OCI Connection - User Interface Components

Prev Next

1.0 Introduction

This article describes the user interface (UI) features of the OCI connection on Fortanix Key Insight.

2.0 Terminology References

For Fortanix Key Insight – OCI concepts and supported features, refer to OCI Connection Concepts.

3.0 Overview

The Overview page appears after adding an OCI connection. It provides a high-level summary of the OCI connection's cryptographic assets, including keys and services, based on the applied Fortanix Key Insight policy.

For more information on the Fortanix Key Insight policy, refer to Cryptographic Policy Management.

Figure 1: Access OCI overview

  • Click ASSESSMENT REPORT to navigate to the Assessment page and view the assessment report. This report allows you to assess the security posture of your keys and identify potential security risks. For more information, refer to Section 4.0: Assessments.

  • If the number of OCI compartments before the scan does not match the number displayed after the scan:

    • Verify that all required roles and permissions are correctly configured for the OCI Compartments before running the scan.

    • After verifying the permissions, initiate a re-scan using the RESCAN option. For more information, refer to Section 5.0: Rescan an OCI Connection.

NOTE

If your Fortanix Armor account is deactivated and you are accessing the Fortanix Key Insight OCI connection, you will not be able to view data on the Overview, Assessments, Keys, Services, and PQC Central pages. You will only have access to view and delete items within the Connections, Authentication, and Policy Center pages.

The Overview page helps users get a summary of the OCI keys and services as described in the following sections:

3.1 Discovered Assets

This section summarizes the discovered asset counts for an OCI connection.

It shows the count of:

  • Compartments included in the scan

  • Regions in which cryptographic assets are discovered

  • Keys discovered in the scanned compartments

  • Services discovered in the scanned compartments

Click the Keys and Services labels in the Discovered Assets section to view the corresponding list.

3.2 Cryptography Bill of Materials (CBOM)

The CBOM section allows you to export cryptographic assets metadata from the OCI connection into a standard CBOM JSON file. The exported CBOM file can be used to maintain a cryptographic inventory, demonstrate regulatory compliance, and assess post-quantum cryptography (PQC) readiness.

To export the CBOM file, click EXPORT. A file named bom_report_<OCI_scan_id>.json is downloaded to your local system, where <OCI_scan_id> is the unique identifier generated for each OCI connection scan.

For example,

bom_report_8976a481-bc85-11f1-912a-61ef7a7301a3
27.61 KB

The exported file adheres to the CycloneDX specification and includes the following components:

  • bomFormat: Specifies the format of the bill of materials. For CBOM exports, this value is set to CycloneDX.

  • specVersion: Indicates the version of the CycloneDX specification used.

  • version: Denotes the version of the generated CBOM file.

  • components: Lists cryptographic components such as keys and certificates. Each entry includes attributes such as type, name, algorithm, associated resources, and so on.

  • resources: Describes the OCI resources that interact with the listed cryptographic components. Each resource includes attributes such as its name and Universally Unique Identifier (UUID).

  • dependencies: Defines the relationships between keys or certificates and resources, representing how cryptographic elements are interconnected or used together.

3.3 Keys by Status

This section provides a summary of OCI keys categorized by their status:

  • Keys Enabled: These keys are active cryptographic keys that can be used for encryption and decryption operations. In Fortanix Key Insight, these keys are tracked for ongoing usage, risk, and compliance.

  • Keys Disabled: These keys are cryptographic keys that are disabled and cannot be used for encryption or decryption until they are re-enabled. In Fortanix Key Insight, these keys are monitored as part of the key lifecycle to help identify unused or deprecated keys that may require clean-up or reactivation.

  • Pending Deletion: These keys are scheduled for deletion from the connected source but have not yet been permanently deleted. Fortanix Key Insight tracks these keys to provide visibility into their deletion status and support security and compliance reviews.

Click the Keys by Status label or each key type to open the corresponding list view.

3.4 Keys by Type

This section displays a count of key specifications across all OCI compartments included in the scan. For OCI connection, it shows the total number of keys that are configured across the scanned OCI compartments, based on the applied Key Insight policy.

Click any key type to navigate to its corresponding list view.

3.5 Top Compartments by Key and Status

This section lists, in descending order, the top five OCI compartments with the highest number of keys identified during the most recent key scan. The count for each compartment includes both enabled and disabled keys.

Blue indicators represent enabled keys, while orange indicators represent disabled keys.

