diff --git a/backend/src/ee/services/kmip/kmip-service.ts b/backend/src/ee/services/kmip/kmip-service.ts index 48876f2b2..49d90bf21 100644 --- a/backend/src/ee/services/kmip/kmip-service.ts +++ b/backend/src/ee/services/kmip/kmip-service.ts @@ -317,10 +317,6 @@ export const kmipServiceFactory = ({ const caAlg = keyAlgorithmToAlgCfg(kmipConfig.caKeyAlgorithm as CertKeyAlgorithm); - const decryptedCaCertChain = decryptor({ cipherTextBlob: kmipConfig.encryptedClientIntermediateCaChain }).toString( - "utf-8" - ); - const caSkObj = crypto.createPrivateKey({ key: decryptor({ cipherTextBlob: kmipConfig.encryptedClientIntermediateCaPrivateKey }), format: "der", @@ -349,7 +345,11 @@ export const kmipServiceFactory = ({ }); const skLeafObj = KeyObject.from(leafKeys.privateKey); - const certificateChain = `${caCertObj.toString("pem")}\n${decryptedCaCertChain}`.trim(); + + const rootCaCert = new x509.X509Certificate(decryptor({ cipherTextBlob: kmipConfig.encryptedRootCaCertificate })); + const serverIntermediateCaCert = new x509.X509Certificate( + decryptor({ cipherTextBlob: kmipConfig.encryptedServerIntermediateCaCertificate }) + ); await kmipClientCertificateDAL.create({ kmipClientId: clientId, @@ -363,7 +363,7 @@ export const kmipServiceFactory = ({ serialNumber, privateKey: skLeafObj.export({ format: "pem", type: "pkcs8" }) as string, certificate: leafCert.toString("pem"), - certificateChain, + certificateChain: `${serverIntermediateCaCert.toString("pem")}\n${rootCaCert.toString("pem")}`.trim(), projectId: kmipClient.projectId }; }; diff --git a/docs/documentation/platform/kms/kmip.mdx b/docs/documentation/platform/kms/kmip.mdx new file mode 100644 index 000000000..6237fc402 --- /dev/null +++ b/docs/documentation/platform/kms/kmip.mdx @@ -0,0 +1,142 @@ +--- +title: "KMIP Integration" +description: "Learn more about integrating with Infisical KMS using KMIP (Key Management Interoperability Protocol)." +--- + + + KMIP integration is an Enterprise-only feature. Please reach out to + sales@infisical.com if you have any questions. + + +## Overview + +Infisical KMS provides **Key Management Interoperability Protocol (KMIP)** support, enabling seamless integration with KMIP-compatible clients. This allows for enhanced key management across various applications that support the **KMIP 1.4 protocol**. + +## Supported Operations + +The Infisical KMIP server supports the following operations for **symmetric keys**: + +- **Create** - Generate symmetric keys. +- **Register** - Register externally created keys. +- **Locate** - Find keys using attributes. +- **Get** - Retrieve keys securely. +- **Activate** - Enable keys for usage. +- **Revoke** - Revoke existing keys. +- **Destroy** - Permanently remove keys. +- **Get Attributes** - Retrieve metadata associated with keys. +- **Query** - Query server capabilities and supported operations. + +## Benefits of KMIP Integration + +Integrating Infisical KMS with KMIP-compatible clients provides the following benefits: + +- **Standardized Key Management**: Allows interoperability with security and cryptographic applications that support KMIP. +- **Enterprise-Grade Security**: Utilizes Infisical’s encryption mechanisms to securely store and manage keys. +- **Centralized Key Management**: Enables a unified approach for managing cryptographic keys across multiple environments. + +## Compatibility + +Infisical KMIP supports **KMIP versions 1.0 to 1.4**, ensuring compatibility with a wide range of clients and security tools. + +## Secure Communication & Authorization + +KMIP client-server communication is secured using **mutual TLS (mTLS)**, ensuring strong identity verification and encrypted data exchange via **PKI certificates**. Each KMIP entity must possess valid certificates signed by a trusted Root CA to establish trust. +For strong isolation, each Infisical organization has its own KMIP PKI (Public Key Infrastructure), ensuring that cryptographic operations and certificate authorities