Skip to main content

Data Sources

Applies to:
DashboardCLIServiceNowCloud KMSHSMGit Providers
Dashboard means DuoKey Cockpit

The "dashboard" and data-source sync described on this page are configured inside DuoKey Cockpit (the PQC Readiness module) — there is no separate local web server or localhost dashboard shipped by dke-scanner-agent. Some of the CLI examples below (e.g. servicenow, cloud-aws, vanta, drata, integrations status) illustrate the sync concept but are not real dke-scanner-agent subcommands; the actual CLI surface is documented in the CLI Reference. Real scans are run with commands such as filesystem, domain, inventory, source-code, cloud, or vault, and the resulting JSON is uploaded to the Cockpit for compliance checks and integration sync.

Quick Reference​

CategoryData SourceDescriptionStatus
ITSM / CMDBServiceNowCMDB integration with incident managementProduction
HSM / KMSSecurosys CloudHSMHardware Security Module key inventoryProduction
HSM / KMSDuoKey KMSMulti-tenant key management serviceProduction
Firewall / NetworkFortinet FortiGateFirewall certificates, VPN, SSL inspectionProduction
Firewall / NetworkPalo Alto NetworksNext-gen firewall certificates and VPN configsPlanned
Firewall / NetworkCheck PointCheck Point firewall and VPN gateway discoveryPlanned
Firewall / NetworkF5 BIG-IPApplication delivery controller, SSL certificates, TLSPlanned
Firewall / NetworkCisco ASA/FirepowerCisco firewall certificates and VPN configurationPlanned
Firewall / NetworkBarracudaBarracuda firewall and WAF certificate discoveryPlanned
Firewall / NetworkCitrix ADCCitrix NetScaler/ADC SSL certificate managementPlanned
Firewall / NetworkFortiManagerCentralized Fortinet management and certificate syncPlanned
Cloud KMSAWS KMSAmazon Web Services Key Management ServiceProduction
Cloud KMSAzure Key VaultMicrosoft Azure Key VaultBeta
Cloud KMSGoogle Cloud KMSGoogle Cloud Platform Key ManagementBeta
Source Code / GitGitHubGitHub repositories and GitHub EnterpriseProduction
Source Code / GitGitLabGitLab repositories and self-hosted instancesProduction
Source Code / GitAzure DevOpsAzure DevOps repositories and pipelinesProduction
SSH / Keys SSH KeysSSH agent, user keys, authorized_keys, server host keysProduction
SSH / KeysCockpit SSHCockpit-managed SSH keys and certificatesProduction
Network / TLS TLS/SSL EndpointsRemote HTTPS endpoints, certificate chains, cipher suitesProduction
Advanced Network ScannerNetwork-wide cryptographic asset discoveryPlanned
Advanced Packet CapturePost-quantum key exchange detection via packet analysisAlpha
Advanced Domain/SubdomainAutomated discovery across domains and subdomainsAlpha

Overview​

Data Source Capabilities

Import

Import cryptographic assets from external systems

Synchronize

Synchronize asset inventories automatically

Track

Track assets across multiple platforms

Integrate

Integrate with existing security tools

Supported Data Sources​

1. ServiceNow​

ServiceNow

Integrate with ServiceNow CMDB to track cryptographic assets alongside other IT assets.

Features

Bi-directional syncSync with ServiceNow tables
Auto-incident creationFor critical findings
Custom table supportUse your own ServiceNow tables
Real-time updatesVia webhooks

Configuration​

Via Dashboard:

1

Navigate to Settings

Navigate to Settings → Data Sources

2

Select ServiceNow

Click Configure on ServiceNow card

3

Enter Details

FieldDescriptionRequired
Instance URLYour ServiceNow instance (e.g., https://company.service-now.com)Yes
UsernameServiceNow username for basic authYes*
PasswordServiceNow password for basic authYes*
OAuth TokenOAuth token (alternative to username/password)Yes*
API TableCustom table nameNo (default: x_1598283_post_q_0_x_pqc_crypto_asset)
Auto-Create IncidentsAutomatically create incidents for critical findingsNo (default: true)

* Either username/password or OAuth token required

Via CLI:

# Set environment variables
export SERVICENOW_INSTANCE="https://company.service-now.com"
export SERVICENOW_USER="admin"
export SERVICENOW_PASSWORD="your-password"
# Or use OAuth token
export SERVICENOW_TOKEN="your-oauth-token"

# Test connection
dke-scanner-agent servicenow --test-connection

# Publish scan results
dke-scanner-agent servicenow --input scan-results.json

Testing Connection​

Via Dashboard:

  1. Click Test Connection button
  2. Wait for result: Success or Failure
  3. Review error messages if connection fails

Via CLI:

dke-scanner-agent servicenow \
--instance https://company.service-now.com \
--token $SERVICENOW_TOKEN \
--test-connection

2. Securosys CloudHSM​

Securosys

Import cryptographic keys from Securosys CloudHSM for quantum readiness assessment.

Features

Direct HSM key inventoryRead keys from HSM partitions
Key usage analyticsTrack key usage patterns
Algorithm complianceCheck algorithm compliance
Key rotation planningAutomated rotation plans

Configuration​

Via Dashboard:

1

Navigate to Settings

Navigate to Settings → Data Sources

2

Select Securosys CloudHSM

Click Configure on Securosys CloudHSM card

3

Enter Details

FieldDescriptionRequired
API URLSecurosys CloudHSM API endpointYes
API TokenAuthentication tokenYes
Environmentproduction, staging, or developmentNo

API Token Generation:

  1. Log in to Securosys CloudHSM console
  2. Navigate to Settings → API Tokens
  3. Click Generate New Token
  4. Select scopes: key:read, key:list
  5. Copy and save the token securely

3. Fortinet FortiGate​

Fortinet

Discover cryptographic assets in Fortinet FortiGate firewalls including certificates, VPN configurations, and SSL/TLS settings.