Click a compartment name to open the list view and view all keys in that compartment.

3.6 Key Source

This section summarizes OCI keys grouped by source.

The key counts are categorized as follows:

  • OCI Software: Count of keys created and managed using OCI software-protected key management.

  • OCI HSM: Count of keys created and managed using OCI Hardware Security Module (HSM)

  • External: Keys discovered from external key management systems or on-premises systems integrated with OCI. These keys are managed outside OCI and accessed through the configured external key management integrations.

Click a key source label to view the keys for the selected key source in tabular format.

3.7 Protected Services

This section shows the number of encrypted, unencrypted, and customer-managed services.

  • Clicking the Encrypted label takes you to the Services table, which shows all the encrypted services.

  • Clicking the Unencrypted label takes you to the Services table, which shows all the services that are not encrypted.

  • Clicking the Customer managed keys (incl. CSP-generated key services) label takes you to the Services table, which shows all the services that are encrypted with a customer master key.

4.0 Assessments

After you add an OCI connection, access the Fortanix Key Insight Assessment page from the left navigation panel.

The Assessment page shows:

  • Key security posture details for the OCI connection.

  • Violations that must be remediated to improve the security status.

  • Remediation advice to improve the security status.

Figure 2: OCI assessment report

4.1 Risk Score

This section provides the overall risk score of the keys and services.

The following are the different risk score categories and their associated risks:

  • Critical – A critical risk score indicates the total number of non-compliant keys, expired keys, services encrypted with purged keys, and unencrypted services detected that need attention.

  • High – A high score signifies the total number of shared keys, keys with rotation disabled, and services encrypted with shared keys.

  • Medium – A medium risk score indicates the total number of CSP-generated keys and services encrypted with platform-managed keys.

The overall risk score is prioritized based on the number of risks, in order of severity from highest to lowest:

  • Critical

  • High

  • Medium

Click each risk label or count to access its corresponding list view.

4.2 Service Violations

This section provides insights into service violations across your OCI connection.

You can view the total number of violations and their associated services, along with specific violations for each service. These violations may result from issues such as the use of shared, deleted, or soon-to-be-deleted keys, excessive permissions, cross-compartment key usage, non-compliant configurations, or unencrypted keys.

This information helps you identify which services are at risk, enabling you to implement unique, compliant, and encrypted keys to strengthen your security posture.

Also,

  • Risk levels for each service are color-coded for easier identification and prioritization.

  • Select VIEW ALL to navigate to the Services page and explore all key-related violations for each service.

  • Click any service to view a detailed list of the top 10 key violations associated with it, sorted by severity. Select any violation type to navigate to its corresponding full list.

  • Click BACK to navigate to the service violations card view.

4.3 Top Security issues

This section provides the following information about the keys:

  • Shared keys: Displays the total number of keys in the OCI connection that are shared by two or more services for encrypting the services. Shared keys increase security risk and help you identify keys that require unique encryption keys to improve security.

  • Exportable keys: Displays the total number of keys in the OCI connection that are configured to allow key material to be exported. Exportable keys can increase security risk and help you identify keys that may require review and remediation.

  • Non-compliant keys: Displays the total number of keys in the OCI connection that are violating the cryptographic policy that is set for a Fortanix Key Insight account. This metric helps identify keys that are non-compliant with the Key Insight Cryptographic policy so that you can take appropriate action to address the non-compliant key.

    Any key that utilizes the following algorithm and key size combinations is considered Non-Compliant in Fortanix Key Insight, according to the National Institute of Standards and Technology (NIST) 800-57 standard:

    • AES: Key sizes less than 128 bits.

    • 3DES: Keys with sizes of 112 bits and 168 bits.

    • DES: Keys with a size of 56 bits.

    • RSA: Keys with a size less than 2048 bits.

    • DSA: Keys with a size less than 2048 bits.

    • ECC: Keys with a size less than 224 bits.

    • HMAC: Keys with a size less than 112 bits.

    Non-compliant keys increase data security risk and appear as vulnerabilities on the Keys page.

    Fortanix Key Insight recommends using stronger key algorithms and ensuring that the key strength aligns with your defined policies and NIST standards.

  • PQC readiness: Displays the percentage of your OCI cryptographic assets that are currently quantum-safe, showing your OCI connection preparedness for PQC. This percentage reflects the portion of assets using PQC-compliant algorithms or configurations. Clicking the percentage value takes you to the PQC Central page, where you can view detailed data for the corresponding OCI connection and assess the readiness of individual assets.