remain separate across organizations. + +Infisical KMS enforces a **two-layer authorization model** for KMIP operations: + +1. **KMIP Server Authorization** – The KMIP server, acting as a proxy, must have the `proxy KMIP` permission to forward client requests to Infisical KMS. This is done using a **machine identity** attached to the KMIP server. +2. **KMIP Client Authorization** – Clients must have the necessary KMIP-level permissions to perform specific key management operations. + +By combining **mTLS for secure communication** and **machine identity-based proxying**, Infisical KMS ensures **strong authentication, controlled access, and centralized key management** for KMIP operations. + +## Setup Instructions + +### Setup KMIP for your organization + + + + From there, press Setup KMIP. + ![KMIP org navigate](/images/platform/kms/kmip/kmip-org-setup-navigation.png) + + + In the modal, select the desired key algorithm to use for the KMIP PKI of your organization. Press continue. + ![KMIP org PKI setup](/images/platform/kms/kmip/kmip-org-setup-modal.png) + + This generates the KMIP PKI for your organization. After this, you can proceed to setting up your KMIP server. + + + + +### Deploying and Configuring the KMIP Server + +Follow these steps to configure and deploy a KMIP server. + + + + Configure a [machine identity](https://infisical.com/docs/documentation/platform/identities/machine-identities#machine-identities) for the KMIP server to use. + ![KMIP create machine identity](/images/platform/kms/kmip/kmip-create-mi.png) + + Create a custom organization role and give it the **Proxy KMIP** permission. + ![KMIP create custom role](/images/platform/kms/kmip/kmip-create-custom-role.png) + ![KMIP assign proxy to role](/images/platform/kms/kmip/kmip-assign-custom-role-proxy.png) + + Assign the machine identity to the custom organization role. This allows the machine identity to serve KMIP client requests and forward them from your KMIP server to Infisical. + ![KMIP assign role to machine identity](/images/platform/kms/kmip/kmip-assign-mi-to-role.png) + + + + + To deploy the KMIP server, use the Infisical CLI’s `kmip start` command. + Before proceeding, make sure you have the [Infisical CLI installed](https://infisical.com/docs/cli/overview). + + Once installed, launch the KMIP server with the following command: + + ```bash + infisical kmip start \ + --identity-client-id= \ # This can be set by defining the INFISICAL_UNIVERSAL_AUTH_CLIENT_ID ENV variable + --identity-client-secret= \ # This can be set by defining the INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET ENV variable + --domain=https://app.infisical.com \ + --hostnames-or-ips="my-kmip-server.com" + ``` + + The following flags are available for the `infisical kmip start` command:: + - **addr** (default: localhost:5696): The address the KMIP server listens on. + - **identity-auth-method** (default: universal-auth): The authentication method for the machine identity. + - **identity-client-id**: The client ID of the machine identity. This can be set by defining the `INFISICAL_UNIVERSAL_AUTH_CLIENT_ID` ENV variable. + - **identity-client-secret**: The client secret of the machine identity. This can be set by defining the `INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET` ENV variable. + - **server-name** (default: "kmip-server"): The name of the KMIP server. + - **certificate-ttl** (default: "1y"): The duration for which the server certificate is valid. + - **hostnames-or-ips:** A comma-separated list of hostnames or IPs the KMIP server will use (required). + + + + +### Add and Configure KMIP Clients + + + + From there, press Add KMIP Client + ![KMIP client overview](/images/platform/kms/kmip/kmip-client-overview.png) + + + In the modal, provide the details of your client. The selected permissions determine what KMIP operations can be performed in your KMS project. + ![KMIP client modal](/images/platform/kms/kmip/kmip-client-modal.png) + + + Once