Manual Import Connection - User Interface Components

Prev Next

1.0 Introduction

This article describes the user interface (UI) features of the Manual Import connection on Fortanix Key Insight.

2.0 Terminology References

For Fortanix Key Insight – Manual Import concepts and supported features, refer to Manual Import Connection Concepts.

3.0 Overview

The Overview page appears after adding a Manual Import connection. It provides a high-level summary of the manually imported cryptographic assets, including keys, certificates, and resources based on the applied Fortanix Key Insight policy.

For more information on the Fortanix Key Insight policy, refer to Cryptographic Policy Management.

Figure 1: Access Manual Import Overview

  • Last Import Details: Click VIEW DETAILS to view the latest import details for the displayed connection. This section displays the number of records that were successfully imported and the number of records that failed to import.

    NOTE

    Click DOWNLOAD to download the records that failed to import. Update the failed assets as required and then upload the file to import them. For more information on how to upload a file after an import failure, refer to If Some Assets Failed to Import.

  • Click ASSESSMENT REPORT to navigate to the Assessment page and view the assessment report. This report allows you to assess the security posture of your keys and identify potential security risks. For more information, refer to Section 4.0: Assessments.

    NOTE

    If your Fortanix Armor account is deactivated and you are accessing the Fortanix Key Insight Manual Import connection, you will not be able to view data on the Overview, Assessments, Keys, Resources, and Certificates pages. You will only have access to view and delete items within the Connections and Policy Center pages.

The Overview page helps users get a summary of the manually imported keys, certificates, and resources, as described in the following sections:

3.1 Discovered Assets

This section summarizes the discovered asset counts for a Manual Import connection.

It shows the count of:

  • Resources

  • Keys

  • Certificates

Click the Keys, Certificates, and Resources labels in the Discovered Assets section to view the corresponding list.

3.2 Cryptography Bill of Materials (CBOM)

The CBOM section allows you to import cryptographic assets to understand key usage, encryption coverage, and potential cryptographic risks. It also enables you to export cryptographic assets metadata to maintain a cryptographic inventory, demonstrate regulatory compliance, and assess post-quantum cryptography (PQC) readiness.

3.2.1 Import Assets

This section describes how to import cryptographic assets into an existing connection using a CSV or CBOM file.

NOTE

  • The import operation replaces the complete set of cryptographic assets associated with the connection with the assets specified in the import file. It does not add the imported assets to the existing asset set.

  • Ensure that the import file contains all cryptographic assets that you want to retain, including existing assets, new assets, and any assets that previously failed to import.

  • Assets currently associated with the connection but not included in the import file will no longer be associated with the connection after the import is completed.

Perform the following steps to import the CSV or CBOM file:

  1. Navigate to Overview → CBOM.

  2. Click IMPORT.

  3. Click CSV or CBOM to download the sample template.

    A file named manual_import_cbom_template.json or manual_import_csv_template.csv is downloaded to your local system.

    Figure 2: Manual Import file

  4. Populate the template with the existing and new assets that you want to import.

    WARNING

    The assets in the import file replace the assets in the existing connection. Ensure that the file contains all assets that you want to retain, including previously imported assets and new assets.

  5. Drag and drop the completed file into the upload area or click Browse to select the file.

  6. Click IMPORT.

    Key Insight validates the file and imports the assets.

  7. Click VIEW DETAILS at the top-right corner of the screen to view the latest import details.

    The Last Import Details displays the number of records that were successfully imported and the number of records that failed to import.

    NOTE

    Click DOWNLOAD to download the records that failed to import. Update the failed assets as needed and then upload the file again by repeating this procedure.

3.2.2 Export

This section describes how to export cryptographic asset metadata from the Manual Import connection into a standardized CBOM JSON file.

To export the CBOM file, click EXPORT.

A file named bom_report_<Manual_Import_scan_id>.json is downloaded to your local system, where <Manual_Import_scan_id> is the unique identifier generated for each Manual Import connection scan.

For example,

bom_report_f0c4ed96-b25b-11f1-9e28-e5fe37879df1
7.38 KB

The exported file adheres to the CycloneDX specification and includes the following components:

  • bomFormat: Specifies the format of the bill of materials. For CBOM exports, this value is set to CycloneDX.

  • specVersion: Indicates the version of the CycloneDX specification used.

  • version: Denotes the version of the generated CBOM file.

  • components: Lists cryptographic components such as keys and certificates. Each entry includes attributes such as type, name, algorithm, associated resources, and so on.

