New Features

This section describes the new features in this release.

Automation

  • Enhancement to Resume or Re-trigger Workflow Requests at Any Stage

    Introduced support for resuming or re-triggering failed or partially completed workflow requests from any selected stage. This enhancement enables users to restart execution from a specific stage without re-running the entire workflow.

  • Configurable Comment Option for Email Approval/Rejection in Visual Workflows

    Added support for capturing approval and rejection comments in Email Palette-based workflow approvals. Comment capture can be configured as optional or mandatory within the workflow design based on business requirements.

ADC

  • Support for F5 v21 devices

    Added support for onboarding and full life‑cycle management of F5 21.x ADC devices for both LTM and BIG-IP DNS modules . Version support is included in existing OOB workflows.

  • rSeries Features
    • rSeries Host Software Management

      Implemented F5 OS software management for rSeries hosts, Include upgrade and downgrade support, pre- and post-validation checks, and Rollback options.

    • rSeries Host Software Upgrade - Image Upload

      Implemented rSeries host and tenant software image upload capability as part of the "Device Bulk Image Transfer" workflow.

      Note: Allowed image types are <.bundle> and <.iso>.
    • rSeries Tenant Provisioning and Management on Host device

      Introduced provisioning and lifecycle management support for F5 rSeries tenants on host devices. Enables administrators to create and manage tenant instances from AppViewX with operational consistency. Improves readiness for large-scale rSeries adoption in enterprise ADC environments.

    • rSeries Host CPU/TMM utilization check

      Added a reports workflow to automatically discover F5 rSeries host devices and collect CPU and TMM memory utilization metrics. Provides centralized host health monitoring through a consolidated tabular operational view. Improves visibility into resource utilization trends for proactive performance monitoring and capacity planning.

    Note: rSeries Host device certified version 1.8.
  • External Backup download from AppViewX

    Enabled secure download of externally stored backup files directly from AppViewX UI. Users can now retrieve backup artifacts locally without direct access to external backup servers.

  • AI ADC Reports

    AI based ADC reporting (MVP) to generate Device/Application reports using natural language. Provides context aware reporting for use cases such as Get VIP/WideIP/Device details, State/Status/Partition filtering, Unused/Orphan objects.

CLM

  • Enhanced Sectigo Attribute Synchronization and Discovery

    The Sectigo CA integration has been enhanced to synchronize and discover both mandatory and optional certificate attributes. This ensures that discovered certificates contain complete metadata required for renewal, reissue, compliance, and automation workflows, reducing manual intervention.

  • Daily Attribute Synchronization Between AppViewX and GoDaddy

    AppViewX now supports automated daily metadata synchronization with GoDaddy CA. This ensures all GoDaddy CA certificates, enrolled as well externally discovered, retain the necessary order and renewal attributes required for smooth renewal workflows.

  • Enhanced DigiCert Attribute Synchronization and Discovery

    The DigiCert CA integration has been enhanced to synchronize and discover both mandatory and optional certificate attributes, including vendor-specific metadata. This ensures complete certificate information is available for renewal, reissue, compliance, and automation workflows, reducing manual effort and improving operational efficiency.

  • Automated SQL Server Certificate Private Key Permission Validation

    SQL Server certificate binding operations now automatically validate and grant the required private key permissions to the SQL Server service account. This ensures certificates can be loaded successfully during service startup, preventing restart failures and maintaining secure TLS communication.

  • CA Attribute Sync Optimization

    AppViewX now optimizes CA attribute synchronization by accurately associating certificates with their issuing CA accounts through a daily synchronization process. A new CA Attribute Sync option allows administrators to specify which CA accounts participate in attribute synchronization, reducing unnecessary CA calls, improving renewal efficiency, and minimizing synchronization failures. This enhancement is currently supported for DigiCert, GoDaddy, and Sectigo CA integrations.

