This article provides an overview of the new features, improvements, and on-premises scanner updates in the Fortanix Key Insight 25.07 release.
1.0 New Features
Added the new violation type Cross Account Key Usage for AWS connections, enhancing visibility into the state of keys with historical cross-account access (JIRA: KI-2338).
The new key status type Cross Account Key Usage is added on the Overview page.
The violation is added to the Risk Score, Service Violations and Top Security Issues sections of the Assessment page.
You can filter keys and services using this violation.
For more information, refer to Fortanix Key Insight User Interface Components – AWS.
Fortanix Key Insight now allows account administrators to add certificate ownership details for AWS connection, thereby improving certificate management, enhancing tracking, and streamlining remediation workflows (JIRA: KI-2604).
As an account administrator, on the Certificates page,
You can add primary and secondary owners for selected certificate(s) using the ADD DETAILS option by providing either the name or employee ID and email address.
You can update existing certificate details with primary and secondary owners using the EDIT DETAILS option, either on the certificate details page or from the certificate list.
For more information, refer to Fortanix Key Insight User Interface Components – AWS.
Fortanix Key Insight now supports grouping Post-Quantum Cryptography (PQC) vulnerabilities by Certificates in AWS connection on PQC Central page (JIRA: KI-2627).
For AWS connections, the PQC dashboard provides a detailed breakdown of Post-Quantum Readiness and PQC Vulnerabilities by Cryptographic Assets associated with certificates. The drill-down views offer deeper insights to support informed remediation and strategic planning.
A guided tour is now available the first time you access the PQC Central page on Fortanix Key Insight, helping you quickly understand its key capabilities.
For more information, refer to Fortanix Key Insight User Interface Components - PQC Central.
AWS key aliases details are now displayed on the Keys page and the Key Details page, providing clearer identification and improved context for each key. Additionally, users can now search for keys using AWS Key Aliases, simplifying key discovery and improving overall workflow efficiency (JIRA: KI-2387).
For more information, refer to Fortanix Key Insight User Interface Components - AWS.
Fortanix Key Insight now provides a clear distinction between Platform Managed Key and Customer Managed Key when configuring AWS and Azure connections (JIRA: KI-2760).
For an AWS and Azure connection,
Added Platform managed keys and Customer managed keys under Keys by Status section on the Overview page.
Added Services using Platform Managed Keys under the Top Security Issues on the Assessment page.
Added the Key managed by filter to the AWS list view, along with the corresponding label in the key and service details panels for both AWS and Azure.
For more information, refer to the following:
Fortanix Key Insight now displays External Key Store (XKS) details on the Keys details page for AWS keys. Users can also filter and search keys by External Key Store Name and External Key Store ID, improving visibility and management of XKS-integrated keys (JIRA: KI-2751).
For more information, refer to Fortanix Key Insight User Interface Components - AWS.
Fortanix Key Insight now supports Cryptography Bill of Materials (CBOM) export in CBOM JSON format, adhering to the CycloneDX standard, for cryptographic assets discovered across cloud environments (AWS, Azure), on-premises deployments, and external key sources such as Fortanix DSM (JIRA: KI-2603).
This enables organizations to maintain a comprehensive cryptographic inventory, demonstrate regulatory compliance, and evaluate Post-Quantum Cryptography (PQC) readiness.
For more information, refer to the following:
2.0 Improvements
The Azure connection keys filter list is now updated to include Key Id as a filter criterion. Users can now easily search and filter Azure keys using the Key Id, allowing for more precise key management and improved usability (JIRA: KI-2756).
For more information, refer to Fortanix Key Insight User Interface Components - Azure.
The Overview pages for Azure and AWS connections have been streamlined for improved clarity and usability (JIRA: KI-2858).
The Top Subscriptions That Need Attention section has been removed from the Azure Overview page.
The Accounts Requiring Attention section has been removed from the AWS Overview page.
The remaining sections have been reorganized to provide a cleaner layout.
For more information, refer to the following:
Added the PQC Readiness section and removed the existing Quantum-Vulnerable Keys section from the AWS, Azure, and On-Premises Assessment pages (JIRA: KI-3114).
For more information, refer to the following:
The LIST view is now the default view instead of GRAPH for the Keys and Services pages in Fortanix Key Insight for AWS and Azure cloud connections (JIRA: KI-3242).
For more information, refer to the following:
Improved user interface (UI) consistency, enhanced metadata visibility, and refined data presentation across Azure, On-Premises, and External Key Source (Fortanix DSM) connections (JIRA: KI-3273).
Azure
Renamed the Type column to Key Spec for consistent labeling across Keys list views.
Added Resource Group information to both the CSV export and the Keys details page.
On-Premises
On the Keys list, renamed the Key Algorithm column to Key Spec for alignment with Azure.
Enhanced the Keys details page to include Key Spec, Key Name, Key Category, Source, and Host fields.
Updated the Key Version field on the Keys details page to show a template message when empty, replacing the placeholder "--".
Renamed Key Usage to DB Type on the Keys details page for improved clarity.
Removed zero-value entries from the Scanned Resources section on the Overview page to reduce visual clutter.
External Key Source (Fortanix DSM)
Enhanced the Keys details page to include Key Curve and Key Description.
Renamed Key Type to Object Type on the Keys details page to match the corresponding table column header.
For more information, refer to the following:
Enhanced the Keys page filters for Microsoft SQL (MS SQL) Server databases in Fortanix Key Insight On-Premises connections to support additional filter values (JIRA: KI-3299).
Key Source: Azure Key Vault, Native Encryption
Key Category: Asymmetric Key
For more information, refer to Fortanix Key Insight - On-premises User Interface Components for Databases.
3.0 On-Premises Scanner Updates
Improved error handling in the Fortanix Key Insight On-Premises scanner to log detailed diagnostics for failed database connections, while continuing to scan other valid databases in the same configuration file (JIRA: KI-3092).
4.0 Installation
To install the latest Fortanix Key Insight On-Premises connection scanner package, click here.