Migration Execution (Per-Host, Clear-then-Add)

For eligible key-host pairs, AppViewX performs host-specific key-to-certificate migration by building each certificate from zero permissions and adding only the restrictions computed for that host option context.

This behavior applies to key-to-certificate migration for keys that pass eligibility and translation checks. When the same key is present on multiple hosts, migration is executed independently per host, and each host receives a distinct certificate that carries only that host's computed restriction set.

Migration Behavior

  • Migration runs per key-host pair after eligibility and translation validation.
  • Certificate issuance uses the Certificate Authority configured in the associated key policy.
  • Certificate permissions are computed using a clear-then-add model: permission set starts empty, then only host-specific allowed options are re-applied.
  • A single key mapped to multiple hosts results in separate certificates, one per host context.

Execution Flow

  1. Generate certificate data from authorized key options available for the host context.
  2. Provision the generated certificate on the client endpoint for the matching key-host pair.
  3. Provision server-side trust artifacts needed for certificate validation.
  4. Update migration progress in workflow execution stages.
  5. Persist CA and principal mappings in key and certificate collections.
  6. Apply gateway-side migration changes required by the key-to-certificate flow.