  • Optional policy controls for Key Type, Hash Function, and Validity Unit

    Added flexible enforcement modes for key policy fields in re-enrollment: inherit, strict single value, or allow-list with default fallback.Ensures consistent behavior across UI and automation workflows when evaluating certificate renewal constraints.Improves traceability by recording policy decisions as Inherited, Allowed, or Overridden.

  • Automated template and policy selection for manual re-enrollment

    Enabled intelligent manual re-enrollment that auto-detects the applicable CA, template, and policy from certificate context.Applies group-specific policy mapping with automatic fallback to default re-enrollment policy when no explicit mapping exists.Reduces manual input and operational errors while delivering a streamlined one-click renewal experience.

  • Automated template selection for auto re-enrollment

    Enhanced auto re-enrollment to automatically resolve both certificate template and CSR generation source.Preserves original key security posture by honoring source context such as Product, Endpoint Agent, or HSM.Enables fully hands-free renewals without compromising private key handling controls.

  • Standardized Renew vs Regenerate logic for Sectigo templates

    Introduced template-level re-enrollment action control to explicitly select Renew or Regenerate behavior for Sectigo CA flows.Ensures the platform invokes the correct CA API path based on configured lifecycle intent.Improves compatibility with CA-side order/subscription handling and billing/tracking models.

  • Standardized Re-enrollment Template for MS ADCS

    Introduced improvements to the MS ADCS template configuration, allowing administrators to define how re-enrollment should behave for a particular account. This provides more predictable and consistent Certificate lifecycle behavior for MS ADCS integrations across re-enrollment operations.

  • Standardized Renew vs Regenerate logic for DigiCert CertCentral templates

    Implemented configurable re-enrollment action behavior for DigiCert CertCentral templates.Supports precise selection of Renew versus Regenerate to align with organizational lifecycle policies.Improves control and predictability for certificate renewal workflows integrated with DigiCert APIs.

  • Standardized Re-enrollment Template for Globalsign SSL CA

    Introduced a CA-specific template for GlobalSign SSL CA that allows administrators to define how re-enrollment should behave for a particular account. This helps ensure consistent and predictable CA interaction during both manual and automated certificate lifecycle operations.

  • Migration and intelligent mapping for CA-specific templates

    Added upgrade-time migration to support CA-specific template mapping using CA vendor and account context.Introduced contextual lookup with automatic fallback to default template when no exact match is available.Ensures continuity of re-enrollment operations with minimal disruption during template model transition.

  • Rebrand Windows Gateway

    Updated Windows Gateway and related Cloud Connector-integrated components to CLM branding.Replaced legacy product naming references in package identity and diagnostic/log outputs.Improves branding consistency across deployed components and operational troubleshooting artifacts.

  • Fetch detailed certificate information via MCP framework

    Introduced MCP-based retrieval of detailed certificate lifecycle and metadata information for AI and automation use cases.Enables security and PKI teams to consume certificate intelligence programmatically without relying on UI navigation.Reduces investigation time by integrating certificate detail access into external operational workflows.

  • Retrieve filtered certificate lists and metadata via MCP framework

    Added MCP capability to query filtered certificate inventories along with relevant metadata for broad audits.Supports AI-assisted and programmatic posture assessments across machine identity environments.Improves scalability of certificate discovery and audit workflows beyond interactive UI-based operations.

  • CMP Server Support for Initialization Request (IR) Mode

    The CMP Server has been enhanced to support Initialization Request (IR) mode in addition to existing P10CR and CCR modes, improving compatibility with CMP-based AppViewX Native PKI and EJBCA environments. This enhancement enables processing of IR requests, certificate issuance through supported CAs, and configuration of the preferred CMP authentication mode.

  • Dynamic Challenge Password Support for SCEP

    SCEP integrations now support both static and dynamic challenge passwords, including support for FleetDM as an MDM vendor. This enhancement introduces secure dynamic challenge password generation and retrieval, enabling streamlined and secure certificate enrollment workflows for supported MDM platforms.