the KMIP client is created, you will have to generate a client certificate. + Press Generate Certificate. + ![KMIP generate client cert](/images/platform/kms/kmip/kmip-client-generate-cert.png) + + Provide the desired TTL and key algorithm to use and press Generate Client Certificate. + ![KMIP client cert config](/images/platform/kms/kmip/kmip-client-cert-config-modal.png) + + Configure your KMIP clients to use the generated client certificate, certificate chain and private key. + ![KMIP client cert modal](/images/platform/kms/kmip/kmip-client-certificate-modal.png) + + + + +## Additional Resources + +- [KMIP 1.4 Specification](http://docs.oasis-open.org/kmip/spec/v1.4/os/kmip-spec-v1.4-os.html) diff --git a/docs/images/platform/kms/kmip/kmip-assign-custom-role-proxy.png b/docs/images/platform/kms/kmip/kmip-assign-custom-role-proxy.png new file mode 100644 index 000000000..498fc2012 Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-assign-custom-role-proxy.png differ diff --git a/docs/images/platform/kms/kmip/kmip-assign-mi-to-role.png b/docs/images/platform/kms/kmip/kmip-assign-mi-to-role.png new file mode 100644 index 000000000..93d4c7f84 Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-assign-mi-to-role.png differ diff --git a/docs/images/platform/kms/kmip/kmip-client-cert-config-modal.png b/docs/images/platform/kms/kmip/kmip-client-cert-config-modal.png new file mode 100644 index 000000000..45eb8c830 Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-client-cert-config-modal.png differ diff --git a/docs/images/platform/kms/kmip/kmip-client-certificate-modal.png b/docs/images/platform/kms/kmip/kmip-client-certificate-modal.png new file mode 100644 index 000000000..d6f9fc2ad Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-client-certificate-modal.png differ diff --git a/docs/images/platform/kms/kmip/kmip-client-generate-cert.png b/docs/images/platform/kms/kmip/kmip-client-generate-cert.png new file mode 100644 index 000000000..40b49f570 Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-client-generate-cert.png differ diff --git a/docs/images/platform/kms/kmip/kmip-client-modal.png b/docs/images/platform/kms/kmip/kmip-client-modal.png new file mode 100644 index 000000000..5038c2a87 Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-client-modal.png differ diff --git a/docs/images/platform/kms/kmip/kmip-client-overview.png b/docs/images/platform/kms/kmip/kmip-client-overview.png new file mode 100644 index 000000000..794a91d42 Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-client-overview.png differ diff --git a/docs/images/platform/kms/kmip/kmip-create-custom-role.png b/docs/images/platform/kms/kmip/kmip-create-custom-role.png new file mode 100644 index 000000000..5e6a5145d Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-create-custom-role.png differ diff --git a/docs/images/platform/kms/kmip/kmip-create-mi.png b/docs/images/platform/kms/kmip/kmip-create-mi.png new file mode 100644 index 000000000..ed8a0988c Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-create-mi.png differ diff --git a/docs/images/platform/kms/kmip/kmip-org-setup-modal.png b/docs/images/platform/kms/kmip/kmip-org-setup-modal.png new file mode 100644 index 000000000..6fc6dd7ce Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-org-setup-modal.png differ diff --git a/docs/images/platform/kms/kmip/kmip-org-setup-navigation.png b/docs/images/platform/kms/kmip/kmip-org-setup-navigation.png new file mode 100644 index 000000000..5a77878e5 Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-org-setup-navigation.png differ diff --git a/docs/mint.json b/docs/mint.json index b62af6533..6c78d0ea3 100644 --- a/docs/mint.json +++ b/docs/mint.json @@ -120,7 +120,8 @@ "pages": [ "documentation/platform/kms/overview", "documentation/platform/kms/hsm-integration", - "documentation/platform/kms/kubernetes-encryption" + "documentation/platform/kms/kubernetes-encryption", + "documentation/platform/kms/kmip" ] }, {