  • resources: Describes the manually imported resources that interact with the listed cryptographic components. Each resource includes attributes such as its name and Universally Unique Identifier (UUID).

  • dependencies: Defines the relationships between keys or certificates and resources, representing how cryptographic elements are interconnected or used together.

3.3 Keys by Status

This section provides a summary of manually imported keys categorized by their status:

  • Keys Enabled: These keys are active cryptographic keys that can be used for encryption and decryption operations. In Fortanix Key Insight, these keys are tracked for ongoing usage, risk, and compliance.

  • Keys Disabled: These keys are cryptographic keys that are disabled and cannot be used for encryption or decryption until they are re-enabled. In Fortanix Key Insight, these keys are monitored as part of the key lifecycle to help identify unused or deprecated keys that may require clean-up or reactivation.

  • Keys Expired: These keys are cryptographic keys that have reached their defined expiration date and are no longer valid for encryption or decryption operations. In Fortanix Key Insight, these keys are tracked to identify keys that may require rotation, replacement, or clean-up.

  • Keys Status Unknown: These keys are manually imported cryptographic keys whose status cannot be determined based on the available key metadata. In Fortanix Key Insight, these keys are tracked to identify keys that require further review or additional information for proper lifecycle management.

Click the Keys by Status label or each key type to open the corresponding list view.

3.4 Keys by Type

This section displays a count of key specifications for the cryptographic assets imported through Manual Import connection. For Manual Import connections, it shows the total number of keys provided in the imported CSV or CBOM file, based on the applied Key Insight policy.

Click any key type to navigate to its corresponding list view.

3.5 Certificates by Status

This section summarizes the status of manually imported certificates, showing the number of issued, unknown, and expired certificates. Click the label or count to navigate to a filtered list view of the corresponding certificates.

3.6 Certificates by Algorithm Type

This section provides a summary of certificate distribution by key algorithm type (For example, RSA 1024). For Manual Import certificates, it displays the total count of each key algorithm used across all scanned certificates.

Click any key algorithm type to view a filtered list of certificates using that algorithm.

3.7 Protected Resources

This section shows the number of encrypted and unencrypted resources.

  • Clicking the Encrypted label takes you to the Resources table, which shows all the encrypted resources.

  • Clicking the Unencrypted label takes you to the Resources table, which shows all the resources that are not encrypted.

4.0 Assessments

After you add a Manual Import connection, access the Fortanix Key Insight Assessment page from the left navigation panel.

The Assessment page shows:

  • Key security posture details for the Manual Import connection.

  • Violations that must be remediated to improve the security status.

  • Remediation advice to improve the security status.

Figure 3: Manual Import Assessment report

4.1 Risk Score

This section provides the overall risk score of the keys, certificates, and resources.

The following are the different risk score categories and their associated risks:

  • Critical – A critical risk score indicates the total number of non-compliant keys, expired certificates, non-compliant certificates by algorithm, and unencrypted resources detected that need attention.

  • High – A high score signifies the total number of shared keys, shared certificates, overly permissive (usage) keys, overly permissive certificate (keys usage), and non-compliant certificates by signature.

NOTE

A Manual Import connection does not have a medium risk score.

The overall risk score is prioritized based on the number of risks, in order of severity from highest to lowest:

  • Critical

  • High

Click each risk label or count to access its corresponding list view.

4.2 Resources Violations

This section provides insights into resource violations across your Manual Import connection.

You can view the total number of violations and their associated resources, along with specific violations for each resource. These violations may result from issues such as the use of shared, deleted, or soon-to-be-deleted keys, excessive permissions, cross-account key usage, non-compliant configurations, or unencrypted keys.

This information helps you identify which resources are at risk, enabling you to implement unique, compliant, and encrypted keys to strengthen your security posture.

Also,

  • Risk levels for each resource are color-coded for easier identification and prioritization.

  • Select VIEW ALL to navigate to the Resources page and explore all key-related violations for each resource.

  • Click any resource to view a detailed list of the top 10 key violations associated with it, sorted by severity. Select any violation type to navigate to its corresponding full list.

  • Click BACK to navigate to the resource violations card view.

4.3 Top Security Issues

This section provides the following information about the keys and certificates:

  • Shared keys: Displays the total number of keys in the Manual Import connection that are shared by two or more services for encrypting the resources. Shared keys increase security risk and help you identify keys that require unique encryption keys to improve security.

