AppViewX
Certificate issuance and revocation through the AppViewX CERT+ lifecycle platform.
Overview
AppViewX is registered as an issuer type in Cockpit's PKI module. The connector talks to the AppViewX CERT+ certificate lifecycle platform's REST API, submitting enrollment and revocation requests against a named CA connector configured inside AppViewX.
Requests are filed against a named CA connector configured inside AppViewX, not against a CA directly.
| Property | Value |
|---|---|
| Issuer type | appviewx |
| Backend | AppViewX CERT+ REST API |
| Authentication | Static API key, or username/password exchanged for a session token |
| Issuance model | Certificate returned inline, or via a follow-up download when a workflow requires it |
| Key custody | Caller/CSR-based — AppViewX never returns a private key |
The AppViewX base URL commonly points at an appliance on your own network rather than the public internet. Cockpit's outbound connection policy explicitly allows private network ranges for this issuer while still refusing loopback, link-local and cloud metadata addresses.
Configuration
Config fields
| Field | Purpose |
|---|---|
base_url | Base URL of the AppViewX instance (scheme, host and optional port). |
ca_connector_name | Name of the CA connector (CA settings) configured inside AppViewX that signs the certificate. |
certificate_group | Optional AppViewX certificate group the request is filed under. |
workflow_name | Optional automation workflow/policy to trigger for issuance instead of the default create flow. |
default_validity_days | Certificate validity applied when a request does not specify one (default 365). |
tls_skip_verify | Optional, non-production only. Accepts an AppViewX server certificate that fails verification. |
Credentials
AppViewX supports two authentication modes; choose one when registering the issuer.
| Mode | Fields | Purpose |
|---|---|---|
| API key | api_key | A static API key presented on every request. |
| Username / password | username, password | Exchanged for a session token at login and reused for subsequent requests. |
Credentials are encrypted at rest and never echoed back by the platform.
Registering the issuer
Provide the base URL and CA connector
Enter the AppViewX base URL and the name of the CA connector that should sign certificates.
Choose the authentication mode
Provide either an API key, or a username and password.
Set the optional certificate group and workflow
Assign a certificate group and/or automation workflow if your AppViewX configuration requires one.
Test the connection
Run test-connection to confirm authentication succeeds and the platform is reachable.
Issue through the issuer
Request certificates against the issuer; Cockpit submits the CSR, common name, SANs and validity for enrollment.
Issuance flow
Enrollment is synchronous from the caller's perspective, though the certificate may arrive inline or require one extra download step depending on how the CA connector is set up on the AppViewX side.
A workflow-driven CA connector returns a resource id instead of the certificate; the connector follows up with a download before returning.
Supported operations
| Operation | Supported | Notes |
|---|---|---|
| test-connection | Yes | Authenticates (API key or login) and confirms the platform is reachable. |
| issue | Yes | Submits the CSR against the configured CA connector; downloads the certificate by resource id when the response does not inline it. |
| renew | Yes | No native renewal flow — renew re-submits a fresh create request. |
| revoke | Yes | Revokes by certificate serial against the configured CA connector, with a standard revocation reason and optional comment. |
The AppViewX connector is built against AppViewX's published REST contract. It has not yet been validated against a live AppViewX instance. Before relying on it for production issuance, verify the request and response shapes against an AppViewX sandbox and validate a full issue/revoke cycle in a non-production issuer first.