diff --git a/backend/src/ee/services/kmip/kmip-service.ts b/backend/src/ee/services/kmip/kmip-service.ts
index 48876f2b2..49d90bf21 100644
--- a/backend/src/ee/services/kmip/kmip-service.ts
+++ b/backend/src/ee/services/kmip/kmip-service.ts
@@ -317,10 +317,6 @@ export const kmipServiceFactory = ({
const caAlg = keyAlgorithmToAlgCfg(kmipConfig.caKeyAlgorithm as CertKeyAlgorithm);
- const decryptedCaCertChain = decryptor({ cipherTextBlob: kmipConfig.encryptedClientIntermediateCaChain }).toString(
- "utf-8"
- );
-
const caSkObj = crypto.createPrivateKey({
key: decryptor({ cipherTextBlob: kmipConfig.encryptedClientIntermediateCaPrivateKey }),
format: "der",
@@ -349,7 +345,11 @@ export const kmipServiceFactory = ({
});
const skLeafObj = KeyObject.from(leafKeys.privateKey);
- const certificateChain = `${caCertObj.toString("pem")}\n${decryptedCaCertChain}`.trim();
+
+ const rootCaCert = new x509.X509Certificate(decryptor({ cipherTextBlob: kmipConfig.encryptedRootCaCertificate }));
+ const serverIntermediateCaCert = new x509.X509Certificate(
+ decryptor({ cipherTextBlob: kmipConfig.encryptedServerIntermediateCaCertificate })
+ );
await kmipClientCertificateDAL.create({
kmipClientId: clientId,
@@ -363,7 +363,7 @@ export const kmipServiceFactory = ({
serialNumber,
privateKey: skLeafObj.export({ format: "pem", type: "pkcs8" }) as string,
certificate: leafCert.toString("pem"),
- certificateChain,
+ certificateChain: `${serverIntermediateCaCert.toString("pem")}\n${rootCaCert.toString("pem")}`.trim(),
projectId: kmipClient.projectId
};
};
diff --git a/docs/documentation/platform/kms/kmip.mdx b/docs/documentation/platform/kms/kmip.mdx
new file mode 100644
index 000000000..6237fc402
--- /dev/null
+++ b/docs/documentation/platform/kms/kmip.mdx
@@ -0,0 +1,142 @@
+---
+title: "KMIP Integration"
+description: "Learn more about integrating with Infisical KMS using KMIP (Key Management Interoperability Protocol)."
+---
+
+
+ KMIP integration is an Enterprise-only feature. Please reach out to
+ sales@infisical.com if you have any questions.
+
+
+## Overview
+
+Infisical KMS provides **Key Management Interoperability Protocol (KMIP)** support, enabling seamless integration with KMIP-compatible clients. This allows for enhanced key management across various applications that support the **KMIP 1.4 protocol**.
+
+## Supported Operations
+
+The Infisical KMIP server supports the following operations for **symmetric keys**:
+
+- **Create** - Generate symmetric keys.
+- **Register** - Register externally created keys.
+- **Locate** - Find keys using attributes.
+- **Get** - Retrieve keys securely.
+- **Activate** - Enable keys for usage.
+- **Revoke** - Revoke existing keys.
+- **Destroy** - Permanently remove keys.
+- **Get Attributes** - Retrieve metadata associated with keys.
+- **Query** - Query server capabilities and supported operations.
+
+## Benefits of KMIP Integration
+
+Integrating Infisical KMS with KMIP-compatible clients provides the following benefits:
+
+- **Standardized Key Management**: Allows interoperability with security and cryptographic applications that support KMIP.
+- **Enterprise-Grade Security**: Utilizes Infisical’s encryption mechanisms to securely store and manage keys.
+- **Centralized Key Management**: Enables a unified approach for managing cryptographic keys across multiple environments.
+
+## Compatibility
+
+Infisical KMIP supports **KMIP versions 1.0 to 1.4**, ensuring compatibility with a wide range of clients and security tools.
+
+## Secure Communication & Authorization
+
+KMIP client-server communication is secured using **mutual TLS (mTLS)**, ensuring strong identity verification and encrypted data exchange via **PKI certificates**. Each KMIP entity must possess valid certificates signed by a trusted Root CA to establish trust.
+For strong isolation, each Infisical organization has its own KMIP PKI (Public Key Infrastructure), ensuring that cryptographic operations and certificate authorities remain separate across organizations.
+
+Infisical KMS enforces a **two-layer authorization model** for KMIP operations:
+
+1. **KMIP Server Authorization** – The KMIP server, acting as a proxy, must have the `proxy KMIP` permission to forward client requests to Infisical KMS. This is done using a **machine identity** attached to the KMIP server.
+2. **KMIP Client Authorization** – Clients must have the necessary KMIP-level permissions to perform specific key management operations.
+
+By combining **mTLS for secure communication** and **machine identity-based proxying**, Infisical KMS ensures **strong authentication, controlled access, and centralized key management** for KMIP operations.
+
+## Setup Instructions
+
+### Setup KMIP for your organization
+
+
+
+ From there, press Setup KMIP.
+ 
+
+
+ In the modal, select the desired key algorithm to use for the KMIP PKI of your organization. Press continue.
+ 
+
+ This generates the KMIP PKI for your organization. After this, you can proceed to setting up your KMIP server.
+
+
+
+
+### Deploying and Configuring the KMIP Server
+
+Follow these steps to configure and deploy a KMIP server.
+
+
+
+ Configure a [machine identity](https://infisical.com/docs/documentation/platform/identities/machine-identities#machine-identities) for the KMIP server to use.
+ 
+
+ Create a custom organization role and give it the **Proxy KMIP** permission.
