Getting Started with OCI Cloud Connection

Prev Next

1.0 Introduction

This document describes how to create an Oracle Cloud Infrastructure (OCI) connection in Fortanix Key Insight to scan your cryptographic materials (Keys and Services).

2.0 Terminology References

For OCI connection concepts and supported features, refer to OCI Connection concepts.

3.0 Start the Connection Setup

Before configuring an OCI connection, ensure you can access Fortanix Key Insight.

For information about signing up for Fortanix Armor, creating an Armor account, and accessing Fortanix Key Insight, refer to Getting Started with Key Insight.

You can start the connection setup when you first access Fortanix Key Insight or after you have entered the application.

  • First-time users: When you access Fortanix Key Insight for the first time, the connection setup wizard is displayed automatically. Proceed to Section 5.0: Select Cloud Provider to select OCI and configure the connection.

  • Existing users: In Fortanix Key Insight, go to Configuration → Connections → CLOUD → ADD CLOUD CONNECTION. Proceed to Section 5: Select Cloud Provider to select OCI and configure the connection.

4.0 Prerequisites

The following are the prerequisites before configuring an OCI connection on Fortanix Key Insight:

4.1 Set up OCI Role in the OCI Organization

Before onboarding an OCI connection, perform the steps described in OCI Connection Scanning Configuration to set up your OCI Role in the OCI organization.

4.2 IP Whitelisting Requirements for OCI

To enable secure communication between Fortanix Key Insight and your OCI cloud environment, you may need to allow specific network connections.

If IP whitelisting is required, retrieve the current Fortanix IP ranges from the Fortanix SaaS IP Ranges endpoint and allow the applicable IP ranges in your firewall or network infrastructure.

For information about Fortanix SaaS IP ranges and how to determine the applicable IP addresses based on traffic direction, region, and service, refer to Fortanix SaaS IP Whitelisting.

IP whitelisting is not required for all OCI environments. It is required only when inbound network traffic to your OCI resources is restricted.

5.0 Select Cloud Provider

Perform the following steps to select the scan type, connection type, and OCI cloud provider:

  1. On the Select Cloud Provider step, select Automated Scan as the scan type.

  2. Under Select connection type, select Cloud Connections. Under Select cloud provider, select Oracle Cloud Infrastructure.

  3. Under Select Oracle setup type, select Public end points or OCI Dedicated Region as applicable to your OCI environment.

  4. Click NEXT.

    Figure 1: Select the OCI cloud provider

If OCI Dedicated Region is selected, continue with Section 5.1: OCI Dedicated Region Configuration. If Public end points is selected, continue with Section 6.0: Set Up Authentication.

5.1 Configure OCI Dedicated Region Setup

This section describes how to retrieve the required Domain and Realm Key values and use them to configure OCI Dedicated Region setup.

NOTE

OCI Dedicated Region was previously known as Oracle Dedicated Region Cloud@Customer (DRCC).

5.1.1 Retrieve Domain

The Domain identifies the Oracle Cloud domain used to access keys and services in the OCI Dedicated Region environment.

Perform the following steps to retrieve the Domain:

  1. Log in to the Oracle Cloud console for the OCI Dedicated Region environment.

  2. On the Oracle Cloud Console home page, locate the URL in your browser’s address bar.

  3. Copy the domain portion of the URL.

    For example, if the URL is https://console.example-region.example-domain.com, the Domain value is example-domain.com.

5.1.2 Retrieve Realm Key

The Realm Key identifies the Oracle Cloud realm in which your OCI resources are hosted.

Perform the following steps to retrieve the Realm Key:

  1. In the Oracle Cloud console, click the Profile icon in the top-right corner.

  2. Select Tenancy: <your_tenancy_name>.

  3. On the Tenancy Details page, locate the Tenancy OCID.

  4. Identify the Realm Key from the Tenancy OCID.

For example, if the Tenancy OCID is ocid1.tenancy.oc20..xxxxxxxx, the Realm Key value is oc20.

5.1.3 Configure OCI Dedicated Region Setup

This section describes the procedure for configuring the OCI Dedicated Region setup using the Domain and Realm Key values retrieved in the previous section.

Perform the following steps to configure the OCI Dedicated Region setup:

  1. Realm key: Enter the realm key.

    For more information on obtaining the realm key, refer to Section 5.1.2: Retrieve Realm Key.

  2. Realm domain component: Enter the realm domain.

    For more information on obtaining the domain, refer to Section 5.1.1: Retrieve Domain.

  3. Click Next.

    Figure 2: Configure OCI dedicated region setup

6.0 Set Up Authentication

OCI supports the secret-based authentication method to control how users and applications obtain credentials to access OCI services.

6.1 Retrieve User OCID

The User OCID identifies the OCI user account associated with the OCI connection.

Perform the following steps to retrieve the User OCID:

  1. In the Oracle Cloud console, click the Profile icon in the top-right corner.

  2. Select User Settings.

  3. On the My profile Details page, the user OCID appears under User Information.

6.2 Configure Secret-Based Authentication

API key authentication uses an OCI user OCID and RSA key pair. The RSA private key is used to sign API requests, which are verified by OCI.

Perform the following steps to configure secret-based OCI authentication:

  1. On the Set Up Authentication step, enter the following credentials:

    1. User OCID: Enter a user OCID.

      For more information on obtaining the User OCID, refer to Section 6.1: Retrieve User OCID.

    2. RSA Private Key: Enter the RSA private key in Base64-encoded DER format.

      NOTE

      To convert the private key to DER format and Base64-encoded value without newline characters, run the following command:

      openssl rsa -in ./keyinsight_api_key.pem -outform DER | openssl base64 -A

      Use the command output as the RSA Private Key value.

