Venafi Connection - User Interface Components

Prev Next

1.0 Introduction

This article describes the user interface (UI) features of the Venafi connection in Fortanix Key Insight.

2.0 Terminology References

For Venafi concepts and supported features, refer to Venafi Connection Concepts.

3.0 Venafi Connection - Overview

Users can access the Venafi connection Overview page after adding a Venafi connection. The Overview page displays the Venafi certificates discovered during the scan based on the applied Fortanix Key Insight policy.

For more information on the Fortanix Key Insight policy, refer to Cryptographic Policy Management.

NOTE

If your Fortanix Armor account is deactivated and you are accessing the Fortanix Key Insight Venafi connection, you will not be able to view data under the Overview or Certificates pages. You will only have access to view and delete items within the Connections, Policy Center, and Authentication pages.

Figure 1: Venafi Overview

4.0 Rescan a Venafi Connection

Click RESCAN on the top right corner of the Overview page to perform a rescan and verify if any certificates have been added, deleted, or updated in your Venafi environment.

If you click RESCAN to start the scan, you can monitor the progress bar as it runs. After the scan completes successfully:

  • The Last scanned label will update with the completion date and time.

  • The Certificates page will reflect the updated status of the Venafi certificates.

NOTE

The RESCAN option is accessible only to users with the Account Administrator and Group Administrator roles.

5.0 Venafi Connection - Certificates

After onboarding the Venafi connection, click Certificates in the Fortanix Key Insight left navigation panel to view the scanned certificate details. The Certificates page displays information for all Venafi certificates discovered during the scan.

5.1 Certificates List View

The certificates list view displays all certificates in a table, along with their details.

Figure 2: Venafi certificates list view

  • Use the Search field to filter certificates based on the available criteria and supported values.

    For example:

    • Certificate Name

    • Issuer

  • Click in the top-right corner of the table to customize which columns are displayed, beyond the default six.

  • Click EXPORT to export the scanned certificates data. For more information, refer to Section 6.0: Venafi Connection - Scanned Data Export.

  • Click in the VIOLATIONS column to view detailed information about the associated vulnerabilities.

5.1.1 Add Certificate Details

You can assign owners to the scanned certificates to enhance certificate management, simplify tracking, and improve remediation workflows.

Perform the following steps to add the certificate(s) details:

  1. Select the check box () next to the required certificate(s) in the list.

  2. Click ADD DETAILS in the top right corner of the table.

  3. In the Add Details dialog box, enter the following details:

    • Primary owner: Enter the primary owner’s name or employee ID.

    • Email ID: Enter the primary owner’s valid email ID.

    • Click ADD SECONDARY OWNER to add the secondary owner’s details, if required.

    • Description (Optional): Enter an optional description.

    • Click ADD to add the ownership details to the selected certificate(s).

NOTE

To add ownership details, specifying a primary owner is mandatory before adding a secondary owner.

On the Certificates page, the primary and secondary owners’ names or employee IDs and email addresses will appear in the OWNERS column, and the description will appear in the USAGE DESCRIPTION column.

NOTE

Only users with Account Administrator permissions can add or edit certificate details.

5.1.2 Edit Certificate Details

You can modify the details of the selected certificate(s).

Perform the following steps to edit the certificate(s) details:

  1. Select the check box () next to the required certificate(s) in the list.

  2. Click EDIT DETAILS in the top right corner.

  3. In the Edit Details dialog box, update the required values and click UPDATE to apply the changes.

5.1.3 View Certificate Details

Click any Certificate Name in the list to view its properties and violations.

  • The CERTIFICATE DETAILS tab displays the certificate’s properties, ownership information (if provided), and domain name and Subject Alternative Name (SAN) details.

    If required, click EDIT DETAILS on the Ownership section to update the ownership details for the selected certificate.

    Figure 3: Access certificates details view

  • The VIOLATIONS tab displays violation details associated with the certificates.

    Figure 4: View certificate violations

6.0 Venafi Connection - Scanned Data Export

This feature allows you to export the Venafi scanned certificates data from Fortanix Key Insight in Comma-Separated Values (CSV) format. Also, it provides flexibility, enabling you to download data for detailed analysis, audits, or reporting, and to access real-time status.

Figure 5: Access data export feature

In the Venafi Certificates list view, click EXPORT to export the scanned data using any of the available options:

  • Export current page: Use this option to export all column data from the current page in CSV format.

    NOTE

    You can download a maximum of 100 items at a time, based on the settings specified in the Items per page drop down.

  • Export all raw data: Use this option to export all scanned data shown in the certificate tables in CSV format. If you select this option, you can read the details on the Export All Raw Data dialog box and click PROCEED to export all the data.

    After the export process begins, you can track its progress. The export status will be logged with a message under the Activities tab in Fortanix Key Insight. For more information, refer to Section 6.1: View Export Activities.

  • Export selected rows: This option is disabled by default. You can select the checkbox () next to the required rows on the current page and export them in CSV format using this option.

NOTE

  • Users with the Account Administrator and Group Administrator roles can only perform the scanned data export.

  • Within a single account, multiple exports can run concurrently across different connections (cloud, on-premises, external key sources, and vendor applications).

6.1 View Export Activities

After you initiate the export process using Export All Raw Data, you can track the export status in the Activities tab located on the Fortanix Key Insight left navigation panel.

You can view the following details for each export:

  • Name of the activity. For example, Export_all_venafi-certificates.

  • Name of the file. For example, Venafi-Certificates.csv.

  • Activity status: This indicates the current state of the data export. This can be,

    • Completed: The data export has been successful, and the CSV file will automatically download to the location specified on your local machine.

    • In Progress: The data export is in progress, and you can cancel it using if required.

    • Cancelled: The data export has been cancelled due to switching accounts or manually cancelling it while it was in progress.

    • Failed: The data export was not completed and failed due to errors.

  • Name of the connection.

  • Export creation date and time.

Figure 6: View export details

NOTE

  • If you switch to a different account during export, the export will be cancelled and logged in the Activities tab.

  • If you navigate to a different solution (for example, Identity and Access Management), the export will continue, but no logs will appear in the Activities tab. The export status will be confirmed using a toast message.

  • If you refresh the web page during the export, the confirmation dialog box will appear. If you refresh, the export will be cancelled, and all entries in the Activities tab will be removed. Therefore, it is recommended not to refresh the page during the export.