Migration Execution (Per-Host, Clear-then-Add)
For eligible key-host pairs, AppViewX performs host-specific key-to-certificate migration by building each certificate from zero permissions and adding only the restrictions computed for that host option context.
This behavior applies to key-to-certificate migration for keys that pass eligibility and translation checks. When the same key is present on multiple hosts, migration is executed independently per host, and each host receives a distinct certificate that carries only that host's computed restriction set.
Migration Behavior
- Migration runs per key-host pair after eligibility and translation validation.
- Certificate issuance uses the Certificate Authority configured in the associated key policy.
- Certificate permissions are computed using a clear-then-add model: permission set starts empty, then only host-specific allowed options are re-applied.
- A single key mapped to multiple hosts results in separate certificates, one per host context.
Execution Flow
- Generate certificate data from authorized key options available for the host context.
- Provision the generated certificate on the client endpoint for the matching key-host pair.
- Provision server-side trust artifacts needed for certificate validation.
- Update migration progress in workflow execution stages.
- Persist CA and principal mappings in key and certificate collections.
- Apply gateway-side migration changes required by the key-to-certificate flow.
