1.0 Introduction
The article describes the Fortanix Key Insight user interface (UI) features for an on-premises Network infrastructure.
2.0 Terminology References
For Fortanix Key Insight on-premises connection concepts and supported features, refer to On-premises Connection Concepts.
3.0 Overview
The on-premises connection Overview page appears after adding an on-premises connection.
The Overview page displays the scanned cryptographic assets count based on the applied Fortanix Key Insight policy.
For more information on the Fortanix Key Insight policy, refer to Cryptographic Policy Management.

Figure 1: Networks overview
NOTE
If the Overview page for networks does not display any data, configure the Fortanix On-premises Scanner. For more information, refer to On-premises Scanner Configuration.
In the networks UI, the order of tabs depends on the availability of resources in each tab (DATABASES, SOURCE CODE, CONTAINERS, NETWORKS, and FILE SYSTEMS). You will always see results in the first tab that has scanned data available. If no data is present at connection level, the default order is FILE SYSTEMS > DATABASES > SOURCE CODE > CONTAINERS > NETWORKS.
If your Fortanix Armor account is deactivated and you are accessing the Fortanix Key Insight On-premises connection for networks, you will not be able to view data under the Overview, Assessments, Keys, Resources, Certificates, Cryptographic Assets, or PQC Central pages. You will only have access to view and delete items within the Connections, Policy Center, and Authentication pages.
Click RESCAN to rescan the on-premises connection. For more information, refer to Section 5.0: Rescan an On-premises Connection.
Click ASSESSMENT REPORT to navigate to the Assessment page.
Click GO TO CRYPTOGRAPHIC ASSETS to navigate to the Cryptographic Assets page. For more information, refer to Section 6.0: Cryptographic Assets.
The Overview page is described in the following sections:
3.1 Discovered On-Premises Resources
This section provides the count of scanned on-premises infrastructures, including databases, file systems, source code repositories, and container images.
It also displays the count of the following in the scanned on-premises infrastructures:
Cryptographic assets
Keys
Certificates
Resources
NOTE
The total number of cryptographic assets includes those discovered through associated network scans, if any.
The total number of keys displayed in the Discovered On-premises Resources section is only the count of the “Current” key versions in the on-premises infrastructures.
Clicking the Cryptographic Assets, Keys, Certificates, and Resources labels navigates you to their list view.
3.2 Cryptography Bill of Materials (CBOM)
Currently, CBOM export is not supported for Networks. Therefore, the exported data does not include details of cryptographic assets scanned from Networks.
4.0 Assessments
After adding an on-premises connection, you can access the Fortanix Key Insight Assessment page from the left navigation panel.

Figure 2: On-Premises Networks assessment report
Click GO TO CRYPTOGRAPHIC ASSETS to navigate to the Cryptographic Assets page. For more information, refer to Section 6.0: Cryptographic Assets.
5.0 Rescan an On-Premises Connection
Click RESCAN on the top-right corner of the Overview or Assessment page to perform a rescan and verify if any keys have been added, deleted, or updated in the Fortanix On-premises Scanner.
If you click RESCAN and start the scan, you can monitor its progress in the progress bar. After the scan is completed successfully, the Last scanned label will be updated with the completion date and time.
NOTE
The RESCAN option is accessible only to users with the Account Administrator and Group Administrator roles.
The RESCAN option is available only when the on-premises connection status is Connected.
6.0 Cryptographic Assets
After onboarding an on-premises connection with network assets, navigate to the NETWORKS tab under Cryptographic Assets on the Fortanix Key Insight left navigation panel to view all scanned cryptographic assets.
The scanned cryptographic assets are categorized into the following sections:
X509

Figure 3: X509 cryptographic assets
TLS

Figure 4: TLS cryptographic assets
HTTP AND DNS

Figure 5: HTTP and DNS cryptographic assets
For each cryptographic asset:
Click EXPORT to export the scanned cryptographic assets data. For more information, refer to Section 7.0: Export Scanned Data.
Use the Search field to filter the cryptographic assets based on the available criteria and supported values:
For example,
UID
TLS Version
6.1 View Cryptographic Asset Details
NOTE
The VIOLATIONS tab currently does not display any data.
6.1.1 X509
Click a cryptographic asset under the X509 tab to view its properties and associated violations.
The CRYPTOGRAPHIC ASSET DETAILS tab displays the cryptographic asset properties, host, and Subject Alternative Names (SANs) details.

Figure 6: X509 cryptographic assets details
6.1.2 TLS
Click a cryptographic asset under the TLS tab to view its properties and associated violations.
The CRYPTOGRAPHIC ASSET DETAILS tab displays the cryptographic asset properties and host details.

Figure 7: TLS cryptographic assets details
6.1.3 HTTP and DNS
Click a cryptographic asset under the HTTP AND DNS tab to view its properties and associated violations.
NOTE
Use the Asset Type filter to distinguish between HTTP and DNS cryptographic details.
The CRYPTOGRAPHIC ASSET DETAILS tab displays the cryptographic asset properties and host details.

Figure 8: HTTP and DNS cryptographic assets details
7.0 Export Scanned Data
This feature allows you to export the scanned assets from Fortanix Key Insight in Comma-Separated Values (CSV) format. Also, it provides flexibility, enabling you to download data for detailed analysis, audits, or reporting, and to access real-time status.
In the on-premises network’s Cryptographic Assets list view, click EXPORT to export the scanned data using any of the available options:

Figure 9: Access Data Export feature
Export current page: Use this option to export all column data from the current page in CSV format.
NOTE
You can download a maximum of 100 items at a time, based on the settings specified in the Items per page drop down.
Export all raw data: Use this option to export all scanned data in CSV format. Review the details in the Export All Raw Data dialog box and click PROCEED to start the export.
After the export process begins, you can track its progress. The export status will be logged with a message under the Activities tab in Fortanix Key Insight. For more information, refer to Section 7.1: View Export Activities.
Export selected rows: This option is disabled by default. Select the check box (
) next to the required rows on the current page and then use this option to export only those rows in CSV format.
NOTE
Users with the Account Administrator and Group Administrator roles can only perform the scanned data export.
Within a single account, multiple exports can run concurrently across different connections (cloud, on-premises, external key sources, and vendor applications).
7.1 View Export Activities
After you initiate the export process using Export All Raw Data, you can track the export status in the Activities menu located in the left navigation panel.
The following details are available for each export activity:
Name of the activity.
Name of the file. For example, Network-X509-Cryptographic-Assets.csv.
Activity status indicates the current state of the data export.
This can be any of the following:
Completed: The data export has been completed, and the CSV file will automatically download to the location specified on your local machine.
In Progress: The data export is in progress, and you can cancel it using
if required.Cancelled: The data export was cancelled, either manually or due to switching accounts while the export was in progress.
Failed: The data export did not complete successfully due to errors.
Name of the connection
Export creation date and time

Figure 10: Access Network activities
NOTE
If you switch to a different account during export, the export will be cancelled and logged in the Activities tab.
If you navigate to a different solution (for example, Fortanix Identity and Access Management (IAM)), the export will continue, but no logs will appear in the Activities tab. The export status will be confirmed using toast a message.
If you refresh the web page while is the export is in progress, a confirmation dialog box will appear. If you refresh, the export will be cancelled, and all entries in the Activities tab will be removed. To avoid this, do not refresh the page during the export.