Uses an outside KMIP key management server as the source of encryption keys for vCenter. Since vSphere 9.0, wrapped key mode is the default, so many keys sit under a single wrapping key held by the KMS (the Native Key Provider needs no KMS at all).
Read more: Broadcom TechDocs
In the Ultra Transcenders books
Each book explains Standard key provider in context, with comparison tables and the common traps.
Terms in this definition
- KMIP
An industry-standard protocol through which a client application talks to a key management server. vCenter acts as a KMIP client for a standard key provider, whereas vSphere Native Key Provider does not need a KMIP server at all.
- KMS
A KMIP-compliant key server, separate from vCenter, that provides KEKs through a standard key provider. When vSphere Native Key Provider is used, no such server is required.
- Encryption
Scrambling data so it cannot be read without the correct secret key, which is then used to turn it back again. Hashing, by contrast, cannot be reversed.
- vCenter
Management software for VMs, clusters and ESX hosts. Each domain in VCF gets a dedicated one.
- vSphere
VMware's platform for virtualisation, made up of vCenter and ESX hosts, supplying compute for VCF clusters.
- Index field attributes
Settings applied to each field in an Azure AI Search index:
searchablefor full text,retrievableto return it,filterablefor exact-match$filter,sortable,facetablefor counts, andkeyfor the unique document ID. - KMS
Legacy AKS plug-in using an Azure Key Vault key to encrypt Kubernetes Secrets at rest in etcd. On Kubernetes 1.33 onwards, Microsoft Learn points to the newer KMS data encryption experience instead.
- Provider
The organisation that shares data in OpenSharing. Recipients also see a provider as a Unity Catalog securable, from which shares can be mounted as catalogs.