Data Sources
Data Sources
The PQC Scanner dashboard supports multiple external data sources for importing and syncing cryptographic assets. This enables centralized visibility across your entire cryptographic infrastructure.
The "dashboard" and data-source sync described on this page are configured inside DuoKey Cockpit (the PQC Readiness module) — there is no separate local web server or localhost dashboard shipped by dke-scanner-agent. Some of the CLI examples below (e.g. servicenow, cloud-aws, vanta, drata, integrations status) illustrate the sync concept but are not real dke-scanner-agent subcommands; the actual CLI surface is documented in the CLI Reference. Real scans are run with commands such as filesystem, domain, inventory, source-code, cloud, or vault, and the resulting JSON is uploaded to the Cockpit for compliance checks and integration sync.
Quick Reference
| Category | Data Source | Description | Status |
|---|---|---|---|
| ITSM / CMDB | CMDB integration with incident management | Production | |
| HSM / KMS | Securosys CloudHSM | Hardware Security Module key inventory | Production |
| HSM / KMS | DuoKey KMS | Multi-tenant key management service | Production |
| Firewall / Network | Firewall certificates, VPN, SSL inspection | Production | |
| Firewall / Network | Next-gen firewall certificates and VPN configs | Planned | |
| Firewall / Network | Check Point | Check Point firewall and VPN gateway discovery | Planned |
| Firewall / Network | Application delivery controller, SSL certificates, TLS | Planned | |
| Firewall / Network | Cisco firewall certificates and VPN configuration | Planned | |
| Firewall / Network | Barracuda | Barracuda firewall and WAF certificate discovery | Planned |
| Firewall / Network | Citrix ADC | Citrix NetScaler/ADC SSL certificate management | Planned |
| Firewall / Network | FortiManager | Centralized Fortinet management and certificate sync | Planned |
| Cloud KMS | AWS KMS | Amazon Web Services Key Management Service | Production |
| Cloud KMS | Azure Key Vault | Microsoft Azure Key Vault | Beta |
| Cloud KMS | Google Cloud KMS | Google Cloud Platform Key Management | Beta |
| Source Code / Git | GitHub repositories and GitHub Enterprise | Production | |
| Source Code / Git | GitLab repositories and self-hosted instances | Production | |
| Source Code / Git | Azure DevOps repositories and pipelines | Production | |
| SSH / Keys | SSH Keys | SSH agent, user keys, authorized_keys, server host keys | Production |
| SSH / Keys | Cockpit SSH | Cockpit-managed SSH keys and certificates | Production |
| Network / TLS | TLS/SSL Endpoints | Remote HTTPS endpoints, certificate chains, cipher suites | Production |
| Advanced | Network Scanner | Network-wide cryptographic asset discovery | Planned |
| Advanced | Packet Capture | Post-quantum key exchange detection via packet analysis | Alpha |
| Advanced | Domain/Subdomain | Automated discovery across domains and subdomains | Alpha |
Overview
Data Source Capabilities
Import
Import cryptographic assets from external systems
Synchronize
Synchronize asset inventories automatically
Track
Track assets across multiple platforms
Integrate
Integrate with existing security tools
Supported Data Sources
1. ServiceNow
Integrate with ServiceNow CMDB to track cryptographic assets alongside other IT assets.
Features
Configuration
Via Dashboard:
Navigate to Settings
Navigate to Settings → Data Sources
Select ServiceNow
Click Configure on ServiceNow card
Enter Details
| Field | Description | Required |
|---|---|---|
| Instance URL | Your ServiceNow instance (e.g., https://company.service-now.com) | Yes |
| Username | ServiceNow username for basic auth | Yes* |
| Password | ServiceNow password for basic auth | Yes* |
| OAuth Token | OAuth token (alternative to username/password) | Yes* |
| API Table | Custom table name | No (default: x_1598283_post_q_0_x_pqc_crypto_asset) |
| Auto-Create Incidents | Automatically create incidents for critical findings | No (default: true) |
* Either username/password or OAuth token required
Via CLI:
# Set environment variables
export SERVICENOW_INSTANCE="https://company.service-now.com"
export SERVICENOW_USER="admin"
export SERVICENOW_PASSWORD="your-password"
# Or use OAuth token
export SERVICENOW_TOKEN="your-oauth-token"
# Test connection
dke-scanner-agent servicenow --test-connection
# Publish scan results
dke-scanner-agent servicenow --input scan-results.json
Testing Connection
Via Dashboard:
- Click Test Connection button
- Wait for result: Success or Failure
- Review error messages if connection fails
Via CLI:
dke-scanner-agent servicenow \
--instance https://company.service-now.com \
--token $SERVICENOW_TOKEN \
--test-connection
2. Securosys CloudHSM

