---
title: "Fortanix DSM as a KMS to Secure VMware Virtual Environments"
slug: "fortanix-dsm-as-a-kms-to-secure-vmware-virtual-environments"
updated: 2026-07-27T16:23:11Z
published: 2026-07-27T16:23:11Z
canonical: "support.fortanix.com/fortanix-dsm-as-a-kms-to-secure-vmware-virtual-environments"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://support.fortanix.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Fortanix DSM as a KMS to Secure VMware Virtual Environments

## 1.0 Introduction

This article provides step-by-step instructions for configuring **Fortanix-Data-Security-Manager (DSM)** as a Key Management Server (KMS) in vSphere using the **vSphere Web Client**. Establishing trust and authenticating vSphere to Fortanix DSM can be achieved through certificates. This method ensures secure communication between vSphere and Fortanix DSM, enabling various encryption functionalities such as vSphere Virtual Machine (VM) encryption and Virtual Storage Area Network (VSAN) encryption.

## 2.0 Product Versions Tested

The following product versions were tested:

- Fortanix DSM version 4.32.
- VMware vSphere version 8.0 U3

## 3.0 Prerequisites

Before proceeding, ensure the following:

- Fortanix DSM version 4.32 or later.
- A Fortanix DSM account is created. *For more information, refer to the* [*User's Guide: Getting Started with Fortanix Data Security Manager - UI*](/v1/docs/users-guide-getting-started-with-fortanix-data-security-manager-ui)*.*
- VMware vSphere version 7.0 U3 or later.

## 4.0 Configure Fortanix DSM

A Fortanix DSM service must be configured, and the URL must be accessible. To create a Fortanix DSM account and group, refer to the following sections:

### 4.1 Signing Up

To get started with the Fortanix DSM cloud service, you must register an account at <Your_DSM_Service_URL>. For example, [https://amer.smartkey.io.](https://amer.smartkey.io.) On-premises customers use the KMS URL, and the SaaS customers can use the URLs as listed [*here*](https://support.fortanix.com/hc/en-us/articles/4406135346068-Fortanix-DSM-SaaS-Global-Availability-Map) based on the application region.

*For more information on how to set up the Fortanix DSM, refer to the* [*Sign Up for Fortanix Data Security Manager SaaS*](https://support.fortanix.com/docs/users-guide-sign-up-for-fortanix-data-security-manager-saas)*.*

### 4.2 Creating an Account

Access <Your_DSM_Service_URL> in a web browser and enter your credentials to log in to Fortanix DSM.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/DSM_SaaS_Login_page(15).png)

**Figure 1: Logging in**

*For more information on how to set up an account in Fortanix DSM, refer to the* [*Getting Started with Fortanix Data Security Manager - UI*](https://support.fortanix.com/docs/users-guide-getting-started-with-fortanix-data-security-manager-ui)*.*

## 5.0 Using SaaS Deployment

### 5.1 Creating VMware Instance

Perform the following steps to create an application (app) using the VMware wizard in Fortanix DSM SaaS:

1. Sign up at [https://smartkey.io/](https://smartkey.io/) to access DSM SaaS for the AMER region. DSM SaaS supports multiple regions, as listed [*here*](https://support.fortanix.com/hc/en-us/articles/4406135346068-Fortanix-DSM-SaaS-Global-Availability-Map).
2. In the DSM left navigation panel, click the **Integrations** menu item, and then select the **VMware Encryption and Key Management** check box. Click **ADD INSTANCE** on the **vmware** wizard.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/VM-Instances.png)

**Figure 2: Add vmware instance**
3. On the **Add Instance** page:
  1. **Title**: Enter a name for your instance.
  2. **Authentication method**: Select **API Key**.

> [!NOTE]
> NOTE
> 
> Since you do not have a certificate, you must select **API key** as the authentication method to capture the UUID of the app.
    1. **API Key**: This authenticates the application with the API Gateway.
    2. **Client Certificate**: This authenticates the application with Fortanix DSM using a **Client Certificate**.
  3. **Set app secret key size**: Select the application (app) key size from the available options in bytes.
4. Click **SAVE INSTANCE**.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/image-1768774503378.png)

**Figure 3: Add instance**

This action will automatically create an instance, a new group and app within the Fortanix DSM.

