إنتقل إلى المحتوى الرئيسي
ينطبق على:
DuoKey Cockpit v2AppViewX CERT+ platformAPI-key or username/password authentication

Overview​

AppViewX is registered as an issuer type in Cockpit's PKI module. The connector talks to the AppViewX CERT+ certificate lifecycle platform's REST API, submitting enrollment and revocation requests against a named CA connector configured inside AppViewX.

AppViewX connector architecture
DuoKey CockpitPKI issuer connector — AppViewX
API key, or username + password → session token
AppViewX CERT+ platformCertificate lifecycle management appliance
named CA connector
Configured CASigns under the selected CA connector

Requests are filed against a named CA connector configured inside AppViewX, not against a CA directly.

PropertyValue
Issuer typeappviewx
BackendAppViewX CERT+ REST API
AuthenticationStatic API key, or username/password exchanged for a session token
Issuance modelCertificate returned inline, or via a follow-up download when a workflow requires it
Key custodyCaller/CSR-based — AppViewX never returns a private key
Enterprise appliances

The AppViewX base URL commonly points at an appliance on your own network rather than the public internet. Cockpit's outbound connection policy explicitly allows private network ranges for this issuer while still refusing loopback, link-local and cloud metadata addresses.

Configuration​

Config fields​

FieldPurpose
base_urlBase URL of the AppViewX instance (scheme, host and optional port).
ca_connector_nameName of the CA connector (CA settings) configured inside AppViewX that signs the certificate.
certificate_groupOptional AppViewX certificate group the request is filed under.
workflow_nameOptional automation workflow/policy to trigger for issuance instead of the default create flow.
default_validity_daysCertificate validity applied when a request does not specify one (default 365).
tls_skip_verifyOptional, non-production only. Accepts an AppViewX server certificate that fails verification.

Credentials​

AppViewX supports two authentication modes; choose one when registering the issuer.

ModeFieldsPurpose
API keyapi_keyA static API key presented on every request.
Username / passwordusername, passwordExchanged for a session token at login and reused for subsequent requests.

Credentials are encrypted at rest and never echoed back by the platform.

Registering the issuer​

1

Provide the base URL and CA connector

Enter the AppViewX base URL and the name of the CA connector that should sign certificates.

2

Choose the authentication mode

Provide either an API key, or a username and password.

3

Set the optional certificate group and workflow

Assign a certificate group and/or automation workflow if your AppViewX configuration requires one.

4

Test the connection

Run test-connection to confirm authentication succeeds and the platform is reachable.

5

Issue through the issuer

Request certificates against the issuer; Cockpit submits the CSR, common name, SANs and validity for enrollment.

Issuance flow​

Enrollment is synchronous from the caller's perspective, though the certificate may arrive inline or require one extra download step depending on how the CA connector is set up on the AppViewX side.

Synchronous REST issuance via CERT+
1. AuthenticateAPI key, or username/password exchanged for a session token
2. Submit the CSRCSR, common name, SANs and validity, against the configured CA connector
3a. Returned inlineThe default create flow returns the certificate directly
3b. Download by resource idA workflow-driven CA connector returns a resource id; the connector downloads the certificate as a follow-up call
4. Serial recordedKept as the revocation reference against the CA connector

A workflow-driven CA connector returns a resource id instead of the certificate; the connector follows up with a download before returning.

Supported operations​

OperationSupportedNotes
test-connectionYesAuthenticates (API key or login) and confirms the platform is reachable.
issueYesSubmits the CSR against the configured CA connector; downloads the certificate by resource id when the response does not inline it.
renewYesNo native renewal flow — renew re-submits a fresh create request.
revokeYesRevokes by certificate serial against the configured CA connector, with a standard revocation reason and optional comment.
Verify against a sandbox before production use

The AppViewX connector is built against AppViewX's published REST contract. It has not yet been validated against a live AppViewX instance. Before relying on it for production issuance, verify the request and response shapes against an AppViewX sandbox and validate a full issue/revoke cycle in a non-production issuer first.