  • Services using Platform Managed Keys: Displays the total number of OCI services that use platform-managed keys for cryptographic operations. This metric helps identify services that rely on platform-managed keys and assess opportunities to use customer-managed keys where required by security or compliance policies.

  • Expired keys: Displays the total number of keys in the OCI connection that have expired. Expired keys may no longer be valid for cryptographic operations and can indicate keys that require rotation, replacement, or removal.

Click each top security issue to access its corresponding list view.

4.4 Key Count by Sources

This section provides information about the security and risk assessment of the natively managed keys from OCI Vault and externally managed or integrated key sources.

The visual indicators (circles) represent the total number of keys identified across the OCI compartments.

4.4.1 Cloud Generated

This section displays the details of natively managed keys from OCI Vault.

  • OCI Software: Represents the total number of keys discovered from OCI software-protected key management. Click the circle or the warning icon to view the keys associated with the OCI software.

  • OCI HSM: Represents the total number of keys discovered from OCI HSM-protected key management. Click the circle or the warning icon to view the HSM-protected keys.

4.4.2 External

This section displays information about externally managed keys.

External: Keys discovered without a defined key protection source. These keys are managed outside the identified OCI key protection sources.

4.5 Download Assessment Report

Click DOWNLOAD REPORT on the top-right corner of the Assessment page to generate the Data Security Assessment Report for the OCI connection in PDF format.

The report will open in the Print dialog box, where you can print the report or save it locally as a PDF.

5.0 Rescan an OCI Connection

Click RESCAN on the top-right corner of the Overview or Assessment page to perform a rescan and verify if any keys have been added, deleted, or updated in the compartments.

If you click RESCAN and start the scan, you can monitor the progress bar while the scan is running.

After the scan is completed successfully,

  • The Last scanned label will be updated with the completion date and time.

  • The Overview page will reflect the new state of the OCI keys and services.

NOTE

The RESCAN option is accessible only to users with the Account Administrator and Group Administrator roles.

6.0 Keys

After onboarding the OCI connection, click Keys in the Fortanix Key Insight left navigation panel to access the scanned key details.

The keys list view displays all keys in a table, along with details such as KEY NAME, VERSION, STATE, VIOLATIONS, KEY SPEC, COMPARTMENT ID, REGION, VERSION ID, CREATION DATE, DELETION DATE, ROTATION DATE, USAGE DESCRIPTION, and OWNERS.

Figure 3: OCI keys list view

  • Enter a value in the Search field to filter keys based on the available criteria and supported values.

    For example:

    • Key Name

    • Version

    • Key State

  • Click in the top-right corner of the table to customize which columns are displayed.

  • Click EXPORT to export the scanned keys data. For more information, refer to Section 8.0: Export Scanned Data.

  • Click in the VIOLATIONS column to view detailed information about the associated vulnerabilities.

6.1 Add Key Details

You can assign owners to the scanned keys to enhance key management, simplify tracking, and improve remediation workflows.

Perform the following steps to add the key(s) details:

  1. Select the check box next to the required key(s) in the list.

  2. Click ADD DETAILS in the top right corner of the list view.

  3. In the Add Details dialog box:

    1. Primary owner: Enter the primary owner’s name or employee ID.

    2. Email ID: Enter the primary owner’s valid email ID.

    3. Click ADD SECONDARY OWNER to add the secondary owner details, if required.

    4. Description (Optional): Enter a description of the key.

    5. Click ADD to add the ownership details to the selected key(s).

      NOTE

      You must specify a primary owner before adding a secondary owner.

After you add the details, the OWNERS column on the Keys page displays the primary and secondary owner names or employee IDs and email addresses. The USAGE DESCRIPTION column displays the description provided for the key.

NOTE

Only users with Account Administrator permissions can add or edit key details.

6.2 Edit Key Details

You can modify the details of the selected key(s).

Perform the following steps to edit the key(s) details:

  1. Select the check box next to the required key(s) in the list.

  2. Click EDIT DETAILS in the top right corner.

  3. In the Edit Details dialog box, update the required values.

  4. Click UPDATE to apply the changes.

6.3 View Key Details

Click any KEY IDENTIFIER in the Keys list to view its properties, rotation history, associated violations, and service mappings.

  • The KEY DETAILS tab displays the key properties, ownership information (if provided), and automatic rotation policy details.

