1.0 Introduction
This document describes the Manual Import connection concepts and supported features in Fortanix Key Insight. Fortanix Key Insight enables you to apply uniform key lifecycle management policies and processes to cryptographic key management systems.
2.0 Concepts
The following table summarizes the Manual Import connection concepts used in Fortanix Key Insight:
CONCEPT | DESCRIPTION |
|---|---|
Manual Import Connection | Fortanix Key Insight allows you to manually import cryptographic keys and other cryptographic assets to discover and map keys to the resources they protect. |
Key Discovery | The process of scanning the cryptographic keys from the uploaded file. Fortanix Key Insight provides a key discovery report based on the manually imported data to analyze the usage of keys, certificates, and resources. |
Keys | Keys are the primary resource in a manual import connection and represent cryptographic keys. Each key is assigned a unique key identifier or key ID. Fortanix Key Insight scans all keys in the uploaded file and evaluates their compliance status. |
Resources | Resources represent the services or resources associated with the cryptographic keys imported through the CSV or CBOM file. Fortanix Key Insight displays the resources and services provided in the imported file without automatically detecting the cloud provider, environment, or resource type. |
Certificates | Certificates are digital credentials used to authenticate machines, applications, and resources using SSL/TLS. For manual import connections, Fortanix Key Insight analyses certificates provided through the imported file to assess certificate details and compliance status. Fortanix Key Insight evaluates manually imported certificates to identify risks such as expiration, weak algorithms, and non-compliant configurations. |
Cryptographic Assets | Cryptographic assets include manually imported keys, certificates, and resources. Fortanix Key Insight provides a centralized inventory of these assets, enabling visibility, risk assessment, and compliance monitoring. |
3.0 Supported features
The Fortanix Key Insight Manual Import connection supports the following features:
Supports selecting a region (European Union (EU) or North America (NA)) when accessing Fortanix Key Insight SaaS from Fortanix Armor. All scanned data is displayed in the Key Insight UI based on the selected region, enabling region-specific data handling, reporting, and visualization while supporting compliance and governance requirements.
NOTE
The Region field is available only in the Fortanix Key Insight Software-as-a-Service (SaaS) environment. It is not displayed in the on-premises user interface.
Allows users to manually upload and scan cryptographic assets, such as keys, certificates, and resource encryption data, from a CSV or CBOM file. The scan determines which resources are encrypted, which keys were used for encryption, and the status of those keys and certificates.
Provides a dashboard view of manually imported cryptographic key, certificate, and resource compliance status across multiple resources.
The dashboard shows the following information:
Scanned resources, certificates, and keys
Cryptography Bill of Materials (CBOM) import and export
Protected resources
Key types
Key by status
Key source
Certificate by status
Certificate by algorithm types
Generates reports on non-compliant keys, certificates, and resources.
The assessment report shows the following information:
The risk score
Top security issues
Resource violations
Certificate expiry by issuers
Certificate by violation type
Post Quantum Cryptography (PQC) readiness of keys, resources, and certificates
For each key in a manual import connection,
Provides a tabular view that shows the key details such as key identifier, key source, key state, key violations, key algorithm, expiration date, creation date, key rotation status, next rotation date, and so on.
Displays a map of the key compliance statuses.
Detects non-compliant keys based on the applied policies and issues vulnerability alerts according to NIST standards.
Provides essential information such as key properties, key owner(s), rotation details, resource mappings, and related violations.
For each resource in a manual import connection,
Displays a comprehensive overview that allows you to filter resources by type, violations, encryption status, and key data. You can click on each resource to view a detailed list of associated vulnerabilities, if applicable.
Offers a tabular view showing resource information such as the resource identifier, resource type, violations, encryption status, key name, and key ID.
Provides detailed insights into resource configurations and any violations associated with each resource, helping you to understand potential issues and compliance gaps.
NOTE
For Manual Import connections, the RESOURCE IDENTIFIER and RESOURCE TYPE values are based on the information provided in the imported CSV or CBOM file.
For each certificate in a manual import connection,
Provides a tabular view that shows the certificate details, such as certificate name, status, serial number, issuer, key algorithm, description, creation date, and so on. You can filter the specific certificates based on the requirement.
Displays a map of the certificate compliance status.
Detects non-compliant certificates based on the applied policy and issues vulnerability alerts according to NIST standards.
Provides essential information such as certificate properties, owner(s), domain name, Subject Alternative Name (SAN), resource mappings, and related violations.
Allows users to import the CBOM or CSV file containing encryption keys and cryptographic assets into Key Insight to assess risk, compliance, and key lifecycle status.
NOTE
CBOMs exported from connections cannot be manually imported into Fortanix Key Insight. Manual import is supported only for CBOMs that use the provided CSV or JSON templates.
Allows users to export all scanned keys, certificates, and resource data in comma-separated values (CSV) format and provides the ability to track export activities.
Allows users to export all scanned keys, certificates, and resource metadata in CBOM-compliant JSON format to track post-quantum readiness and cryptographic risk.
Allows users to create and manage user-defined policies, duplicate and modify system-defined, Fortanix DSM, or existing user-defined policies, and automatically retrieve cryptographic policies from Fortanix DSM to apply them to scanned connections.
Provides an assessment report that identifies vulnerabilities by providing a snapshot of your data security posture and risk score, highlighting areas of strength, and pinpointing opportunities for improvement.
Provides a dashboard for assessing Manual Import connection Post-Quantum Cryptography (PQC) readiness, featuring a sunburst chart layout that simplifies the visualization of keys, resources, and certificates data points, and includes drill-down capabilities for deeper insights.