Skip to content

Commit 179b791

Browse files
committed
Changing port for RSA endpoint and updating KMS regions
1 parent 72e6edd commit 179b791

File tree

15 files changed

+564
-569
lines changed

15 files changed

+564
-569
lines changed

pages/hosted_private_cloud/hosted_private_cloud_powered_by_vmware/vmware_okms_vm-encrypt/guide.de-de.md

Lines changed: 27 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: "KMS for VMware on OVHcloud - Configuring VM encryption"
33
excerpt: "Find out how to enable VM encryption in your managed Hosted Private Cloud VMware vSphere with the OVHcloud KMS (OKMS) solution managed as a service"
4-
updated: 2024-08-28
4+
updated: 2025-07-22
55
---
66

77
<style>
@@ -18,11 +18,6 @@ content:'\25BC';
1818
}
1919
</style>
2020

21-
> [!primary]
22-
>
23-
> This feature is available in beta version.
24-
>
25-
2621
## Objective
2722

2823
**Find out how to order, activate and configure an OVHcloud KMS (OKMS) within a VMware vSphere managed on OVHcloud to enable the encryption policy for your virtual machines.**
@@ -59,25 +54,31 @@ For more information on the choices you can make with KMS and VMware on OVHcloud
5954

6055
> [!primary]
6156
>
62-
> Information and API calls for beta phase.
57+
> Information and API endpoints.
6358
>
6459
65-
| **Type** | **URL** | **Region** | **OKMS Enum Region** | **IP** |
66-
|:-------------:|:---------------------------------|:---------------------:|:----------------------:|:----------------:|
67-
| **KMIP** | eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
68-
| **KMIP** | eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
69-
| **REST** | eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
70-
| **Swagger** | swagger-eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
71-
| **KMIP** | eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
72-
| **KMIP** | eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
73-
| **REST** | eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
74-
| **Swagger** | swagger-eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
60+
| **Type** | **URL** | **Region** | **OKMS Enum Region** | **IP** |
61+
| :----------: | :------------------------------- | :-------------------------: | :------------------: | :-----------------------------------------: |
62+
| **Endpoint** | eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
63+
| **Swagger** | swagger-eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
64+
| **Endpoint** | eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
65+
| **Swagger** | swagger-eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
66+
| **Endpoint** | ca-east-bhs.okms.ovh.net | North America - Beauharnois | CA_EAST_BHS | 142.44.140.50 |
67+
| **Swagger** | swagger-ca-east-bhs.okms.ovh.net | North America - Beauharnois | CA_EAST_BHS | 142.44.140.50 |
68+
| **Endpoint** | ca-east-tor.okms.ovh.net | North America - Toronto | CA_EAST_TOR | 72.251.10.6 |
69+
| **Swagger** | swagger-ca-east-tor.okms.ovh.net | North America - Toronto | CA_EAST_TOR | 72.251.10.6 |
70+
| **Endpoint** | ap-southeast-syd.okms.ovh.net | Asia Pacific - Sydney | AP_SOUTHEAST_SYD | 139.99.175.10 |
71+
| **Swagger** | ap-southeast-syd.okms.ovh.net | Asia Pacific - Sydney | AP_SOUTHEAST_SYD | 139.99.175.10 |
72+
| **Endpoint** | ap-southeast-sgp.ovh.net | Asia Pacific - Singapore | AP_SOUTHEAST_SGP | 51.79.192.115 <br>51.79.192.94 |
73+
| **Swagger** | swagger-ap-southeast-sgp.ovh.net | Asia Pacific - Singapore | AP_SOUTHEAST_SGP | 51.79.192.115 <br>51.79.192.94 |
74+
| **Endpoint** | eu-west-par.okms.ovh.net | France - Paris | EU_WEST_PAR | 57.130.4.16 <br>57.130.4.25 <br>57.130.4.26 |
75+
| **Swagger** | swagger-eu-west-par.okms.ovh.net | France - Paris | EU_WEST_PAR | 57.130.4.16 <br>57.130.4.25 <br>57.130.4.26 |
7576

7677
#### List of API v1 and v2 KMS calls <a name="listing-api"></a>
7778

7879
> [!primary]
7980
>
80-
> Information and API calls for beta phase.
81+
> Information and API calls.
8182
>
8283
8384
| **Method** | **API** | **Path** | **Comments** |
@@ -120,12 +121,7 @@ For more information on the choices you can make with KMS and VMware on OVHcloud
120121

121122
To access the OVHcloud KMS, log in to your [OVHcloud Control Panel](/links/manager), then go to the `Hosted Private Cloud`{.action} section. In the left-hand column, click `Identity, Security & Operation`{.action}, then `Key Management Service`{.action}.
122123

