1.0 Introduction
This document describes how to create a Manual Import connection in Fortanix Key Insight to scan cryptographic assets, including keys, resources, and certificates.
2.0 Terminology References
For Manual Import connection concepts and supported features, refer to Manual Import Concepts.
3.0 Start the Connection Setup
Before configuring a Manual Import connection, ensure you can access Fortanix Key Insight.
For information about signing up for Fortanix Armor, creating an Armor account, and accessing Fortanix Key Insight, refer to Getting Started with Key Insight.
You can start the connection setup when you first access Fortanix Key Insight or after you have entered the application.
First-time users: When you access Fortanix Key Insight for the first time, the connection setup wizard is displayed automatically. Proceed to Section 4.0: Select connection type to upload the files for the Manual Import connection.
Existing users: In Fortanix Key Insight, go to Configuration → Connections → MANUAL IMPORT → MANUAL IMPORT CONNECTION. Proceed to Section 5.0: Manual Import File to upload the files for the Manual Import connection.
4.0 Select Connection Type
Perform the following steps to select the connection type:
On the Select Connection Type step, under Select scan type, select Manual Import.
Click CONTINUE WITH MANUAL IMPORT and proceed to Section 5.0: Manual Import File to upload a file for manual import.
.png?sv=2026-02-06&spr=https&st=2026-10-09T03%3A56%3A45Z&se=2026-10-09T04%3A12%3A45Z&sr=c&sp=r&sig=b9ZhfOMjPuuJ%2FDOiqAhpKZ7QwHV%2Bklz%2BiK72Yf7c8l0%3D)
Figure 1: Select Manual Import
NOTE
Use manual import for cryptographic assets that cannot be discovered automatically (for example, keys in SaaS or air-gapped environments).
Import key metadata into cryptographic assets Insight to assess risk, compliance, and key lifecycle status.
Upload one or more keys in the supported CBOM or CSV format.
5.0 Manual Import File
Perform the following steps to upload a Manual Import file:
On the Manual Import File step:
In Connection name, enter a name for the Manual Import connection.
Click CSV or CBOM to download the sample template in the selected format.
A sample file named
manual_import_cbom_template.jsonormanual_import_csv_template.csvis downloaded to your local system.
Figure 2: Manual Import File step
Open the downloaded template and enter the required details in the appropriate fields.
For a list of supported algorithms, refer below:
Supported Algorithms
Fortanix Key Insight supports the following algorithms for manual CBOM import:
MAC Algorithms
HMAC-SHA
Block Cipher Algorithms
AES
ARIA
DES
3DES
RC2
Signature Algorithms
EC Curves
P-256
P-384
Ed25519
secp256k1
ED25519
ML-DSA
PKE Algorithms
RSA
KDF Algorithms
Argon2i
Argon2d
Argon2id
KEM Algorithms
SIKE
ML-KEM
AE Algorithms
ChaCha20-Poly1305
Drag and drop the completed file into the upload area or click Browse to select the file from your local system.
NOTE
CBOMs exported from connections cannot be manually imported into Fortanix Key Insight. Manual import is supported only for CBOMs that use the provided CSV or JSON templates.
A maximum of one file can be uploaded per connection.
The file size should not exceed 2 MB.
The uploaded file is validated before it is imported. The validation process may take several minutes, depending on the file size.
Click NEXT.
6.0 Select Key Insight Policy
The System Defined Policy is selected by default on the Key Insight Policy step. This policy is designed to facilitate the scanning of keys, certificates, and resources based on predefined key sizes and permitted operations, ensuring compliance with standard security configurations.
Click FINISH to complete the Manual Import connection onboarding.

Figure 3: Select Key Insight policy
Additionally,
Click ADD POLICY to add a new user-defined policy to the policy center.
Click
to copy and modify a system-defined policy, converting it into a user-defined policy.
For more information on Fortanix Key Insight policies and features, refer to Cryptographic Policy Management.
NOTE
Key Insight scans the uploaded file, extracts keys, certificates, and resources, checks the compliance policy, and prepares the dashboard. This process may take some time. The system notifies you when the scan is complete.
7.0 Review Upload and Scan Results
After you upload the file, Key Insight validates the file, scans the assets, and prepares the imported data for display.