Import cryptographic keys from Securosys CloudHSM for quantum readiness assessment.
Features
Configuration
Via Dashboard:
Navigate to Settings
Navigate to Settings → Data Sources
Select Securosys CloudHSM
Click Configure on Securosys CloudHSM card
Enter Details
| Field | Description | Required |
|---|---|---|
| API URL | Securosys CloudHSM API endpoint | Yes |
| API Token | Authentication token | Yes |
| Environment | production, staging, or development | No |
API Token Generation:
- Log in to Securosys CloudHSM console
- Navigate to Settings → API Tokens
- Click Generate New Token
- Select scopes:
key:read,key:list - Copy and save the token securely
3. Fortinet FortiGate
Discover cryptographic assets in Fortinet FortiGate firewalls including certificates, VPN configurations, and SSL/TLS settings.
Features
Configuration
Via Dashboard:
Navigate to Settings
Navigate to Settings → Data Sources
Select Fortinet FortiGate
Click Configure on Fortinet FortiGate card
Enter Details
| Field | Description | Required |
|---|---|---|
| Base URL | FortiGate base URL (e.g., https://192.168.1.1) | Yes |
| API Token | FortiGate API access token (Bearer token) | Yes |
| Skip SSL Verify | Skip SSL certificate verification for self-signed certs | No (default: true) |
| Timeout | Connection timeout in seconds | No (default: 30) |
API Token Generation
- Log in to FortiGate web interface
- Navigate to System → Administrators
- Create a new REST API Admin
- Generate API token with required permissions:
certificate(read),vpn.ipsec(read),vpn.ssl(read) - Copy and save the token securely
Risk Analysis
The scanner automatically detects:
- Quantum-vulnerable algorithms: RSA-2048, ECDSA, weak DH groups
- Weak TLS versions: TLS 1.0, TLS 1.1
- Certificate expiration: Upcoming expiry dates
- Private key exposure: Keys accessible via API
- Weak VPN configurations: DH groups 1, 2, 5
4. AWS KMS

Discover and assess cryptographic keys in AWS Key Management Service across multiple regions.
Features
Configuration
Via Dashboard:
Navigate to Settings
Navigate to Settings → Data Sources
Select AWS KMS
Click Configure on AWS KMS card
Enter Details
| Field | Description | Required |
|---|---|---|
| AWS Access Key ID | IAM access key with KMS permissions | Yes |
| AWS Secret Access Key | IAM secret access key | Yes |
| Regions | AWS regions to scan (comma-separated) | Yes |
Supported Key Types
The scanner analyzes all AWS KMS key specs:
- Symmetric: AES-256, AES-128
- Asymmetric RSA: RSA-2048, RSA-3072, RSA-4096
- Asymmetric ECC: ECC_NIST_P256, ECC_NIST_P384, ECC_NIST_P521, ECC_SECG_P256K1
- SM2: Chinese cryptographic standard
Quantum Risk Assessment
| Key Spec | Algorithm | Quantum Vulnerable | Risk Score |
|---|---|---|---|
| SYMMETRIC_DEFAULT | AES-256 | No | Low |
| RSA_2048 | RSA-2048 | Yes | High |
| RSA_3072 | RSA-3072 | Yes | Medium |
| RSA_4096 | RSA-4096 | Yes | Medium |
| ECC_NIST_P256 | ECDSA P-256 | Yes | High |
5. Azure Key Vault

Integrate with Microsoft Azure Key Vault for comprehensive key and certificate inventory.
Features
Configuration
Via Dashboard:
| Field | Description | Required |
|---|---|---|
| Tenant ID | Azure AD tenant identifier | Yes |
| Client ID | Application (client) ID | Yes |
| Client Secret | Application client secret | Yes |
| Subscription ID | Azure subscription ID | Yes |
Service Principal Setup
- Register an application in Azure AD
- Create a client secret
- Assign Key Vault permissions:
Key Vault Readerrole on subscriptionKey Vault Crypto Userfor key operationsKey Vault Certificates Userfor certificates
Supported Operations
- List all key vaults in subscription
- Enumerate keys and certificates
- Analyze key types (RSA, EC, AES)
- Check key sizes and curves
- Review expiration dates
- Assess quantum vulnerability
6. Google Cloud KMS

Discover cryptographic keys across Google Cloud Platform projects.
Features
Configuration
Via Dashboard:
| Field | Description | Required |
|---|---|---|
| Service Account JSON | GCP service account credentials | Yes |
| Projects | GCP project IDs (comma-separated) | Yes |
Service Account Setup
- Create a service account in GCP Console
- Grant roles:
Cloud KMS ViewerCloud KMS CryptoKey Decrypter(if analyzing key usage)
- Create and download JSON key
- Paste JSON content into scanner configuration
Supported Key Types
GOOGLE_SYMMETRIC_ENCRYPTIONRSA_SIGN_PSS_2048_SHA256RSA_SIGN_PSS_3072_SHA256RSA_SIGN_PSS_4096_SHA256EC_SIGN_P256_SHA256EC_SIGN_P384_SHA384
7. DuoKey KMS