123-
To order a new KMS server, click the `Order a KMS`{.action} button, then `Select a region`{.action} from the two currently available:
124-
125-
You currently have the following regions available:
126-
127-
- `Europe - France Roubaix`
128-
- `Europe - France Strasbourg`
124+
To order a new KMS server, click the `Order a KMS`{.action} button, then `Select a region`{.action}.
129125

130126
The encryption keys and access certificates for this KMS will be stored in the specified region. They can be used for any OVHcloud product, regardless of region.
131127

@@ -196,7 +192,8 @@ Return example:
196192
{
197193
"id": "Null",
198194
"region": "EU_WEST_RBX",
199-
"kmipEndpoint": "eu-west-rbx.okms.ovh.net:5696",
195+
"kmipEndpoint": "eu-west-rbx.okms.ovh.net:5696"
196+
"kmipRsaEndpoint": "eu-west-rbx.okms.ovh.net:5697",
200197
"restEndpoint": "https://eu-west-rbx.okms.ovh.net",
201198
"swaggerEndpoint": "https://swagger-eu-west-rbx.okms.ovh.net",
202199
"iam": {
@@ -245,7 +242,7 @@ In the new window that pops up, fill out the following forms:
245242
To retrieve the TLS fingerprint, launch the following OpenSSL command (adapt your OKMS endpoint to the right region (e.g. eu-west-rbx/sbg), which includes your OVHcloud KMS):
246243