7.1 Review the Upload Results
If the file upload succeeds, the success message Upload <file_name> for <connection_name> completed appears. Where <file_name> is the name of the Manual Import file and <connecton_name> is the name of the Manual Import connection.
Click VIEW DETAILS in the top-right corner of the screen to view the details of the latest import.
.png?sv=2026-02-06&spr=https&st=2026-10-09T03%3A56%3A45Z&se=2026-10-09T04%3A12%3A45Z&sr=c&sp=r&sig=b9ZhfOMjPuuJ%2FDOiqAhpKZ7QwHV%2Bklz%2BiK72Yf7c8l0%3D)
Figure 4: View Details option
7.2 If the File Upload Fails
If the file upload fails because of an incorrect file format or network issue, the Upload <file_name> for <connection_name> failed message appears with the reason for the failure. Where <file_name> is the name of the Manual Import file and <connection_name> is the name of the Manual Import connection.
Perform the following steps to upload the file again:
Verify that you are using the correct file format.
Click UPLOAD FILE.
.png?sv=2026-02-06&spr=https&st=2026-10-09T03%3A56%3A45Z&se=2026-10-09T04%3A12%3A45Z&sr=c&sp=r&sig=b9ZhfOMjPuuJ%2FDOiqAhpKZ7QwHV%2Bklz%2BiK72Yf7c8l0%3D)
Figure 5: Upload file
Drag and drop the completed file into the upload area or click Browse to select the file from your local system.
Click UPLOAD.
Key Insight validates and uploads the file.
7.3 If Some Assets Failed to Import
If some assets failed to import, review the details of the failed assets, update the import file as required, and reimport the file.
Perform the following steps to review the failed assets and reimport the file:
Click VIEW DETAILS to review the details of the latest import.
Click DOWNLOAD to download the records that failed to import.
.png?sv=2026-02-06&spr=https&st=2026-10-09T03%3A56%3A45Z&se=2026-10-09T04%3A12%3A45Z&sr=c&sp=r&sig=b9ZhfOMjPuuJ%2FDOiqAhpKZ7QwHV%2Bklz%2BiK72Yf7c8l0%3D)
Figure 6: Download record
NOTE
The downloaded report lists the assets that failed to import and provides the reason for each failure.
When you reimport the assets, upload the file containing all the assets, not only the assets that failed to import.
Update the failed assets information in the import file as required.
On the Overview page, in the CBOM section, click IMPORT in the lower-right corner to upload the updated file. For more information, refer to Import Assets.
7.4 If the File Scan Fails
If the scan has failed because of a technical issue or network error, the message File scan failed appears.
Perform the following steps to upload the file again:
Verify that you are using the correct file format.
Click UPLOAD FILE.
.png?sv=2026-02-06&spr=https&st=2026-10-09T03%3A56%3A45Z&se=2026-10-09T04%3A12%3A45Z&sr=c&sp=r&sig=b9ZhfOMjPuuJ%2FDOiqAhpKZ7QwHV%2Bklz%2BiK72Yf7c8l0%3D)
Figure 7: Upload file
Drag and drop the completed file into the upload area or click Browse to select the file from your local system.
Click UPLOAD.
8.0 View the Manual Import Connection
After onboarding the manual import connection, you can view the Manual Import connection data and scan results on the following pages:
Overview
Assessment
Keys
Resources
Certificates
.png?sv=2026-02-06&spr=https&st=2026-10-09T03%3A56%3A45Z&se=2026-10-09T04%3A12%3A45Z&sr=c&sp=r&sig=b9ZhfOMjPuuJ%2FDOiqAhpKZ7QwHV%2Bklz%2BiK72Yf7c8l0%3D)
Figure 8: Manual Import connection
You can switch regions at any time using the Region drop down in the top navigation bar. When you change the region, the user interface (UI) automatically updates to show the data, connections, and scan results for the selected region.
For more information about the Manual Import connection UI, refer to Manual Import Connection - User Interface Components.
NOTE
The Region field is available only in the Fortanix Key Insight Software-as-a-Service (SaaS) environment. It is not displayed in the on-premises user interface.
Users with the Account Administrator or Group Administrator roles can manage (edit and delete) the connection from the Configuration → Connections → MANUAL IMPORT.
Deleting the Manual Import connection cannot be undone.
A group with the same name is created on the Fortanix IAM Groups page. For more information, refer to Fortanix Armor Identity and Access Management (IAM).