Coexistence Window and Key Decommission
Use Key Policy and Key Inventory to configure coexistence, run migration, and decommission keys per host after the coexistence window based on policy action.
After key-to-certificate migration starts, AppViewX keeps the certificate and original key active during a coexistence window. When the window ends, AppViewX applies decommission logic for each key-host pair based on policy configuration.
Before you begin
- Certificate support is enabled in SSH key policy configuration.
- You have permission to update key policies and run key migration from inventory.
- Selected keys are eligible for migration and are not suspicious, rogue, misplaced, or shared.
Configure coexistence and post-window action in policy
- Go to Menu > SSH > Policy > Key Policy.
- Open the required key policy used by target user keys.
- In SSH Certificate Configuration, go to migration settings.
- Set Coexistence Duration in days. Default is 14 days; supported maximum is 90 days.
- Set Post-Window Action to Manual Confirmation or Auto Decommission.
- Save the policy.
| Setting | Description |
|---|---|
| Coexistence Duration | Days both credentials remain active after certificate issuance. |
| Post-Window Action | Manual Confirmation or Auto Decommission when coexistence ends. |
Run key-to-certificate migration from inventory
- Go to Menu > SSH > Inventory > Key Inventory.
- Select eligible keys to migrate.
- From Actions, select Key to Certificate Migration.
- Review validation messages for ineligible keys.
- Confirm and submit migration.
Migration is tracked per key-host pair. The same key on multiple hosts is processed independently for each host.
Track coexistence and decommission status
- Open Menu > SSH > Inventory > Key Inventory.
- Verify Migration Status and Days Left to Decommission columns for migrated key-host pairs.
- Open SSH dashboard and check the Migration Activity tile for aggregate progress.
- Review in-app notifications sent to the migration initiator.
For Auto Decommission, AppViewX sends a reminder 24 hours before scheduled decommission. For Manual Confirmation, AppViewX notifies when the entry reaches awaiting confirmation state.
Complete post-window action
- When coexistence expires, check the key-host migration entry status.
- If action is Manual Confirmation, complete manual approval from the relevant migration workflow or inventory action.
- If action is Auto Decommission, verify scheduler-driven decommission completion after reminder and execution window.
- Confirm that status updates are reflected in inventory and dashboard views.
