CA Migration to AVX Native PKI
The migration enables organizations to adopt a more secure, modern platform that is Post-Quantum Cryptography (PQC) ready and aligned with evolving security and compliance requirements, ensuring that all certificate enrollment is routed through the AppViewX Enrollment Server with no client-side changes required. For ADCS migrations, the process includes pre-validation and permission checks, discovery of active MSCA instances, CA mapping, and creation of equivalent certificate templates in AppViewX, with key attributes such as EKU and KU preserved. The entire workflow features real-time progress tracking, validation checkpoints, and rollback guidance, with a step-by-step interface that allows users to resume from the last completed step.
Prerequisite
- CA policy must have only issuer-based configuration.
- RBAC configuration for PKI must be reconfigured.
- There must be no custodian or CA in the in-progress state.
- For on-premise deployments, the required settings must be configured. See Settings.
- You must have the CA Migration ACF permission assigned to your role.
Navigate to CA Migration
- Go to Menu, select PKI.
-
Select CA Migration.
The CA Migration page is displayed.
The CA Migration landing page provides a central dashboard for managing all migration workflows across three dedicated sections
Table 1. CA Migration Page Sections Section Description Continue Migration Lists active and in-progress migrations that can be resumed (Draft, Awaiting Approval, Validation Pending, In Progress, Migration In Progress). Displays migration name, source CA, status, step progress, and last updated timestamp, with options to resume from the last saved step or discard the migration. Start New Migration Lists supported CAs eligible for a new migration (CAs without active in-progress runs), showing the CA name, type, and last migration date with an action to launch the wizard directly. Note: Unsupported CAs display a "Coming Soon" badgeMigration History Provides a read-only record of all terminal migration runs (Completed, Failed, Cancelled). -
Select the migration type based on your source CA.
- Migrating from AVX Standard CA to AVX Native CA, see Migrating from AVX Standard CA to AVX Native CA.
- Migrating from MS ADCS to AVX Native CA, see Migrating from MS ADCS to AVX Native CA.
-
Follow the step-by-step migration wizard to complete the migration.
The wizard supports resuming from the last completed step if the migration is interrupted.
ACF Permissions Required
| Permission | Description |
|---|---|
| View | Users can view and access the CA Migration page. |
| Add/Modify | Users can start, resume, and manage CA migration
workflows. Note: Enabling CA Migration Add/Modify
permissions also automatically enables CA Inventory
Add/Modify and Templates Add/Modify
permissions. |
