A KMIP-compliant key server, separate from vCenter, that provides KEKs through a standard key provider. When vSphere Native Key Provider is used, no such server is required.
Also called Key Management Server.
Read more: Broadcom TechDocs
In the Ultra Transcenders books
Each book explains KMS in context, with comparison tables and the common traps.
Terms in this definition
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - vCenter
Management software for VMs, clusters and ESX hosts. Each domain in VCF gets a dedicated one.
- Standard key provider
Uses an outside KMIP key management server as the source of encryption keys for vCenter. Since vSphere 9.0, wrapped key mode is the default, so many keys sit under a single wrapping key held by the KMS (the Native Key Provider needs no KMS at all).
- vSphere Native Key Provider
Built into vCenter, this provider generates encryption keys itself, so no external KMS is needed; back it up before first use.
Related terms
- KMIP
An industry-standard protocol through which a client application talks to a key management server. vCenter acts as a KMIP client for a standard key provider, whereas vSphere Native Key Provider does not need a KMIP server at all.