### 5.2 VMware Wizard Instance Detailed View

Navigate to the **Integrations** menu item → **VMware wizard** → VMware instances table. In the instance detailed view page, the following information is represented:

- **CREDENTIALS**: Indicates the method used for app authentication.
  - Click **CERTIFICATE** to download the Client Certificate. This is applicable only if the app authentication method is Client Certificate.
  - Click **COPY API KEY** to view the details of API key, such as username and password. This is applicable only if the app authentication method is API Key.
- **MANAGE KEYS**: Click **MANAGE** to oversee the keys created.
- **INSTANCE STATUS**: To disable the created instance, toggle **Disabled**.
- **DELETE**: To delete the instance, click the overflow menu ![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Screenshot (1342)(5).png) and select **DELETE**. Note that deleting an instance will result in the removal of the app, group, and all security objects associated with the instance, rendering all key material inaccessible.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/image-1768774516353.png)

**Figure 4: Detailed instance**

## 6.0 Using On-Premises Deployment

### 6.1 Creating a Group

Perform the following steps to create a group in the Fortanix DSM:

1. In the DSM left navigation panel, click the **Groups** menu item, and then click **ADD GROUP** to create a new group.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-Group(33).png)

**Figure 5: Add groups**
2. On the **Adding new group** page:
  1. **Title**: Enter a name for your group.
  2. **Description** (optional): Enter a short description of the group.
3. Click **SAVE** to create the new group.

*For more information about groups, refer to* [*Definitions*](/v1/docs/dsm-definitions#40-groups)*.*

> [!NOTE]
> TIP
> 
> It is recommended to configure a **Key undo policy** for groups for the cryptographic keys used by the application before creating or using the keys. Without a configured **Key undo policy**, key deletion is permanent and the deleted key cannot be recovered. Deleting an encryption key may result in permanent loss of access to the protected data and service disruption for applications that depend on the deleted key. *For detailed steps, refer to* [*Key Undo Policy*](/v1/docs/fortanix-dsm-key-undo-policy)*.*

### 6.2 Creating an Application

Perform the following steps to create an application (app) in the Fortanix DSM:

1. In the DSM left navigation panel, click the **Apps** menu item, and then click **ADD APP** to create a new app.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Add-App(31).png)

**Figure 6: Add application**
2. On the **Adding new app** page:
  1. **App name**: Enter the name for your application.
  2. **ADD DESCRIPTION** (optional): Enter a short description of the application.
  3. **Authentication method**: Select the default **API Key** as the authentication method from the drop down menu. *For more information on these authentication methods, refer to the* [*User's Guide: Authentication*](https://support.fortanix.com/docs/users-guide-authentication)*.*
  4. **Assigning the new app to groups**: Select the group created in [*Section 6.1: Creating a Group*](/v1/docs/using-fortanix-data-security-manager-as-a-kms-to-secure-vmware-virtual-environments#61-creating-a-group)[](/v1/docs/using-data-security-manager-with-idcentral-key-management#43-creating-a-group)from the list.
3. Click **SAVE** to add the new application.

*For more information about applications, refer to* [*Definitions*](https://support.fortanix.com/docs/dsm-definitions#50-applications)*.*

### 6.3 Copying the App UUID

Perform the following steps to copy the app UUID from the Fortanix DSM:

1. In the DSM left navigation panel, click the **Apps** menu item, and then click the app created in [*Section 6.2: Creating an Application*](/v1/docs/using-fortanix-data-security-manager-as-a-kms-to-secure-vmware-virtual-environments#62-creating-an-application) [](/v1/docs/using-data-security-manager-with-idcentral-key-management#44-creating-an-application)to go to the detailed view of the app.
2. From the top of the app’s page, click the copy icon ![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/image-1747062862398.png) next to the app **UUID** to copy it to use in [*Section 6.4: Generating the Certificate*](/v1/docs/using-fortanix-data-security-manager-as-a-kms-to-secure-vmware-virtual-environments#80-generating-the-certificate) as the value of Common Name (CN) to generate a self-signed certificate or private key.

### 6.4 Generating the Certificate

Perform the following steps to generate a self-signed certificate or CA certificate such that the CN contains the app UUID:

1. Run the following command to generate a client certificate and create a new `key+cert` with `CN=FORTANIX_APP_UUID`:

```bash
openssl req -newkey rsa:2048 -nodes -keyout sdkms.key -x509 -days 365 -out sdkms.crt
```

Ensure to update certificate parameters such as country, state, organization, so on, and ensure that the common name (CN) is set to the Fortanix app UUID.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/VMware-Virtual-CN.png)

**Figure 7: Generate client certificate**

### 6.5 Updating the Authentication Method

Perform the following steps to change the authentication method:

1. Go to the detailed view of the app created in [*Section 6.2: Creating an Application*](/v1/docs/using-fortanix-data-security-manager-as-a-kms-to-secure-vmware-virtual-environments#62-creating-an-application) and click **Change authentication method** and select **Certificate** to change the authentication method to Certificate.
2. Click **SAVE**.
3. In the **Add certificat**e dialog box, click **UPLOAD NEW CERTIFICATE** to upload the certificate file or paste the content of the certificate generated in [*Section 6.4: Generating the Certificate*](/v1/docs/using-fortanix-data-security-manager-as-a-kms-to-secure-vmware-virtual-environments#80-generating-the-certificate).
4. Select both check boxes to confirm your understanding of the action.
5. Click **UPDATE** to save the changes.

## 7.0 Configure KMS in vCenter Using Certificate

### 7.1 Configuring Fortanix DSM in vCenter

You can configure Fortanix DSM as an external KMS in vCenter using the vSphere Client UI.

1. Log in to vCenter using vSphere Client UI.
2. Navigate to the required project → **Configure** tab → **Key Providers**.

![ClientUI.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/10563347401236.png)

**Figure 8: Key providers tab**
3. On the Key Management **ADD STANDARD KEY PROVIDER** form:
  - **Name:** Name of KMS - **DSM**
  - **Address**: Either the IP address or URL of the Fortanix DSM cluster you are using. For example, SaaS customers can use the following URLs based on the region:
    - Europe: [eu.smartkey.io](https://eu.smartkey.io/)
    - APAC: [apac.smartkey.io](https://apac.smartkey.io/)
    - United States of America: [amer.smartkey.io](https://amer.smartkey.io/)
  - **Port**: **5696**
  - **Username**: to be left blank
  - **Password**: to be left blank

![Region.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/26549446273684.png)

**Figure 9: Add standard key provider dialog box**
4. Click **Add Key Provider**.
5. Click the **Establish Trust** → **Make vCenter Trust KMS** to establish trust between Fortanix DSM and vCenter. Click **TRUST**.

![TrustKMS.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/10563409276308.png)

**Figure 10: Establish trust**

### 7.2 Uploading the Client Certificate

Perform the following steps to upload the client certificate:

1. Copy or upload the vCenter Certificate in the **Upload certificate** text box for the Fortanix DSM app and save the details, generated in [*Section 6.4: Generating the Certificate*](/v1/docs/using-fortanix-data-security-manager-as-a-kms-to-secure-vmware-virtual-environments#80-generating-the-certificate).
2. Log in to the vSphere Client and navigate to **Configure** tab.
3. Create a new Key Management Service:
  - Make it **DEFAULT**.
  - Ensure the fields **User name** and **Password** are empty.

![Vmware-KMS-4.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/360070885652.png)

**Figure 11: Create key management service**

### 7.3 Establishing Trust with Fortanix DSM

Perform the following steps to import the key+cert to vSphere.

1. Navigate to the **ESTABLISH TRUST** tab, select **Make KMS trust vCenter**.
2. In the **Choose a method** section, select the method as **KMS Certificate and Private Key** and click **NEXT**.

![Vmware-KMS5.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/360070885672.png)

**Figure 12: Initiate importing certificate and private key**
3. In the **Establish Trust** section, click **UPLOAD A FILE** to import the certificate and private key. Click **ESTABLISH TRUST**.

![Vmware-KMS6.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/360071069431.png)

**Figure 13: Importing certificate and private key**

## 8.0 Set Up Encrypted VM

Perform the following steps to configure the encrypted VM:

1. Create a VM and select the default **VM Encryption Policy**.

![Vmware-KMS7.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/360071069451.png)

**Figure 14: Create a VM**
2. Click **FINISH** to finalize the VM creation process.

![Vmware-KMS8.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/360071069491.png)

**Figure 15: VM created**
3. Log in to Fortanix DSM to review the logs to monitor the connection, capturing all cryptographic operations performed by the application and any associated key creations.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/VMware-VirtualEnv-1.png)

**Figure 16: Audit logs showing crypto operations**

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/VMware-VirtualEnv-2.png)

**Figure 17: Security object created**

### 8.1 Rotating or Re-encrypting the Keys

In the ever-changing landscape of cybersecurity, the regular rotation and re-encryption of keys are essential to upholding the integrity and security of sensitive data within VMware vSphere 7.0.

Rotating keys involves periodic updates to the cryptographic keys used for encryption, authentication, and other security processes. This proactive approach mitigates the risk of prolonged exposure to potential vulnerabilities. In VMware vSphere 7.0, the seamless rotation of keys ensures that cryptographic materials remain resilient against emerging threats.