  • Automatic Certificate Revocation for Intune Devices

    Introduced automated certificate revocation for devices marked as Retired or Wiped in Microsoft Intune. A scheduled job is added to fetch device status and identify associated certificates in AppViewX. A configurable settings has been enabled for revocation trigger, certificate type, and mapping attributes. It also supports CN-based matching using device/user identifiers.

  • SLC Dashboard Widget Performance Optimization

    The loading time for the Age (Validity Period) and Certificates by Issuing CAs widgets on the SLC dashboard has been improved by replacing synchronous chart generation with asynchronous data retrieval and pre-populated chart data. This optimization enhances dashboard responsiveness and delivers a faster user experience.

  • Root and Intermediate Certificate Push to Cloud Connector

    Enabled the ability to push Root and Intermediate CA certificates to Cloud Connectors with comprehensive validation. The system verifies successful certificate deployment, ensures correct association between Intermediate and Root certificates, and confirms connector visibility in the unified view. Post-deployment checks validate that EST and ACME enrollments function without SSL handshake issues, ensuring end-to-end trust chain integrity.

  • Configurable Discovery Options for Microsoft Servers
    • Appviewx has introduced configurable certificate discovery settings for Microsoft Server devices, including Location Type (File System, Certificate Store, Port Scan) and Keystore Formats (for example, CRT, CER, PEM, PFX, JKS). At least one option must be selected in each category to proceed.

    • Added support for defining global defaults via Global Device Settings (GDS), with all discovery sources and keystore formats selected by default.

    • Established preference order: Device-level configuration > GDS > System defaults.

    • Applied configurations across device onboarding, updates, manual/scheduled discovery, and config sync operations.

  • AppViewX now supports the provision to update the number of days before Renroll/Regenerate/ Renew for the next generated certificates.
  • AI-Assisted Certificate RBAC Management with InfinityAI

    InfinityAI now enables AI-assisted assignment of certificate-related permissions to user groups, eliminating the need for manual role and permission creation. Based on administrator intent, the system can recommend existing roles or automatically create custom roles, resources, and required ACF permissions. Support covers certificate discovery, inventory operations, lifecycle management, trust store actions, dashboards, groups, policies, and approval workflows, simplifying RBAC administration and accelerating access provisioning.

  • Enable Kerberos Authentication Support Across WAEP and Cloud Connector

    This enhancement enables Kerberos authentication support for WinRM communication across WAEP and Cloud Connector deployments. Administrators can now configure NTLM or Kerberos authentication and choose HTTP or HTTPS communication protocols as required. The solution maintains backward compatibility by continuing to use NTLM when no authentication mode is specified.

Code Signing

  • Code Signing Dashboard

    Code Signing now includes a centralized dashboard that provides real-time and historical visibility into signing activities and policy usage. The dashboard offers interactive analytics, drill-down reporting, advanced search, data export capabilities, user-based filtering, and comprehensive RBAC and audit logging support to improve operational visibility and reporting.

Kube

  • Automated Policy Assignment for Cluster Onboarding

    Added support for regex-based automated policy assignment for clusters and namespaces in both Legacy Cluster Policy and Policy Engine. Platform and DevOps engineers can define cluster and namespace regex patterns directly within a policy. During cluster onboarding or policy creation/update, the system automatically evaluates the configured regex rules, maps matching clusters and namespaces to the policy, and pushes the Policy YAML configuration. The enhancement also includes deterministic cluster-to-namespace mapping to prevent ambiguous regex pattern combinations and a cron-based retry mechanism for failed policy push operations.

  • Automatic CA Connector Creation for Discovered Kubernetes Certificates

    When a Kubernetes cluster is onboarded, the platform now automatically creates CA connectors for discovered certificates whose issuing Certificate Authority already exists in the platform. The auto-created connectors inherit configured group properties, including renewal and expiration policies, ensuring consistent lifecycle management across all certificates issued by the same CA. This eliminates manual CA connector creation and per-certificate lifecycle configuration, enabling scalable certificate governance across Kubernetes environments.