    If required, click EDIT DETAILS in the Ownership section to update the ownership details for the selected key.

    Figure 4: Access key details view

  • The VIOLATIONS tab displays violation details associated with the key.

    Figure 5: View key violations

  • The SERVICE MAPPING tab displays the mapping between the key and OCI service(s), if any. You can view the details of the key and its associated services through Legends.

    Figure 6: Key and service mapping

7.0 Services

After onboarding the OCI connection, click Services in the Fortanix Key Insight left navigation panel to access the map of all the OCI services (OCI File Storage and OCI Object Storage) grouped by OCI compartments.

The Services page displays the scanned services in a table with details such as NAME, TYPE OF SERVICE, ENCRYPTION, VIOLATIONS, COMPARTMENT ID, and REGION.

Figure 7: OCI services list view

  • Click ENCRYPTION column values to check whether the service was encrypted. Clicking the label opens a dialog box that shows details such as the server-side encryption (SSE) algorithm, key state, origin, key manager, key specification, and key usage.

  • Click icon in the VIOLATIONS column to view detailed information about the associated vulnerabilities.

  • Enter a value in the Search field to filter the resources based on the available criteria and supported values.

    For example:

    • Service ID

    • Type

    • Encryption: Encrypted, Unencrypted

  • Click EXPORT to export the scanned resources data. For more information, refer to Section 8.0: Export Scanned Data.

7.1 View Service Details

Click any OCI service name in the Services list to view its configuration details and associated violations.

  • The SERVICE DETAILS tab displays the service configurations and associated key information.

    Figure 8: Access service details view

  • The VIOLATIONS tab displays any violations associated with the service.

    Figure 9: View service violations

8.0 Export Scanned Data

The EXPORT feature allows you to export the OCI scanned key and service data from Fortanix Key Insight in Comma-Separated Values (CSV) format. You can use the exported data for analysis, audits, reporting, and record-keeping.

In the Keys and Services list view, click EXPORT to export the scanned data using one of the following options:

Figure 10: Access data export feature

  • Export current page: Exports all column data displayed on the current page in CSV format.

    NOTE

    You can export a maximum of 100 items at a time, based on the number of items specified in the Items per page drop down.

  • Export all raw data: Export all available scanned data shown in the keys and services tables in CSV format. When you select this option, the Export All Raw Data dialog box opens. Review the information and click PROCEED to export all the data.

    NOTE

    After you start an export, you can track its progress in the Activities tab. The export status is recorded as an activity in Fortanix Key Insight. For more information, refer to Section 8.1: View Export Activities.

  • Export selected rows: Exports the selected rows on the current page in CSV format. This option is disabled until you select one or more rows using the check box next to each row.

NOTE

  • Only users with the Account Administrator and Group Administrator roles can export scanned data.

  • Multiple exports can run concurrently within the same account across different connections (manual import, cloud, on-premises, external key sources, and vendor applications).

8.1 View Export Activities

After you initiate the export process using Export All Raw Data, you can track the export status from Activities in the Fortanix Key Insight left navigation panel.

The Activities page displays the following details for each export activity:

  • ACTIVITY NAME: Displays the name of the export activity. For example, an export of all OCI keys is displayed as Export_all_key.

  • FILE NAME: Displays the name of the exported CSV file.

  • STATUS: Indicates the current state of the export.

    The status can be one of the following:

    • Completed: The export completed successfully, and the CSV file is automatically downloaded to the location specified on your local machine.

    • In Progress: The export is in progress, and you can cancel it using , if required.

    • Cancelled: The export was cancelled, either because you switched accounts or cancelled the export while it was in progress.

    • Failed: The export could not be completed because of an error.

  • CONNECTION: Displays the name of the connection associated with the export.

  • CREATED AT: Displays the date and time when the export activity was created.

Figure 11: Access OCI activities

NOTE

  • If you switch to a different account during export, the export is cancelled, and the cancellation is recorded in the Activities.

  • If you navigate to a different solution (for example, Identity and Access Management) while the export is in progress, the export continues. However, the export activity is not displayed in the Activities. The export status is provided through a confirmation message.

  • Avoid refreshing the web page while an export is in progress. If you refresh the page, a confirmation dialog box is displayed. If you confirm the refresh, the export is cancelled and all related entries are removed from the Activities.

Fortanix-logo

4.6

star-ratings

As of August 2025