From d1fda882a570d34f256e61ee207a163aa4cb4072 Mon Sep 17 00:00:00 2001 From: James Bayer <1139532+jbayer@users.noreply.github.com> Date: Mon, 8 Apr 2024 12:51:05 -0700 Subject: [PATCH] [DOCS] Update kmip.mdx to add Cert Authority details (#23907) * Update kmip.mdx to add Cert Authority details * Update website/content/docs/secrets/kmip.mdx Accepted suggestion Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com> --------- Co-authored-by: Sarah Chavis <62406755+schavis@users.noreply.github.com> --- website/content/docs/secrets/kmip.mdx | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/website/content/docs/secrets/kmip.mdx b/website/content/docs/secrets/kmip.mdx index d1ce62b387..dda13a6789 100644 --- a/website/content/docs/secrets/kmip.mdx +++ b/website/content/docs/secrets/kmip.mdx @@ -74,6 +74,15 @@ requests. ```text $ vault write kmip/config listen_addrs=0.0.0.0:5696 ``` +### KMIP Certificate Authority for Client Certificates + +When the KMIP Secrets Engine is initially configured, Vault generates a KMIP +Certificate Authority (CA) whose only purpose is to authenticate KMIP client +certificates. + +Vault uses the internal KMIP CA to generate certificates for clients +authenticating to Vault with the KMIP protocol. You cannot import external KMIP +authorities. All KMIP authentication must use the internally-generated KMIP CA. ## Usage