AWS S3 Bucket Scan, Discovery, and Content Push Validation

Use this procedure to scan AWS S3 buckets for certificate files, validate discovery filters, and perform content push with supported certificate types.

  • AWS S3 integration is configured and reachable from AppViewX.
  • You have permission to run certificate discovery from KUBE visibility screens.
  • If password-protected certificates exist in S3, keep the password available directly or through a configured vault reference.
  1. Go to menu > KUBE > VISIBILITY > Server.
    The Server Certificate inventory page is displayed.
  2. Start discovery and choose the on-demand option for AWS S3, then click Add Resource.
    The Add Resource popup opens for entering discovery source details.
  3. In the vendor-auth section, enter and validate required AWS S3 authentication details as prompted in the popup.
    The request passes vendor-auth validation checks and the discovery job can proceed.
  4. In the Add Resource popup, set discovery scope values for bucket scanning, including file-type and file-size limitations as applicable to your environment.
    Discovery scope is limited to eligible files in the selected S3 location.
  5. Provide file-name filter regex patterns for certificate selection, for example *.pem, *.certificate, or certificate.*.
    Only objects matching the configured file filter are considered during scanning.
  6. Configure discovery filters and include certificate types to be discovered, such as .crt, .cer, .der, .pem, .p7b, .p7c, .pfx, .p12, and .jks.
    On-demand discovery is configured to evaluate all supported certificate formats.
  7. For password-protected certificates, provide a password directly in the request or select the configured vault-stored password reference.
    Password-protected certificates can be processed during discovery with secure credential handling.
  8. Submit the discovery job to scan the S3 bucket, parse eligible certificate files, and frame app connector mapping for the discovered certificates.
    Certificates from the configured S3 resource are discovered and reflected in inventory based on validation and password handling settings.
  9. For a discovered certificate, start the push workflow to AWS S3 and select the certificate content type as .crt, .cer, .der, or .pem.
    The S3 content push form loads type-specific field validation.
  10. In the S3 push form, provide S3 Prefix (optional) and Object Name (mandatory), then validate that Object Name does not contain path separators and follows S3 object-key naming rules.
    Object-key validation is enforced before submission.
  11. Validate password-field behavior during push:
    • For .p12/.pfx, password can be provided (or left empty when allowed).
    • For .crt/.cer/.der/.pem, password is not required.
    • Password input behavior aligns with the selected certificate type.
  12. Review Push to Intermediate Certificate (default enabled), then submit the push request and monitor the status.
    The certificate content is pushed to AWS S3 using the validated type and object-path fields.

AWS S3 on-demand discovery and content push are completed with validated S3 fields, including bucket scanning with regex-based filtering and support for all supported discovery formats.