      For more information on how to fetch the secret-based authentication credentials, refer to OCI Connection Scanning Configuration.

  2. Click NEXT.

    Figure 3: Set up authentication

7.0 Set Up Cloud Connections

This section describes how to retrieve the required Tenancy OCID, Region identifier, and Compartment OCID values and use them to set up the OCI cloud connection.

7.1 Retrieve Tenant OCID

The Tenant OCID uniquely identifies your OCI tenancy (root compartment).

Perform the following steps to retrieve the Tenant OCID:

  1. In the Oracle Cloud console, click the Profile icon in the top-right corner.

  2. Select Tenancy: <your_tenancy_name>.

  3. On the Tenancy Details page, copy the value of the OCID field.

NOTE

The Tenant OCID identifies the root compartment of your OCI tenancy. If the OCI resources are located in the root compartment, the Tenant OCID and Compartment OCID are the same. If the resources are located in a sub-compartment, the Tenant OCID and Compartment OCID are different.

7.2 Retrieve Compartment OCID

The Compartment OCID uniquely identifies the OCI compartment where your resources are located. If the resources are located in a sub-compartment, the Compartment OCID differs from the Tenancy OCID.

Perform the following steps to retrieve the Compartment OCID:

  1. In the Oracle Cloud console, click the Profile icon in the top-right corner.

  2. Select your profile.

  3. In the search bar, enter Compartments and press Enter.

  4. Select the required Compartment from the results.

  5. In the Details tab, copy the value of the OCID field.

NOTE

If you are using the root compartment, the Compartment OCID is the same as the Tenant OCID. If you are using a sub-compartment, the Compartment OCID is unique to that compartment.

7.3 Retrieve Region

Each OCI tenancy has a home region, where IAM resources such as users and policies are defined. Fortanix Key Insight uses the home region identifier to retrieve the regions subscribed to the tenancy. Key Insight uses the subscribed regions to selectively scan resources and avoid unnecessary API calls.

Perform the following steps to retrieve the Region identifier:

  1. In the Oracle Cloud console, click the Profile icon in the top-right corner.

  2. Select Tenancy: <your_tenancy_name>.

  3. Select Region management.

  4. Locate your active region and copy its Region identifier.

7.4 Set Up Cloud Connections

Perform the following steps in the Set Up Cloud Connections step:

  1. Connection name: Enter a name for your OCI connection.

  2. Tenancy OCID: Enter the OCID of the OCI tenancy that you want to scan.

    For more information on obtaining the Tenancy OCID, refer to Section 7.1: Retrieve Tenant OCID.

  3. Home region: Enter the OCI home region of the OCI tenancy.

    For more information on obtaining the home region, refer to Section 7.3: Retrieve Home Region.

  4. Under Select Scope, select the scope of the OCI services to scan:

    1. Tenancy: Select this option to scan all services in the entire tenancy, including services in all compartments.

    2. Compartments: Select this option to scan services in a specific compartment and all sub-compartments within it.

    Figure 4: Select scope

  5. If Compartments is selected, continue with the next step; otherwise, proceed to Step 7.

  6. Compartment OCID: Enter the OCID of the compartment that you want to scan.

    For more information on obtaining the Compartment OCID, refer to Section 7.2: Retrieve Compartment OCID.

    Figure 5: Compartment OCID field

  7. Click NEXT.

If Compartments is selected, continue with Section 7.5: Select Compartments. If Tenancy is selected, proceed to Section 8.0: Select Key Insight Policy.

7.5 Select Compartments

Select the sub-compartments to be scanned under the Compartment OCID specified in the previous section.

Perform the following steps to select sub-compartments:

  1. On the Select Compartments step, select the check box for each sub-compartment that you want to scan.

  2. Click NEXT.

    Figure 6: Select compartments

8.0 Select Key Insight Policy

The System Defined Policy is selected by default on the Key Insight Policy step. This policy enables the scanning of keys and services based on predefined key sizes and permitted operations, ensuring compliance with standard security configurations.

Click FINISH to complete the OCI connection onboarding.

Figure 7: Select Key Insight policy

Additionally,

  • Click ADD POLICY to add a new user-defined policy to the policy center.

  • Click to copy and modify a system-defined policy, converting it into a user-defined policy.

For more information on Fortanix Key Insight policies and features, refer to Cryptographic Policy Management.

NOTE

If you change or update the policy instead of the System Defined Policy, you must Rescan the OCI connection to apply the new policy.

9.0 View the OCI Connection

After onboarding the OCI connection, you can view the OCI connection data and scan results on the following pages:

  • Overview

  • Assessment

  • Keys

  • Services

Figure 8: OCI connection

You can switch regions at any time using the Region drop down in the top navigation bar. When you change the region, the user interface (UI) automatically updates to show the data, connections, and scan results for the selected region.

For more information about the OCI connection UI, refer to OCI Connection User Interface Components.

NOTE

  • The Region field is available only in the Fortanix Key Insight Software-as-a-Service (SaaS) environment. It is not displayed in the on-premises user interface.

  • Users with the Account Administrator and Group Administrator roles can manage (edit, delete, rescan) the connection from the Configuration → Connections → CLOUD.

    • Deleting the OCI connection cannot be undone.

  • A group with the same name is created on the Fortanix IAM Groups page. For more information, refer to Fortanix Armor Identity and Access Management (IAM).

10.0 Troubleshooting

For information about common issues and troubleshooting steps when configuring Fortanix Key Insight in cloud environments, refer to Cloud Connection Troubleshooting.

Fortanix-logo

4.6

star-ratings

As of August 2025