Integrate with DuoKey Key Management Service for comprehensive key lifecycle management.
Features
Configuration
Via Dashboard:
| Field | Description | Required |
|---|---|---|
| API URL | DuoKey KMS API endpoint (e.g., https://kms.duokey.com) | Yes |
| Tenant ID | Your organization's tenant identifier | Yes |
| Client ID | OAuth client ID | Yes |
| Client Secret | OAuth client secret | Yes |
| Username | KMS username | Yes |
| Password | KMS password | Yes |
| Scope | OAuth scope | No (default: default-api) |
Authentication Flow
The scanner uses OAuth 2.0 Resource Owner Password Credentials flow:
The scanner exchanges KMS password credentials for a bearer token, then pulls the key inventory with risk scores.
8. GitHub
Scan GitHub repositories for cryptographic usage in source code, including GitHub.com and GitHub Enterprise.
Features
Configuration
Via CLI:
# Scan GitHub repository
dke-scanner-agent source-code \
--github-repo owner/repository \
--github-token $GITHUB_TOKEN \
--branch main \
--output scan-results.json
| Parameter | Description | Required |
|---|---|---|
| --github-repo | Repository in format owner/repo | Yes |
| --github-token | Personal Access Token (PAT) | Yes (set GITHUB_TOKEN env var) |
| --github-url | GitHub API URL for Enterprise | No (default: https://api.github.com) |
| --branch | Branch to scan | No (default: main or master) |
Personal Access Token Setup
- Go to GitHub Settings → Developer settings → Personal access tokens
- Click Generate new token (classic)
- Select scopes:
repo(Full control of private repositories)read:org(if scanning organization repos)
- Generate and copy the token
- Set environment variable:
export GITHUB_TOKEN="ghp_xxxxxxxxxxxx"
9. GitLab
Scan GitLab repositories, including GitLab.com and self-hosted GitLab instances.
Features
Configuration
Via CLI:
# Scan GitLab project
dke-scanner-agent source-code \
--gitlab-project group/project \
--gitlab-token $GITLAB_TOKEN \
--branch main \
--output scan-results.json
| Parameter | Description | Required |
|---|---|---|
| --gitlab-project | Project in format group/project | Yes |
| --gitlab-token | Personal Access Token or Project Access Token | Yes (set GITLAB_TOKEN env var) |
| --gitlab-url | GitLab instance URL | No (default: https://gitlab.com) |
| --branch | Branch to scan | No (default: main or master) |
Access Token Setup
Personal Access Token:
- Go to GitLab User Settings → Access Tokens
- Create token with scopes:
read_api,read_repository - Copy token and set:
export GITLAB_TOKEN="glpat-xxxxxxxxxxxx"
Project Access Token:
- Go to Project → Settings → Access Tokens
- Create token with role:
DeveloperorMaintainer - Select scopes:
read_api,read_repository
10. Azure DevOps
Scan Azure DevOps repositories with full support for Azure DevOps Services and Server.
Features
Configuration
Via CLI:
# Scan Azure DevOps repository
dke-scanner-agent source-code \
--azdo-org myorg \
--azdo-project myproject \
--azdo-repo myrepo \
--azdo-token $AZDO_TOKEN \
--branch main \
--output scan-results.json
| Parameter | Description | Required |
|---|---|---|
| --azdo-org | Organization name | Yes |
| --azdo-project | Project name | Yes |
| --azdo-repo | Repository name | Yes |
| --azdo-token | Personal Access Token (PAT) | Yes (set AZDO_TOKEN env var) |
| --azdo-url | Azure DevOps URL | No (default: https://dev.azure.com) |
| --branch | Branch to scan | No (default: main) |
Personal Access Token Setup
- Go to Azure DevOps User Settings → Personal Access Tokens
- Click New Token
- Select scopes:
Code(Read)Project and Team(Read)
- Create and copy the token
- Set environment variable:
export AZDO_TOKEN="xxxxxxxxxxxx"
Data Source Workflow
Each data source moves from initial setup through verification to continuous monitoring.
Configuration
Configure the data source via dashboard or CLI:
- Navigate to Settings → Data Sources
- Click Configure on the desired data source
- Enter connection parameters and credentials
Connection Testing
Verify connectivity and authentication:
- Click Test Connection button
- Scanner validates credentials and permissions
- Review connection status
Data Synchronization
Run scans and sync cryptographic assets:
# Run a scan
dke-scanner-agent agent --output scan.json
# Sync to data source
dke-scanner-agent servicenow --input scan.json
Real-Time Monitoring
The dashboard provides continuous monitoring:
- Last Sync: Timestamp of last successful synchronization
- Assets Synced: Total number of cryptographic assets synchronized
- Status: Connection health (Connected / Disconnected / Error)
- Errors: Any synchronization errors or warnings
Data Source API
The dashboard exposes an API for listing configured data sources, saving a data source configuration, and testing a connection — so you can manage data sources programmatically instead of through the UI.
Detailed API endpoints are documented separately in the Developer Docs.
Security Considerations
Security Best Practices
Credential Storage
Use environment variables, never hardcode credentials
Network Security
HTTPS/TLS 1.2+ for all connections
Access Control
Minimal privileges for service accounts
Token Rotation
Rotate credentials regularly
Best Practices
Troubleshooting
Support
For additional help with data sources, contact DuoKey Support.
Check Point
Barracuda
Citrix ADC
FortiManager