Platform

  • Proactive HSM Integration Health Monitoring and Alerting

    AppViewX now provides proactive health monitoring for HSM integrations, including Entrust, Fortanix, Utimaco, and Thales. The system performs periodic health checks and generates in-product notifications and email alerts when issues are detected, helping ensure HSM availability and reducing operational downtime.

  • Fortanix HSM Auto Provisioning and Onboarding

    Enabled direct creation and onboarding of Fortanix HSM accounts within AppViewX for customers with valid HSM licenses. The Fortanix HSM account setup option is conditionally available based on HSM licensing and supports automated account creation and registration. Additionally, HSM credential update workflows have been introduced, allowing SRE teams to securely update credentials for Fortanix HSM accounts.

  • Implement self-service diagnosis and remediation for Cloud Connector

    AppViewX now provides self-diagnosis and remediation capabilities for Cloud Connector connectivity issues and Kubernetes certificate failures. Added centralized Cloud Connector self-diagnosis through avxctl as a single customer-facing troubleshooting utility. Introduced diagnostic checks for flannel, connectivity configuration, CoreDNS, and firewalld, with automated fixes where applicable. Improves self-service operations by enabling faster issue identification and remediation directly from the Cloud Connector VM.

  • CoreDNS NodeHosts Update with /etc/hosts Entries in Cloud Connector

    AppViewX now propagates non-localhost entries from /etc/hosts in the Cloud Connector host to CoreDNS NodeHosts ConfigMap for in-cluster name resolution. This ensures custom hostnames are resolvable from pods in K3s environments. The update includes controlled restart handling to prevent duplicate CoreDNS rollouts during nameserver update operations.

  • Cloud Connector 3PP Image and Binary Upgrade

    Cloud Connector third-party images and binaries have been upgraded to newer supported versions. This improves security by reducing known vulnerabilities and aligns runtime dependencies with updated platform standards for better stability, compliance, and maintainability.

  • Support Cloud Connector standalone installation on SUSE Linux

    Added support for installing Cloud Connector on SUSE Linux using the existing standalone deployment model. Extends the same installation pattern already available for RHEL and Rocky Linux to SUSE environments. Maintains consistent installation workflow and runtime behavior across supported Linux platforms.

  • RBAC Simplification for Certificate Management Using Infinity AI

    AppViewX now provides an AI-powered RBAC configuration experience for certificate lifecycle management through Infinity AI. Administrators can assign and retrieve certificate group (resource) mappings and certificate-related permissions for user groups using natural language inputs and guided conversational prompts, eliminating the need to navigate multiple disjointed screens across the platform. When assigning certificate operation permissions such as renew, revoke, or regenerate, AppViewX Infinity AI automatically associates the appropriate Visual Workflow (VWF) approval behavior with the user group's resource, enforcing the correct approval path at execution time. To support these workflows, the Infinity AI interface now dynamically renders interactive data grids with built-in search, pagination, multiselect, and action button support, replacing plain-text responses with structured, actionable components. Administrators can also query existing RBAC configurations, including cert group mappings and assigned roles and permissions, directly through the Infinity AI interface.

  • Model Context Protocol (MCP) Framework

    AppViewX now supports the Model Context Protocol (MCP), expanding integration capabilities for AI agents, LLM-powered applications, and automation platforms. By adopting a standardized protocol for tool discovery and execution, organizations can more easily connect AppViewX with MCP-compatible hosts. This creates a common extensibility layer across AppViewX products, providing a foundation for consistent AI-driven interactions and enabling future MCP-based integrations across the platform.In this release, MCP is available through the STDIO transport mode and is delivered as a downloadable MCP plugin through the Agents & Downloads section. The plugin package includes the required artifacts and setup guidance to simplify deployment and integration with AI tools that support MCP over STDIO. Running locally, the plugin enables MCP-compatible hosts to securely access AppViewX capabilities through a standardized interface.The initial MCP toolset focuses on AppViewX CLM read-only capabilities, with additional AppViewX products and tools planned for future expansion.

