Key management server requirements
If you are using a key management server, it must meet the following requirements:
Protocol: Key Management Interoperability Protocol 1.0 (KMIP1.0)
Software: SafeNet KeySecure k460 6.4.1 or Thales keyAuthority 4.0.2
Certificates:
Root certificate of the key management server (X.509)
Client certificate in PKCS#12 format
Configuration: Two clustered servers, if you want to protect key encryption keys.