Re-encrypting keys is a complementary process that enhances the overall security posture. By periodically updating encryption algorithms or re-encrypting data with stronger cryptographic standards, the defence against evolving cyber threats is fortified. This measure aligns with a commitment to staying ahead of the curve and maintaining the highest standards of data protection.

Implementing a robust key management strategy within VMware vSphere 7.0 demonstrates dedication to cybersecurity best practices. This approach not only safeguards digital assets but also instills confidence in stakeholders, assuring them that top-notch security protocols are adhered to in today's interconnected and dynamic business environment.

Perform the following steps to rotate or re-encrypt the keys in vSphere Client:

1. Select the target VM for the key rotation procedure.

![14.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/24722671993620.png)

**Figure 18: Select re-encrypt**
2. Click **Re-Encrypt** to generate a new key within the Fortanix KMS. The virtual machine then re-encrypts using a new key obtained from the current cluster's default key provider.
3. After the re-encryption process is completed, a newly generated key is added to the KMS interface.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/image-1768774603766.png)

**Figure 19: Key created**

## 9.0 Renewing the VM Trust Certificates

If your KMS certificate is expired, the connection status might change, and VMware shows an error as **Not Connected.**

![error screen.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/17770365373716.png)

**Figure 20: Error screen**

Perform the following steps to renew the VM trust certificates:

1. Log in to the vSphere Client and navigate to **Configure** tab.
2. Locate and click **ESTABLISH TRUST** → **Make KMS trust vCenter** from the drop down menu.
3. In the **Make KMS Trust vCenter** dialog box:
  1. In the **Choose a method** tab, select **KMS certificate and private key**.
  2. Click **NEXT**.
  3. In the **Upload KMS Credentials** tab, upload the KMS certificate and KMS Private Key in the respective fields.
  4. Click **ESTABLISH TRUST**.
4. Locate and click **ESTABLISH TRUST** → **Make vCenter Trust KMS** from the drop down menu.
5. On the **Make vCenter Trust KMS** dialog box, verify the details and click **TRUST** to initiate the renewal of the KMS certificate.

![renew KMS certificate.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/17770351377428.png)

**Figure 21: Renew KMS certificate**
6. After the KMS certificate is updated, click **Trust** to confirm the updated KMS certificates in the prompted dialog box.

![trust button.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/17770351378452.png)

**Figure 22: Trust**

![image (3).png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/17770365377940.png)

**Figure 23: Connection status**
7. If the KMS application certificate has expired, run the following OpenSSL command to generate the new certificate and private key using the same UUID of the app created in [*Section 6.2: Create an Application*](/v1/docs/using-fortanix-data-security-manager-as-a-kms-to-secure-vmware-virtual-environments#62-creating-an-application):

```bash
openssl req -newkey rsa:2048 -nodes -keyout renewsdkms.key -x509 -days 365 -out renewsdkms.crt
```
8. Update the `renewsdkms.crt` to the Fortanix DSM app associated with VMware.
9. Update the same `renewsdkms.crt` and `renewsdkms.key` certificates in VMware.

![image (2).png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/17770365380244.png)

**Figure 24: Upload the certificates**
10. Click **ESTABLISH TRUST**. After the trust is established, the connection is updated as shown in the following figure:

![image.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/17770365389844.png)

**Figure 25: Updated connection status**

*For more information, refer to the* [*Fortanix DSM VSAN KMIP*](https://www.youtube.com/watch?v=Yg8SyXkqnwI) *demo.*

### 9.1 Removing the Fortanix KMS

Perform the following steps to delete the Fortanix KMS from VMware:

1. Select the VM machine from where the encryption needs to be removed.
2. Navigate to the **Summary** tab, select **VM policies** → **Edit Storage Policies** from the nested menu.

![22.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/24722997617172.png)

**Figure 26: VM policies**
3. On the **Edit VM Storage Policies** page, select the **Datastore Default** from the drop down menu.

![23.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/24723012581652.png)

**Figure 27: Datastore default**
4. Click **OK** to confirm the action.

The datastore is reconfigured and the VM is un-encrypted.

![24.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/24723037532820.png)

**Figure 28: Select encryption**

### 9.2 Migrate the Virtual Machine Disk File

This section illustrates the following steps to effectively migrate a Virtual Machine Disk (VMDK) file from one vCenter to another, ensuring consistency in KMS settings and seamless restoration with key retrieval from the Fortanix KMS.