247244
```shell
248-
openssl s_client -connect eu-west-rbx.okms.ovh.net:5696 < /dev/null 2>/dev/null | openssl x509 -fingerprint -noout -in /dev/stdin
245+
openssl s_client -connect eu-west-rbx.okms.ovh.net:5697 < /dev/null 2>/dev/null | openssl x509 -fingerprint -noout -in /dev/stdin
249246
---
250247
Return:
251248
SHA1 Fingerprint=FE:21:E2:DE:B7:51:34:E9:9A:AB:E0:27:FF:1E:42:3A:15:9C:76:47
@@ -323,7 +320,7 @@ Copy and paste (with KMS settings):
323320
To retrieve the KMS TLS fingerprint, run the following command **OpenSSL**, adapting the command to the region where your KMS is located:
324321

325322
```shell
326-
openssl s_client -connect eu-west-rbx.okms.ovh.net:5696 < /dev/null 2>/dev/null | openssl x509 -fingerprint -noout -in /dev/stdin
323+
openssl s_client -connect eu-west-rbx.okms.ovh.net:5697 < /dev/null 2>/dev/null | openssl x509 -fingerprint -noout -in /dev/stdin
327324
---
328325
Back:
329326
SHA1 Fingerprint=FE:21:E2:DE:B7:51:34:E9:9A:AB:E0:27:FF:1E:42:3A:15:9C:76:47
@@ -364,7 +361,7 @@ After running the API, you should see the following result in response:
364361
```shell
365362
{
366363
"kmsId": XXX,
367-
"kmsTcpPort": 5696,
364+
"kmsTcpPort": 5697,
368365
"sslThumbprint": "Null",
369366
"description": "OKMS description",
370367
"state": "delivered",
@@ -449,7 +446,7 @@ After ordering your OKMS, open the flows within your OVHcloud managed vSphere. A
449446
>>
450447
>> ![KMS Key Provider](images/kms_key_provider.png){.thumbnail}
451448
>>
452-
>> Once you have selected the option to add a Key Provider, a window or form will open to enter the details of the **Key Provider** you wish to add. This may include information such as the IP address or domain name (DNS) of the OKMS server, but also the port used (5696).
449+
>> Once you have selected the option to add a Key Provider, a window or form will open to enter the details of the **Key Provider** you wish to add. This may include information such as the IP address or domain name (DNS) of the OKMS server, but also the port used (5697).
453450
>>
454451
>> The domain names and the port (KMIP) do not change.
455452
>>
@@ -462,7 +459,7 @@ After ordering your OKMS, open the flows within your OVHcloud managed vSphere. A
462459
>> | **Name** | | - Name your cluster within vCenter. |
463460
>> | **KMS** | | - The name that will appear in vSphere for your OKMS. |
464461
>> | **Address** | eu-west-rbx.okms.ovh.net <br/> eu-west-sbg.okms.ovh.net | - **Endpoint** of the OKMS server. Choose a domain name over an IP (in vSphere). |
465-
>> | **Port** | 5696 | - Port used by KMIP (does not change). |
462+
>> | **Port** | 5697 | - Port used by KMIP (does not change). |
466463
>>
467464
>> Wait for vSphere to establish the connection with the Key Provider you added. You should see a hint or message confirming that the connection has been successfully established.
468465
>>

pages/hosted_private_cloud/hosted_private_cloud_powered_by_vmware/vmware_okms_vm-encrypt/guide.en-asia.md

Lines changed: 27 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: "KMS for VMware on OVHcloud - Configuring VM encryption"
33
excerpt: "Find out how to enable VM encryption in your managed Hosted Private Cloud VMware vSphere with the OVHcloud KMS (OKMS) solution managed as a service"
4-
updated: 2024-08-28
4+
updated: 2025-07-22
55
---
66

77
<style>
@@ -18,11 +18,6 @@ content:'\25BC';
1818
}
1919
</style>
2020

21-
> [!primary]
22-
>
23-
> This feature is available in beta version.
24-
>
25-
2621
## Objective
2722

2823
**Find out how to order, activate and configure an OVHcloud KMS (OKMS) within a VMware vSphere managed on OVHcloud to enable the encryption policy for your virtual machines.**
@@ -59,25 +54,31 @@ For more information on the choices you can make with KMS and VMware on OVHcloud
5954

6055
> [!primary]
6156
>
62-
> Information and API calls for beta phase.
57+
> Information and API endpoints.
6358
>
6459
65-
| **Type** | **URL** | **Region** | **OKMS Enum Region** | **IP** |
66-
|:-------------:|:---------------------------------|:---------------------:|:----------------------:|:----------------:|
67-
| **KMIP** | eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
68-
| **KMIP** | eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
69-
| **REST** | eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
70-
| **Swagger** | swagger-eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
71-
| **KMIP** | eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
72-
| **KMIP** | eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
73-
| **REST** | eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
74-
| **Swagger** | swagger-eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
60+
| **Type** | **URL** | **Region** | **OKMS Enum Region** | **IP** |
61+
| :----------: | :------------------------------- | :-------------------------: | :------------------: | :-----------------------------------------: |
62+
| **Endpoint** | eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
63+
| **Swagger** | swagger-eu-west-rbx.okms.ovh.net | France - Roubaix | EU_WEST_RBX | 91.134.128.102 |
64+
| **Endpoint** | eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
65+
| **Swagger** | swagger-eu-west-sbg.okms.ovh.net | France - Strasbourg | EU_WEST_SBG | 137.74.127.152 |
66+
| **Endpoint** | ca-east-bhs.okms.ovh.net | North America - Beauharnois | CA_EAST_BHS | 142.44.140.50 |
67+
| **Swagger** | swagger-ca-east-bhs.okms.ovh.net | North America - Beauharnois | CA_EAST_BHS | 142.44.140.50 |
68+
| **Endpoint** | ca-east-tor.okms.ovh.net | North America - Toronto | CA_EAST_TOR | 72.251.10.6 |
69+
| **Swagger** | swagger-ca-east-tor.okms.ovh.net | North America - Toronto | CA_EAST_TOR | 72.251.10.6 |
70+
| **Endpoint** | ap-southeast-syd.okms.ovh.net | Asia Pacific - Sydney | AP_SOUTHEAST_SYD | 139.99.175.10 |
71+
| **Swagger** | ap-southeast-syd.okms.ovh.net | Asia Pacific - Sydney | AP_SOUTHEAST_SYD | 139.99.175.10 |
72+
| **Endpoint** | ap-southeast-sgp.ovh.net | Asia Pacific - Singapore | AP_SOUTHEAST_SGP | 51.79.192.115 <br>51.79.192.94 |
73+
| **Swagger** | swagger-ap-southeast-sgp.ovh.net | Asia Pacific - Singapore | AP_SOUTHEAST_SGP | 51.79.192.115 <br>51.79.192.94 |
74+
| **Endpoint** | eu-west-par.okms.ovh.net | France - Paris | EU_WEST_PAR | 57.130.4.16 <br>57.130.4.25 <br>57.130.4.26 |
75+
| **Swagger** | swagger-eu-west-par.okms.ovh.net | France - Paris | EU_WEST_PAR | 57.130.4.16 <br>57.130.4.25 <br>57.130.4.26 |
7576

7677
#### List of API v1 and v2 KMS calls <a name="listing-api"></a>
7778

7879
> [!primary]
7980
>
80-
> Information and API calls for beta phase.
81+
> Information and API calls.
8182
>
8283
8384
| **Method** | **API** | **Path** | **Comments** |
@@ -120,12 +121,7 @@ For more information on the choices you can make with KMS and VMware on OVHcloud
120121

121122
To access the OVHcloud KMS, log in to your [OVHcloud Control Panel](/links/manager), then go to the `Hosted Private Cloud`{.action} section. In the left-hand column, click `Identity, Security & Operation`{.action}, then `Key Management Service`{.action}.
122123

123-
To order a new KMS server, click the `Order a KMS`{.action} button, then `Select a region`{.action} from the two currently available:
124-
125-
You currently have the following regions available:
126-
127-
- `Europe - France Roubaix`
128-
- `Europe - France Strasbourg`
124+
To order a new KMS server, click the `Order a KMS`{.action} button, then `Select a region`{.action}.
129125

130126
The encryption keys and access certificates for this KMS will be stored in the specified region. They can be used for any OVHcloud product, regardless of region.
131127

@@ -196,7 +192,8 @@ Return example:
196192
{
197193
"id": "Null",
198194
"region": "EU_WEST_RBX",
199-
"kmipEndpoint": "eu-west-rbx.okms.ovh.net:5696",
195+
"kmipEndpoint": "eu-west-rbx.okms.ovh.net:5696"
196+
"kmipRsaEndpoint": "eu-west-rbx.okms.ovh.net:5697",
200197
"restEndpoint": "https://eu-west-rbx.okms.ovh.net",
201198
"swaggerEndpoint": "https://swagger-eu-west-rbx.okms.ovh.net",
202199
"iam": {
@@ -245,7 +242,7 @@ In the new window that pops up, fill out the following forms:
245242
To retrieve the TLS fingerprint, launch the following OpenSSL command (adapt your OKMS endpoint to the right region (e.g. eu-west-rbx/sbg), which includes your OVHcloud KMS):
246243

247244
```shell
248-
openssl s_client -connect eu-west-rbx.okms.ovh.net:5696 < /dev/null 2>/dev/null | openssl x509 -fingerprint -noout -in /dev/stdin
245+
openssl s_client -connect eu-west-rbx.okms.ovh.net:5697 < /dev/null 2>/dev/null | openssl x509 -fingerprint -noout -in /dev/stdin
249246
---
250247
Return:
251248
SHA1 Fingerprint=FE:21:E2:DE:B7:51:34:E9:9A:AB:E0:27:FF:1E:42:3A:15:9C:76:47
@@ -323,7 +320,7 @@ Copy and paste (with KMS settings):
323320
To retrieve the KMS TLS fingerprint, run the following command **OpenSSL**, adapting the command to the region where your KMS is located:
324321

