.mdx +++ b/website/content/docs/secrets/kmip.mdx @@ -74,6 +74,15 @@ requests. ```text $ vault write kmip/config listen_addrs=0.0.0.0:5696 ``` +### KMIP Certificate Authority for Client Certificates + +When the KMIP Secrets Engine is initially configured, Vault generates a KMIP +Certificate Authority (CA) whose only purpose is to authenticate KMIP client +certificates. + +Vault uses the internal KMIP CA to generate certificates for clients +authenticating to Vault with the KMIP protocol. You cannot import external KMIP +authorities. All KMIP authentication must use the internally-generated KMIP CA. ## Usage