Configuring Certificate Settings
Configuring Password Vault
Before you Begin
The prerequisites for configuring the Password Vault in
AppViewX as are follows:
- A valid certificate password for password-protected certificates to decrypt.
- You have the Password Vault Modify permission.
- If you want to use a HashiCorp credential, HashiCorp must be configured in , and the target credential must exist.
- If you want to assign an Onboarding Group, the group must be configured in Device Onboarding Settings.
-
Go to
.
-
Enter an Identity Name of the password you want to
add in the vault.
The identity name uniquely identifies the vault entry.
-
Optional, select an Onboarding Group from the
drop-down list.
The list shows all configured Device Onboarding Groups. Leave blank if no onboarding group association is required.
- Optional, select Device Name from the dropdown list, select the device whose password-protected certificate details you want to store.
- Optional, enter a certificate file name to help users identify in the File Name field.
-
Select the Password Source.
Password Source Action Manual Entry Enter the password in the Password field that is associated with the certificate. The password is encrypted and stored in AppViewX. Credential List - HashiCorp Select the credential from the Password Identifier drop-down list. The list shows all credentials available in the HashiCorp integration. No local password is stored. -
Click Save.
The vault entry appears in the Password Vault grid. If you selected Credential List - HashiCorp, the corresponding credential in the Credential Library is marked Active and the identity name appears in the Associated Identities section of the Active popup.
Import Password Vault Entries
- Go to .
- Click Import and then click Sample File to get the current seven-column template.
-
Fill in the sample file.
Tip: Leave the password column blank for any row using HashiCorp as the Password Source.
-
Select your completed file and click Upload.
-
Review the preview grid and resolve any validation errors shown in
red.
Common errors include:
- Invalid onboarding group name: The name must exactly match a configured group.
- Invalid Password Identifier: The credential name must exist in the HashiCorp integration.
- Missing password: A password is required for Manual Entry rows.
- Missing Password Identifier: Password Identifier is required for HashiCorp rows.
- Select the rows you want to commit, then click Save to Password Vault to save the valid entries.
Credential List - HashiCorp Vault, the
referenced credential in the Credential Library is automatically marked
Active.Export Password Vault Entries
- Click Export Password on the top-right to export all stored certificate passwords from the vault as a zip file to your computer.
- To modify the existing details, Click Edit.
- To update the password, click Update.
-
To delete the password details, click Delete.
Note: The WindowsCertificateStore identity name will be used to parse certificates discovered from the Windows certificate store. Edit and delete actions are not allowed.
Password Protected Certificates
-
Go to
(Menu) >
CLM > CERTIFICATE
DISCOVERY > Discovery Status >
OnDemand.
- Click on the discovery name under discovery inventory.
- Click Certificates under the tab.
-
To view all password-protected certificates, click Password
Protected Certificates.