325322
```shell
326-
openssl s_client -connect eu-west-rbx.okms.ovh.net:5696 < /dev/null 2>/dev/null | openssl x509 -fingerprint -noout -in /dev/stdin
323+
openssl s_client -connect eu-west-rbx.okms.ovh.net:5697 < /dev/null 2>/dev/null | openssl x509 -fingerprint -noout -in /dev/stdin
327324
---
328325
Back:
329326
SHA1 Fingerprint=FE:21:E2:DE:B7:51:34:E9:9A:AB:E0:27:FF:1E:42:3A:15:9C:76:47
@@ -364,7 +361,7 @@ After running the API, you should see the following result in response:
364361
```shell
365362
{
366363
"kmsId": XXX,
367-
"kmsTcpPort": 5696,
364+
"kmsTcpPort": 5697,
368365
"sslThumbprint": "Null",
369366
"description": "OKMS description",
370367
"state": "delivered",
@@ -449,7 +446,7 @@ After ordering your OKMS, open the flows within your OVHcloud managed vSphere. A
449446
>>
450447
>> ![KMS Key Provider](images/kms_key_provider.png){.thumbnail}
451448
>>
452-
>> Once you have selected the option to add a Key Provider, a window or form will open to enter the details of the **Key Provider** you wish to add. This may include information such as the IP address or domain name (DNS) of the OKMS server, but also the port used (5696).
449+
>> Once you have selected the option to add a Key Provider, a window or form will open to enter the details of the **Key Provider** you wish to add. This may include information such as the IP address or domain name (DNS) of the OKMS server, but also the port used (5697).
453450
>>
454451
>> The domain names and the port (KMIP) do not change.
455452
>>
@@ -462,7 +459,7 @@ After ordering your OKMS, open the flows within your OVHcloud managed vSphere. A
462459
>> | **Name** | | - Name your cluster within vCenter. |
463460
>> | **KMS** | | - The name that will appear in vSphere for your OKMS. |
464461
>> | **Address** | eu-west-rbx.okms.ovh.net <br/> eu-west-sbg.okms.ovh.net | - **Endpoint** of the OKMS server. Choose a domain name over an IP (in vSphere). |
465-
>> | **Port** | 5696 | - Port used by KMIP (does not change). |
462+
>> | **Port** | 5697 | - Port used by KMIP (does not change). |
466463
>>
467464
>> Wait for vSphere to establish the connection with the Key Provider you added. You should see a hint or message confirming that the connection has been successfully established.
468465
>>

0 commit comments

Comments
 (0)