PKI

  • Migration from AppViewX Standard CA to AppViewX Native CA (PQC-Ready)

    AppViewX now provides a guided CA migration workflow to transition from AppViewX Standard CA (GCP-backed) to AppViewX Native CA. The workflow supports cloning, creating, or mapping Native CAs with custodian approval, preserves existing RBAC and ACL configurations, tracks migration progress, optimizes license usage, and enables retirement of legacy GCP-backed CAs after migration.

  • CA Migration to AppViewX Native PKI

    AppViewX now supports migration of end-entity certificate issuance from external CAs such as GCP CAS, Microsoft ADCS, and EJBCA to AppViewX Native PKI. Administrators can migrate individual or multiple certificates while preserving certificate attributes and application bindings, with optional support for PQC and hybrid algorithms. The migration process is available through both the UI and API, with comprehensive audit logging for traceability and compliance.

  • ADCS to AppViewX Native PKI – Guided Migration Journey

    AppViewX now provides a guided migration workflow to simplify the transition from Microsoft ADCS to AppViewX Native PKI. The workflow automates CA discovery, template migration, prerequisite validation, and Windows Auto-Enrollment Proxy (WAEP) configuration, while providing step-by-step guidance, progress tracking, and validation to ensure a secure and auditable migration experience.

  • AI-Driven CPS Interpretation and Policy Enforcement

    AppViewX Native PKI now supports uploading Certification Practice Statement (CPS) documents in PDF format. The system parses the uploaded CPS, extracts structured policy-relevant sections using an AI framework service, and presents the interpreted output including validity limits, Extended Key Usage constraints, wildcard rules, and naming restrictions in a dedicated review interface. Users can approve, edit, or reject each extracted value individually, or use Approve All for efficiency. Once values are confirmed, the Generate Policy action creates a CLM Certificate Policy using only the approved inputs, with missing mandatory fields prompted before creation and optional fields auto populated with defaults. Generated policies are associated with AppViewX Native CA Certificate Authorities, are fully editable post-creation, and carry an auditable link back to the governing CPS via the tenant CPS URL extension. Users can also download the original CPS PDF, replace or re-upload a document, and navigate directly from a CPS entry to its generated policy using the View Policy option.

  • PKI Automated HSM Onboarding

    AppViewX now provides direct access to HSM onboarding from the PKI Get Started page, enabling users to quickly onboard and manage Fortanix or other HSMs without navigating to the Platform HSM module. Access is controlled through existing HSM onboarding permissions.

Policy Engine

  • Ability to define pre/post actions in policies based on template selection

    Introduced template-driven lifecycle stage controls in Policy Engine to define approvals, schedules, implementation, and post-actions per policy stage.Supports selecting multiple templates with rule-based execution (for example sequential, first success/failure) and dynamic resolution using CA and certificate attributes.Improves governance and auditability with stage-wise execution visibility, configurable failure handling, and controlled override behavior.

QTH

  • ServiceNow CMDB Integration for PQC Readiness

    The platform now integrates with ServiceNow CMDB to enrich discovered cryptographic assets with business and operational context.

    • Automatically correlate cryptographic assets with Configuration Items (CIs) from ServiceNow CMDB.
    • Enrich cryptographic assets with key business and operational metadata, including:
      • Business Application
      • Application Owner
      • Business Criticality
      • CMDB Operational Status
    • Provide a unified view of cryptographic assets alongside their associated business context.

    By combining cryptographic asset intelligence with ServiceNow CMDB data, organizations can better understand the business impact of quantum-related risks and prioritize PQC readiness efforts based on criticality, ownership, operational status, and application dependencies. This enables more effective planning and execution of quantum-safe migration initiatives.

  • Agentless Cryptographic Discovery via Tenable

    The platform now integrates with Tenable IO & Tenable SC to enable agentless discovery of cryptographic assets using existing vulnerability management data.

