Configuring Certificate Settings

Configuring Password Vault

The Password Vault stores certificate passwords for all selected devices. When AppViewX discovers password-protected certificates, it decrypts them and adds them to the discovery grid in AppViewX Inventory only if the certificate passwords match the passwords stored in the vault.

Before you Begin

The prerequisites for configuring the Password Vault in AppViewX as are follows:
  • A valid certificate password for password-protected certificates to decrypt.
  • You have the Password Vault Modify permission.
  • If you want to use a HashiCorp credential, HashiCorp must be configured in Platform > Credential Library Settings, and the target credential must exist.
  • If you want to assign an Onboarding Group, the group must be configured in Device Onboarding Settings.
  1. Go to Menu > CLM > ADMINISTRATION > Password Vault.
  2. Enter an Identity Name of the password you want to add in the vault.
    The identity name uniquely identifies the vault entry.
  3. Optional, select an Onboarding Group from the drop-down list.
    The list shows all configured Device Onboarding Groups. Leave blank if no onboarding group association is required.
  4. Optional, select Device Name from the dropdown list, select the device whose password-protected certificate details you want to store.
  5. Optional, enter a certificate file name to help users identify in the File Name field.
  6. Select the Password Source.
    Password Source Action
    Manual Entry Enter the password in the Password field that is associated with the certificate. The password is encrypted and stored in AppViewX.
    Credential List - HashiCorp Select the credential from the Password Identifier drop-down list. The list shows all credentials available in the HashiCorp integration. No local password is stored.
  7. Click Save.
    The vault entry appears in the Password Vault grid. If you selected Credential List - HashiCorp, the corresponding credential in the Credential Library is marked Active and the identity name appears in the Associated Identities section of the Active popup.

Import Password Vault Entries

To import multiple Password Vault entries at once, click Import in the top-right corner and upload a CSV or XLS file containing your certificate passwords. This stores passwords directly in the vault without manual entry. Download the sample file from the Password Vault page before preparing your file.
  1. Go to Menu > CLM > ADMINISTRATION > Password Vault.
  2. Click Import and then click Sample File to get the current seven-column template.
  3. Fill in the sample file.
    Tip: Leave the password column blank for any row using HashiCorp as the Password Source.
  4. Select your completed file and click Upload.
  5. Review the preview grid and resolve any validation errors shown in red.
    Common errors include:
    • Invalid onboarding group name: The name must exactly match a configured group.
    • Invalid Password Identifier: The credential name must exist in the HashiCorp integration.
    • Missing password: A password is required for Manual Entry rows.
    • Missing Password Identifier: Password Identifier is required for HashiCorp rows.
  6. Select the rows you want to commit, then click Save to Password Vault to save the valid entries.
Valid rows are added to the Password Vault. For rows with Password Source set to Credential List - HashiCorp Vault, the referenced credential in the Credential Library is automatically marked Active.

Export Password Vault Entries

  1. Click Export Password on the top-right to export all stored certificate passwords from the vault as a zip file to your computer.
  2. To modify the existing details, Click Edit.
  3. To update the password, click Update.
  4. To delete the password details, click Delete.
    Note: The WindowsCertificateStore identity name will be used to parse certificates discovered from the Windows certificate store. Edit and delete actions are not allowed.

Password Protected Certificates

Password mismatch or password unavailable in the vault for the password-protected certificates that are discovered will be under the password-protected certificates section.
  1. Go to (Menu) > CLM > CERTIFICATE DISCOVERY > Discovery Status > OnDemand.
  2. Click on the discovery name under discovery inventory.
  3. Click Certificates under the tab.
  4. To view all password-protected certificates, click Password Protected Certificates.