Perform the following steps:

1. Locate and copy the VMDK file from the datastore or storage associated with vCenter 1.
2. Reconfigure the vCenter 2 with the same KMS Name, Endpoint and Certificate at vCenter 2.

![25.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/24724436675732.png)

**Figure 29: Reconfigure the vCenter**
3. Paste the copied VMDK file into the datastore or storage of vCenter 2.

![26.png](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/24724436690964.png)

**Figure 30: Edit key provider**
4. After restoring the VMDK file in vCenter 2, the key will be automatically fetched from the Fortanix KMS.

### 9.3 Virtual Trusted Platform Module with Fortanix DSM

A Virtual Trusted Platform Module (vTPM) is a software version of a hardware TPM, a chip designed to enhance hardware security using integrated cryptographic keys. In VMware environments, vTPM offers the same security features for virtual machines (VMs) that physical TPMs provide for physical machines, enhancing VM security with encryption, secure boot, and other advanced security capabilities.

#### 9.3.1 Key Benefits

- **Enhanced Security**: vTPM boosts VM security with features like measured boot, ensuring the VM starts in a trusted state.
- **Compliance**: vTPM aids in meeting security compliance requirements that mandate TPM use.
- **Encryption Suppor**t: vTPM supports full-disk encryption and other cryptographic operations.
- **Platform Integrity**: vTPM maintains the integrity of the virtual platform by validating the boot process and safeguarding sensitive data.

#### 9.3.2 Setting Up vTPM in VMware

1. VMware vSphere Prerequisites:
  - **vSphere Version**: vSphere 6.7 or later must be installed.
  - **ESXi Host**: Virtual hardware version 14 or later must be supported.
2. Prerequisites for configuring vTPM:
  - **Firmware**: Set the VM's firmware to UEFI.
  - **Key Management**: Optionally, configure key management services (KMS) for key handling and encryption operations.
3. Enabling vTPM:
  1. Create a new VM or power off an existing VM.
  2. In the **vSphere Client** window, right-click the VM and select **Edit Settings**.
  3. Navigate to the **Virtual Hardware** tab, click **ADD NEW DEVICE**, and select **Trusted Platform Module** from the drop down menu.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/Screenshot (273).png)

**Figure 31: Trusted platform module**
  4. Click **OK** to save the settings and turn on the VM.
  5. After adding vTPM and powering on the VM, review the key in Fortanix Key Management. To view the details about the key, log into the Fortanix DSM UI and navigate to **Security Objects** menu item → select the required key → **ATTRIBUTES/TAGS** tab.

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/image-1768774820608.png)

**Figure 32: New KMIP key is created**

![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/image-1768774837525.png)

**Figure 33: Attributes or tags of the security object**

## 10.0 Troubleshooting and Support

| PROBLEM | RESOLUTION |
| --- | --- |
| Error “Cannot find Key” or “Unable to start or re-encrypt" after successful certificate renewal and establishing Trust with Fortanix DSM. | Check the newly generated certificate (DSM UI **→** **Apps →** **View Certificate**) and if the CN name entered does not look like the figure below (value of CN should be the UUID, not “CN=xxx”), ![](https://cdn.us.document360.io/c3bd85d2-4ad8-4d85-9f60-f1c168a3aad9/Images/Documentation/VMware-Virtual-CNNameTroubleshooting.png) Correct the CN name as created in [*Section 6.4: Generating the Certificate*](/v1/docs/using-fortanix-data-security-manager-as-a-kms-to-secure-vmware-virtual-environments#80-generating-the-certificate). |

Fortanix Data Security Manager (DSM) is the world’s first cloud service secured with Intel® SGX. With Fortanix DSM, you can securely generate, store, and use cryptographic keys and certificates, as well as other secrets such as passwords, API keys, tokens, or any blob of data. Your business-critical applications and containers can integrate with Fortanix DSM using legacy cryptographic interfaces (PKCS#11, CNG, and JCE) or using the native Fortanix DSM RESTful interface.

## Related

- [Command-Line Interface (CLI) for Fortanix DSM (sdkms-cli)](/fortanix-dsm-clients-command-line-interface-cli.md)
- [Fortanix DSM with Keyfactor EJBCA (Primekey)](/fortanix-dsm-with-keyfactor-ejbca-primekey.md)
- [Fortanix DSM with Microsoft PKI](/fortanix-dsm-with-microsoft-pki.md)
- [Fortanix DSM with Scality S3C](/fortanix-dsm-with-scality-s3c.md)