  • Shared certificates: Displays the total number of certificates in the Manual Import connection that are shared across two or more resources. Identifying these shared certificates helps you assess potential exposure risks and take action by using unique encryption certificates for enhanced security.

  • Non-compliant keys: Displays the total number of keys in the Manual Import connection that are violating the cryptographic policy that is set for a Fortanix Key Insight account. This information will help you determine which keys are non-compliant with the Key Insight Cryptographic policy so that you can take appropriate action to address the non-compliant key.

    Any key that utilizes the following algorithm and key size combinations is considered Non-Compliant in Fortanix Key Insight, according to the National Institute of Standards and Technology (NIST) 800-57 standard:

    • AES: Key sizes less than 128 bits.

    • 3DES: Keys with sizes of 112 bits and 168 bits.

    • DES: Keys with a size of 56 bits.

    • RSA: Keys with a size less than 2048 bits.

    • DSA: Keys with a size less than 2048 bits.

    • ECC: Keys with a size less than 224 bits.

    • HMAC: Keys with a size less than 112 bits.

    Non-compliant keys increase data security risk and appear as vulnerabilities on the Keys page.

    Fortanix Key Insight recommends using stronger key algorithms and ensuring that the key strength aligns with your defined policies and NIST standards.

  • PQC readiness: Indicates the percentage of your manually imported cryptographic assets that are currently quantum-safe, showing your Manual Import connection preparedness for PQC. This percentage reflects the portion of assets using PQC-compliant algorithms or configurations.

  • Unused keys: Displays the total number of manually imported keys that remain unused for encryption in the supported resources. You can use this information to identify unused keys and remove them for enhanced security.

  • Expired keys: Displays the number of keys that have passed their expiration date. This information helps you review these expired keys and delete them.

Click each top security issue to access its corresponding list view.

4.4 Certificate Expiry Status

This section provides insights into the expiration status of manually imported certificates.

It helps you identify certificate lifecycle risks and maintain compliance and availability across Manual Import connections.

This section contains the following two subsections:

4.4.1 Certificates Expiring in 30 Days

This section displays the top 10 manually imported certificates that are scheduled to expire within the next 30 days, grouped by certificate issuer. Each issuer is represented by a distinct color.

  • Click the count for an issuer to view a filtered list of certificates associated with that issuer.

  • Click the overall certificates count to view a filtered list of certificates in this category.

  • Click VIEW ALL to view all certificates scheduled to expire within the next 30 days.

4.4.2 Expired Certificates

This section displays the top 10 manually imported certificates that have expired, grouped by certificate issuer. Each issuer is represented by a distinct color.

This data helps to identify misconfigurations, overlooked assets, or potential security risks from expired certificates.

  • Click the count for an issuer to view a filtered list of certificates associated with that issuer.

  • Click the overall certificate count to view a filtered list of all expired certificates.

  • Click VIEW ALL to view all expired certificates in this category.

4.5 Certificate by Violation Type

This section displays the total number of non-compliant certificates, grouped by violation types, such as shared certificates, expired certificates, and quantum-vulnerable certificates. Use this information to identify and address security or policy gaps.

  • Click the count for a specific violation type to view a filtered list of certificates affected by that violation.

  • Click the overall certificate count to view a filtered list of all affected certificates.

4.6 Download Assessment Report

Click DOWNLOAD REPORT on the top-right corner of the Assessment page to generate the Data Security Assessment Report for the Manual Import connection in PDF format.

The report will open in the Print dialog box, where you can print the report or save it locally as a PDF.

5.0 Keys

After onboarding the Manual Import connection, click Keys in the Fortanix Key Insight left navigation panel to access the scanned key details.

The keys list view displays all keys in a table, along with details such as KEY IDENTIFIER, STATE, VIOLATIONS, CREATION DATE, EXPIRATION DATE, KEY SPEC, OWNERS, and USAGE DESCRIPTION.

Figure 4: Manual Import keys list view

  • Enter a value in the Search field to filter keys based on the available criteria and supported values.

    For example:

    • Key Spec

    • Key State

    • Key ID

  • Click in the top-right corner of the table to customize which columns are displayed.

  • Click EXPORT to export the scanned keys data. For more information, refer to Section 8.0: Export Scanned Data.

  • Click in the VIOLATIONS column to view detailed information about the associated vulnerabilities.

5.1 Add Key Details

You can assign owners to the scanned keys to enhance key management, simplify tracking, and improve remediation workflows.