+ 
+ 
+
+ Assign the machine identity to the custom organization role. This allows the machine identity to serve KMIP client requests and forward them from your KMIP server to Infisical.
+ 
+
+
+
+
+ To deploy the KMIP server, use the Infisical CLI’s `kmip start` command.
+ Before proceeding, make sure you have the [Infisical CLI installed](https://infisical.com/docs/cli/overview).
+
+ Once installed, launch the KMIP server with the following command:
+
+ ```bash
+ infisical kmip start \
+ --identity-client-id= \ # This can be set by defining the INFISICAL_UNIVERSAL_AUTH_CLIENT_ID ENV variable
+ --identity-client-secret= \ # This can be set by defining the INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET ENV variable
+ --domain=https://app.infisical.com \
+ --hostnames-or-ips="my-kmip-server.com"
+ ```
+
+ The following flags are available for the `infisical kmip start` command::
+ - **addr** (default: localhost:5696): The address the KMIP server listens on.
+ - **identity-auth-method** (default: universal-auth): The authentication method for the machine identity.
+ - **identity-client-id**: The client ID of the machine identity. This can be set by defining the `INFISICAL_UNIVERSAL_AUTH_CLIENT_ID` ENV variable.
+ - **identity-client-secret**: The client secret of the machine identity. This can be set by defining the `INFISICAL_UNIVERSAL_AUTH_CLIENT_SECRET` ENV variable.
+ - **server-name** (default: "kmip-server"): The name of the KMIP server.
+ - **certificate-ttl** (default: "1y"): The duration for which the server certificate is valid.
+ - **hostnames-or-ips:** A comma-separated list of hostnames or IPs the KMIP server will use (required).
+
+
+
+
+### Add and Configure KMIP Clients
+
+
+
+ From there, press Add KMIP Client
+ 
+
+
+ In the modal, provide the details of your client. The selected permissions determine what KMIP operations can be performed in your KMS project.
+ 
+
+
+ Once the KMIP client is created, you will have to generate a client certificate.
+ Press Generate Certificate.
+ 
+
+ Provide the desired TTL and key algorithm to use and press Generate Client Certificate.
+ 
+
+ Configure your KMIP clients to use the generated client certificate, certificate chain and private key.
+ 
+
+
+
+
+## Additional Resources
+
+- [KMIP 1.4 Specification](http://docs.oasis-open.org/kmip/spec/v1.4/os/kmip-spec-v1.4-os.html)
diff --git a/docs/images/platform/kms/kmip/kmip-assign-custom-role-proxy.png b/docs/images/platform/kms/kmip/kmip-assign-custom-role-proxy.png
new file mode 100644
index 000000000..498fc2012
Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-assign-custom-role-proxy.png differ
diff --git a/docs/images/platform/kms/kmip/kmip-assign-mi-to-role.png b/docs/images/platform/kms/kmip/kmip-assign-mi-to-role.png
new file mode 100644
index 000000000..93d4c7f84
Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-assign-mi-to-role.png differ
diff --git a/docs/images/platform/kms/kmip/kmip-client-cert-config-modal.png b/docs/images/platform/kms/kmip/kmip-client-cert-config-modal.png
new file mode 100644
index 000000000..45eb8c830
Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-client-cert-config-modal.png differ
diff --git a/docs/images/platform/kms/kmip/kmip-client-certificate-modal.png b/docs/images/platform/kms/kmip/kmip-client-certificate-modal.png
new file mode 100644
index 000000000..d6f9fc2ad
Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-client-certificate-modal.png differ
diff --git a/docs/images/platform/kms/kmip/kmip-client-generate-cert.png b/docs/images/platform/kms/kmip/kmip-client-generate-cert.png
new file mode 100644
index 000000000..40b49f570
Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-client-generate-cert.png differ
diff --git a/docs/images/platform/kms/kmip/kmip-client-modal.png b/docs/images/platform/kms/kmip/kmip-client-modal.png
new file mode 100644
index 000000000..5038c2a87
Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-client-modal.png differ
diff --git a/docs/images/platform/kms/kmip/kmip-client-overview.png b/docs/images/platform/kms/kmip/kmip-client-overview.png
new file mode 100644
index 000000000..794a91d42
Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-client-overview.png differ
diff --git a/docs/images/platform/kms/kmip/kmip-create-custom-role.png b/docs/images/platform/kms/kmip/kmip-create-custom-role.png
new file mode 100644
index 000000000..5e6a5145d
Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-create-custom-role.png differ
diff --git a/docs/images/platform/kms/kmip/kmip-create-mi.png b/docs/images/platform/kms/kmip/kmip-create-mi.png
new file mode 100644
index 000000000..ed8a0988c
Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-create-mi.png differ
diff --git a/docs/images/platform/kms/kmip/kmip-org-setup-modal.png b/docs/images/platform/kms/kmip/kmip-org-setup-modal.png
new file mode 100644
index 000000000..6fc6dd7ce
Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-org-setup-modal.png differ
diff --git a/docs/images/platform/kms/kmip/kmip-org-setup-navigation.png b/docs/images/platform/kms/kmip/kmip-org-setup-navigation.png
new file mode 100644
index 000000000..5a77878e5
Binary files /dev/null and b/docs/images/platform/kms/kmip/kmip-org-setup-navigation.png differ
diff --git a/docs/mint.json b/docs/mint.json
index b62af6533..6c78d0ea3 100644
--- a/docs/mint.json
+++ b/docs/mint.json
@@ -120,7 +120,8 @@
"pages": [
"documentation/platform/kms/overview",
"documentation/platform/kms/hsm-integration",
- "documentation/platform/kms/kubernetes-encryption"
+ "documentation/platform/kms/kubernetes-encryption",
+ "documentation/platform/kms/kmip"
]
},
{