VMware vSphere

 View Only

 Installing a Native Key Provider has failed

Werner Zeller's profile image
Werner Zeller posted Mar 04, 2025 09:43 AM

Hi, I want to add a Native Keyprovider for a Win11 VM on vCenter 8U3. After setting the password and click Backup Key Provider, I get an error Backup of a Native Provider has failed. I googled a lot, but coudn't find anything suitable. I am using vCenter V8U3 and esxi (8U3 Hosts).

What am doing wrong?

Thanks for your help!

a_p_'s profile image
a_p_

What did you try so far?

Most search results suggest that it is either an issue with the vCenter Server's hostname, or with accessing the URL other than with the vCneter Server's FQDN.

see e.g. Unable to Backup Native Key Provider when VMware vCenter unset Hostname.

André

Werner Zeller's profile image
Werner Zeller

Hi André, Thanks! If I can't find a solution, I will have to reinstall vCenter for better or worse. Does this error with NKP affect the hosts, which are different, different processor types, with and without TPM2, I also have no shared storage (home automation with mini PC's).

with Bash, and without:

Pre-authentication banner message from server:
|
| VMware vCenter Server 8.0.3.00400
|
| Type: vCenter Server with an embedded Platform Services Controller
|
End of banner message from server
Keyboard-interactive authentication prompts from server:
| Password:
End of keyboard-interactive prompts from server
Connected to service

    * List APIs: "help api list"
    * List Plugins: "help pi list"
    * Launch BASH: "shell"

Command> dcli com vmware vcenter cryptomanager kms providers export --provider NKP
Username: administrator@vsphereHM.local
Password: ********
Do you want to save credentials in the credstore? (y or n) [y]:
Error: Unable to authenticate user. Please enter the credentials again.
Username: administrator@vsphereHM.local
Password:
Do you want to save credentials in the credstore? (y or n) [y]:y
Server error: com.vmware.vapi.std.errors.Unauthenticated
Command> dcli com vmware vcenter cryptomanager kms providers export --provider NKP
Username: root
Password: ************
Do you want to save credentials in the credstore? (y or n) [y]:y
Server error: com.vmware.vapi.std.errors.Unauthorized
Error message:
    The following (object: com.vmware.vcenter.crypto_manager.kms.providers.export privileges: Cryptographer.ManageKeyServers) privileges are insufficient to user
Command>
Command> shell
Shell access is granted to root
root@VCSAHM [ ~ ]#
root@VCSAHM [ ~ ]# dcli com vmware vcenter cryptomanager kms providers export --provider NKP
Server error: com.vmware.vapi.std.errors.Unauthorized
Error message:
    The following (object: com.vmware.vcenter.crypto_manager.kms.providers.export privileges: Cryptographer.ManageKeyServers) privileges are insufficient to user
root@VCSAHM [ ~ ]#