    • Discover cryptographic assets without deploying additional agents across your environment.
    • Leverage Tenable scan data to identify and inventory:
      • Cryptographic libraries
      • SSL/TLS protocols
      • Cipher suites
      • Digital certificates
    • Automatically create a centralized cryptographic inventory from discovered assets.
    • Gain visibility into cryptographic usage across scanned systems and applications.

    By leveraging existing Tenable vulnerability scan data, organizations can rapidly establish a cryptographic inventory without the operational overhead of agent deployment. This provides immediate visibility into cryptographic assets across the environment, helping security teams assess PQC readiness, identify potential areas of risk, and prioritize quantum-safe migration efforts more effectively.

SSH

  • SSH Certificate Configuration in Key Policies

    AppViewX now supports SSH certificate-specific settings within SSH Key Policies, allowing administrators to configure certificate validity, extensions, and critical options. The update includes validation and persistence of certificate configuration settings across policy creation and updates.

  • Migration for SSH Certificate Configuration Defaults

    A migration process has been introduced to populate missing SSH certificate configuration fields with OpenSSH-aligned default values during upgrades. The migration updates only missing values, preserves existing configurations, and provides logging and metrics for improved upgrade visibility and monitoring.

  • Menu Rename for SSH Provisioning

    Renamed the Provision Key menu item to Provision Key and Certificate. The option continues to open the existing SSH provisioning page with pre-populated fields, providing a unified entry point to view and manage key and certificate provisioning details.

  • Stepper-Based SSH Provisioning Flow

    A new stepper-based SSH provisioning workflow guides users through key details, endpoint configuration, vault configuration, and review steps. The update also enhances endpoint management with dynamic Infra Access Group selection, duplicate endpoint prevention, hostname support, multi-user management, and SSH certificate path validation.

  • SSH Certificate Toggle in Provisioning UI

    Added an SSH Certificate toggle to the Provision Key and Certificate page. When enabled, the UI displays certificate-specific fields such as SSH Cert Key ID, Principal(s), Certificate Validity, and Extensions. When disabled, the page functions as standard SSH key provisioning.

  • Workflow Support for SSH Certificate Provisioning

    The SSH provisioning workflow has been enhanced to support SSH certificate provisioning alongside key provisioning. The update captures certificate-specific details, provides separate server and client endpoint views, and improves traceability of provisioning inputs, execution steps, and endpoint responses.

  • Persistence for SSH Certificate Provisioning

    Stored complete provisioning configurations (including certificate settings and server/client details) in the AppViewX database upon submission. Ensured atomic, idempotent, and tenant-safe persistence to support execution, inventory visibility, auditing, and retry workflows.

  • SSH Certificate Provisioning Execution and Tracking

    SSH certificate provisioning is now fully integrated into the provisioning workflow, enabling automated certificate deployment to Linux endpoints with input validation, prerequisite checks, detailed execution tracking, audit visibility, and retry support. The process also verifies trust bootstrap requirements before provisioning to ensure successful and secure certificate deployment.

  • API Support for SSH Certificate Provisioning

    Extended the existing SSH provisioning API (or introduced a backward-compatible version) to support end-to-end SSH certificate provisioning. Enabled the API to accept and validate certificate inputs (e.g., cert ID, validity) along with Client and Server endpoint mappings.

  • Host Trust Provisioning Stage in Workflow

    Added a new workflow stage to display host trust provisioning details for SSH certificate requests. This enhancement improves visibility into prerequisite trust configuration during certificate provisioning.

  • Host CA Trust Configuration

    Updated endpoints’ known_hosts to trust the Host CA using OpenSSH-compliant @cert-authority entries. This enables host certificate-based verification and ensures the update is idempotent, validated, and safely applied.

  • Authorized Principals Configuration for SSH Certificates

    Enabled configuration of allowed principals on server endpoints during SSH certificate provisioning. The system updates OpenSSH settings to use an Authorized Principals file, ensuring only specified identities are permitted for certificate-based authentication.