Perform the following steps to add the key(s) details:

  1. Select the check box next to the required key(s) in the list.

  2. Click ADD DETAILS in the top right corner of the list view.

  3. In the Add Details dialog box:

    1. Primary owner: Enter the primary owner’s name or employee ID.

    2. Email ID: Enter the primary owner’s valid email ID.

    3. Click ADD SECONDARY OWNER to add the secondary owner details, if required.

    4. Description (Optional): Enter a description of the key.

    5. Click ADD to add the ownership details to the selected key(s).

    NOTE

    You must specify a primary owner before adding a secondary owner.

After you add the details, the OWNERS column on the Keys page displays the primary and secondary owner names or employee IDs and email addresses. The USAGE DESCRIPTION column displays the description provided for the key.

NOTE

Only users with Account Administrator permissions can add or edit key details.

5.2 Edit Key Details

You can modify the details of the selected key(s).

Perform the following steps to edit the key(s) details:

  1. Select the check box next to the required key(s) in the list.

  2. Click EDIT DETAILS in the top right corner.

  3. In the Edit Details dialog box, update the required values.

  4. Click UPDATE to apply the changes.

5.3 View Key Details

Click any KEY IDENTIFIER in the Keys list to view its properties, rotation history, and associated violations.

  • The KEY DETAILS tab displays the key properties, ownership information (if provided), and automatic rotation policy details.

    If required, click EDIT DETAILS in the Ownership section to update the ownership details for the selected key.

    Figure 5: Access key details view

  • The VIOLATIONS tab displays violation details associated with the key.

    Figure 6: View key violations

6.0 Resources

After onboarding the Manual Import connection, click Resources in the Fortanix Key Insight left navigation panel to view the scanned resources.

The Resources page displays the scanned resources in a table with details such as RESOURCE IDENTIFIER, RESOURCE TYPE, ENCRYPTION status, and VIOLATIONS.

NOTE

The RESOURCE IDENTIFIER and RESOURCE TYPE values vary based on the resource category:

  • For cloud resources, RESOURCE IDENTIFIER is the service ID and RESOURCE TYPE is the service type, such as S3, EKS, or Redshift.

  • For on-premises resources, RESOURCE IDENTIFIER is the hostname or IP address, and RESOURCE TYPE is the resource category, such as Oracle, MSSQL, or PostgreSQL.

Figure 7: Manual Import resources list view

  • Click icon in the VIOLATIONS column to view detailed information about the associated vulnerabilities.

  • Enter a value in the Search field to filter the resources based on the available criteria and supported values.

    For example:

    • Resource Name

    • Resource ID

    • Encryption: Encrypted, Unencrypted

  • Click EXPORT to export the scanned resources data. For more information, refer to Section 8.0: Export Scanned Data.

6.1 View Resource Details

Select a resource name in the Resource list to view its properties and associated violations.

  • The RESOURCE DETAILS tab displays the resource configuration details.

    Figure 8: Access resource details view

  • The VIOLATIONS tab displays any violations associated with the resource.

    Figure 9: View resource violations

7.0 Certificates

The Certificates feature provides a unified view of manually imported certificates, their associated private keys, and the resources where the certificates are used.

This mapping offers end-to-end visibility into certificate usage, enabling better management of encryption assets, risk assessment, and monitoring compliance.

After onboarding the Manual Import connection, click Certificates in the Fortanix Key Insight left navigation panel.

The Certificates page displays a list of manually imported certificates in a table, along with details such as CERTIFICATE NAME, STATUS, VIOLATIONS, ISSUER, KEY ALGORITHM, SERIAL NUMBER, DOMAIN NAME, Subject Alternative Name (SAN), RENEWAL STATUS, IN USE BY, NOT VALID BEFORE, OWNERS, USAGE DESCRIPTION, CREATION DATE, and EXPIRATION DATE.

Figure 10: Manual Import certificates list

  • Enter a value in the Search field to filter certificates based on the available criteria and supported values.

    For example:

    • Certificate ID

    • Issuer Type

    • Key Algorithm: RSA 1024, RSA 3072, RSA 4096, Unknown

  • Click in the top-right corner of the table to customize which columns are displayed, beyond the default six.

  • Click EXPORT to export the scanned certificates data. For more information, refer to Section 8.0: Export Scanned Data.

  • Click in the VIOLATIONS column to view detailed information about the associated vulnerabilities.

7.1 Add Certificate Details

You can assign owners to the scanned certificates to enhance certificate management, simplify tracking, and improve remediation workflows.

