====== KMIP Server (PyKMIP) ======
* Install Phyton3, the Phyton package manager and dependencies:sudo apt update
sudo apt install python3 python3-pip python3-venv libssl-dev libffi-dev python3-dev libsqlite3-dev
* Verify the installation:pip3 --version
* Create a virtual environment and activate it:python3 -m venv pykmip-env
source pykmip-env/bin/activate
* To deactivate the virtual environment, enter ''deactivate'' within the virtual environment
* To manage packages you can use:pip3 install package_name
pip3 install --upgrade package_name
pip3 uninstall package_name
* Once inside your virtual environment, upgrade ''pip'' and install the ''pykmip'' library:pip install --upgrade pip
pip install pykmip
* Verify the installation:python3 -c "import kmip; print(kmip.__version__)"
* Create folder ''/var/log/pykmip'' with ownership ''root:user'' and permissions ''770''
* Start the server:pykmip-server
* Create the certificates as described in [[syno:dsm7kmip#certificates|KMIP for key management]] and copy them to ''/home/user/certs/''. They keys generated through the Synology script are valid for 10 years.
* Create the configuration file ''/home/user/pykmip-env/server.conf'':[server]
host = 0.0.0.0
port = 5696
certificate_path = ./certs/server.pem
key_path = ./certs/server-key.pem
ca_path = ./certs/ca.pem
auth_suite = TLS1.2
logging_level = INFO
database_path=/var/lib/pykmip/pykmip.db
* Create folder ''/etc/pykmip/'' and establish a symbolic link to the server configuration:ln -s /home/user/pykmip-env/server.conf /etc/pykmip/server.conf
* Add a firewall rule to allow port 5696:sudo ufw allow from client.wan.ip.addr to any port 5696 proto tcp
* To automate setting up and activating a Python virtual environment, use ''direnv'':sudo apt update
sudo apt install direnv
* Hook ''direnv'' to your shell by adding the following line to your shell configuration file as first instruction in the file:vim ~/.bashrc
eval "$(direnv hook bash)"
* Create a config file inside the project folder telling ''direnv'' to load Python:echo "layout python" > ~/pykmip-env/.envrc
* Authorize the script to run safely:direnv allow
* Logout then login and cd to ''~/pykmip-env/'' then start the KMIP Server in the background:cd ~/pykmip-env
pykmip-server&
* It is better not to add the server to systemd, so you start and stop consciously. To stop the server, find it's process id then kill the process gracefully:ps aux | grep kmip
sudo kill -TERM ''ps'' will list 3 processes, it is sufficient to kill the first one listed