Perform the following steps to add the certificate details:

  1. Select the check box next to the required certificate(s) in the list.

  2. Click ADD DETAILS in the top right corner of the list view.

  3. In the Add Details dialog box:

    1. Primary owner: Enter the primary owner’s name or employee ID.

    2. Email ID: Enter the primary owner’s valid email ID.

    3. Click ADD SECONDARY OWNER to add the secondary owner’s details, if required.

    4. Description (Optional): Enter a description for the certificate.

    5. Click ADD to add the ownership details to the selected certificate(s).

      NOTE

      You must specify a primary owner before adding a secondary owner.

After you add the details, the OWNERS column on the Certificates page displays the primary and secondary owners’ names or employee IDs and email addresses. The USAGE DESCRIPTION column displays the description provided for the certificate.

NOTE

Only users with Account Administrator permissions can add or edit certificate details.

7.2 Edit Certificate Details

You can modify the details of the selected certificate(s).

Perform the following steps to edit the certificate(s) details:

  1. Select the check box next to the required certificate(s) in the list.

  2. Click EDIT DETAILS in the top right corner.

  3. In the Edit Details dialog box, update the required values.

  4. Click UPDATE to apply the changes.

7.3 View Certificate Details

Click a certificate name in the Certificates list to view its properties, domain name details, and associated violations.

  • The CERTIFICATE DETAILS tab displays the certificate properties, Domain Name and Subject Alternative Names (SANs), and ownership details (if already provided).

    If required, click EDIT DETAILS in the Ownership section to update the ownership details for the selected certificate.

    Figure 11: Access certificate details

  • The VIOLATIONS tab displays any violations associated with the certificate.

    Figure 12: Certificate Violations

8.0 Export Scanned Data

The EXPORT feature allows you to export the manually imported keys, certificates, and resource data from Fortanix Key Insight in Comma-Separated Values (CSV) format. You can use the exported data for analysis, audits, reporting, and record keeping.

In the Keys, Certificates, and Resources list view, click EXPORT to export the scanned data using one of the following options:

Figure 13: Access data export feature

  • Export current page: Exports all column data displayed on the current page in CSV format.

    NOTE

    You can export a maximum of 100 items at a time, based on the number of items specified in the Items per page drop down.

  • Export all raw data: Export all available scanned data shown in the keys, certificates, and resources tables in CSV format. When you select this option, the Export All Raw Data dialog box opens. Review the information and click PROCEED to export all the data.

    NOTE

    After you start an export, you can track its progress in the Activities tab. The export status is recorded as an activity in Fortanix Key Insight. For more information, refer to Section 8.1: View Export Activities.

  • Export selected rows: Exports the selected rows on the current page in CSV format. This option is disabled until you select one or more rows using the check box next to each row.

NOTE

  • Only users with the Account Administrator and Group Administrator roles can export scanned data.

  • Multiple exports can run concurrently within the same account across different connections (manual import, cloud, on-premises, external key sources, and vendor applications).

8.1 View Export Activities

After you initiate the export process using Export All Raw Data, you can track the export status from Activities in the Fortanix Key Insight left navigation panel.

The Activities page displays the following details for each export activity:

  • ACTIVITY NAME: Displays the name of the export activity. For example, an export of all manually imported keys is displayed as Export_all_key.

  • FILE NAME: Displays the name of the exported CSV file.

  • STATUS: Indicates the current state of the export.

    The status can be one of the following:

    • Completed: The export completed successfully, and the CSV file is automatically downloaded to the location specified on your local machine.

    • In Progress: The export is in progress, and you can cancel it using , if required.

    • Cancelled: The export was cancelled, either because you switched accounts or cancelled the export while it was in progress.

    • Failed: The export could not be completed because of an error.

  • CONNECTION: Displays the name of the connection associated with the export.

  • CREATED AT: Displays the date and time when the export activity was created.

Figure 14: Access Manual Import activities

NOTE

  • If you switch to a different account during export, the export is cancelled, and the cancellation is recorded in the Activities.

  • If you navigate to a different solution (for example, Identity and Access Management) while the export is in progress, the export continues. However, the export activity is not displayed in the Activities. The export status is provided through a confirmation message.

  • Avoid refreshing the web page while an export is in progress. If you refresh the page, a confirmation dialog box is displayed. If you confirm the refresh, the export is cancelled and all related entries are removed from the Activities.

Fortanix-logo

4.6

star-ratings

As of August 2025