Features

SSL/TLS certificate discoveryLocal and CA certificates
VPN IPSec configurationsPhase 1 & 2 interfaces, DH groups
SSL VPN certificatesServer certs, TLS versions, cipher suites
Deep inspection certificatesSSL inspection certificates and keys

Configuration​

Via Dashboard:

1

Navigate to Settings

Navigate to Settings → Data Sources

2

Select Fortinet FortiGate

Click Configure on Fortinet FortiGate card

3

Enter Details

FieldDescriptionRequired
Base URLFortiGate base URL (e.g., https://192.168.1.1)Yes
API TokenFortiGate API access token (Bearer token)Yes
Skip SSL VerifySkip SSL certificate verification for self-signed certsNo (default: true)
TimeoutConnection timeout in secondsNo (default: 30)

API Token Generation​

  1. Log in to FortiGate web interface
  2. Navigate to System → Administrators
  3. Create a new REST API Admin
  4. Generate API token with required permissions: certificate (read), vpn.ipsec (read), vpn.ssl (read)
  5. Copy and save the token securely

Risk Analysis​

The scanner automatically detects:

  • Quantum-vulnerable algorithms: RSA-2048, ECDSA, weak DH groups
  • Weak TLS versions: TLS 1.0, TLS 1.1
  • Certificate expiration: Upcoming expiry dates
  • Private key exposure: Keys accessible via API
  • Weak VPN configurations: DH groups 1, 2, 5

4. AWS KMS​

AWS KMS

Discover and assess cryptographic keys in AWS Key Management Service across multiple regions.

Features

Multi-region key discoveryScan across AWS regions
Customer managed keysCMK analysis
External key storesXKS and CloudHSM keys
Key rotation statusAlgorithm & key spec analysis

Configuration​

Via Dashboard:

1

Navigate to Settings

Navigate to Settings → Data Sources

2

Select AWS KMS

Click Configure on AWS KMS card

3

Enter Details

FieldDescriptionRequired
AWS Access Key IDIAM access key with KMS permissionsYes
AWS Secret Access KeyIAM secret access keyYes
RegionsAWS regions to scan (comma-separated)Yes

Supported Key Types​

The scanner analyzes all AWS KMS key specs:

  • Symmetric: AES-256, AES-128
  • Asymmetric RSA: RSA-2048, RSA-3072, RSA-4096
  • Asymmetric ECC: ECC_NIST_P256, ECC_NIST_P384, ECC_NIST_P521, ECC_SECG_P256K1
  • SM2: Chinese cryptographic standard

Quantum Risk Assessment​

Key SpecAlgorithmQuantum VulnerableRisk Score
SYMMETRIC_DEFAULTAES-256NoLow
RSA_2048RSA-2048YesHigh
RSA_3072RSA-3072YesMedium
RSA_4096RSA-4096YesMedium
ECC_NIST_P256ECDSA P-256YesHigh

5. Azure Key Vault​

Azure Key Vault

Integrate with Microsoft Azure Key Vault for comprehensive key and certificate inventory.

Features

Key discoveryAcross subscriptions
Certificate managementFull cert inventory
Managed HSMHSM-backed keys
Access policy reviewKey versioning tracking

Configuration​

Via Dashboard:

FieldDescriptionRequired
Tenant IDAzure AD tenant identifierYes
Client IDApplication (client) IDYes
Client SecretApplication client secretYes
Subscription IDAzure subscription IDYes

Service Principal Setup​

  1. Register an application in Azure AD
  2. Create a client secret
  3. Assign Key Vault permissions:
    • Key Vault Reader role on subscription
    • Key Vault Crypto User for key operations
    • Key Vault Certificates User for certificates

Supported Operations​

  • List all key vaults in subscription
  • Enumerate keys and certificates
  • Analyze key types (RSA, EC, AES)
  • Check key sizes and curves
  • Review expiration dates
  • Assess quantum vulnerability

6. Google Cloud KMS​

Google Cloud KMS

Discover cryptographic keys across Google Cloud Platform projects.

Features

Multi-project discoveryScan across GCP projects
Key ring enumerationFull key ring inventory
HSM & software keysBoth key types detected
IAM policy reviewAlgorithm analysis & versioning

Configuration​

Via Dashboard:

FieldDescriptionRequired
Service Account JSONGCP service account credentialsYes
ProjectsGCP project IDs (comma-separated)Yes

Service Account Setup​

  1. Create a service account in GCP Console
  2. Grant roles:
    • Cloud KMS Viewer
    • Cloud KMS CryptoKey Decrypter (if analyzing key usage)
  3. Create and download JSON key
  4. Paste JSON content into scanner configuration

Supported Key Types​

  • GOOGLE_SYMMETRIC_ENCRYPTION
  • RSA_SIGN_PSS_2048_SHA256
  • RSA_SIGN_PSS_3072_SHA256
  • RSA_SIGN_PSS_4096_SHA256
  • EC_SIGN_P256_SHA256
  • EC_SIGN_P384_SHA384

7. DuoKey KMS​

DuoKey KMS

Integrate with DuoKey Key Management Service for comprehensive key lifecycle management.

Features

Centralized key inventoryFull key lifecycle management
Multi-tenant supportIsolate per tenant
OAuth 2.0 authenticationSecure token-based access
Real-time monitoringAutomated compliance reporting

Configuration​

Via Dashboard:

FieldDescriptionRequired
API URLDuoKey KMS API endpoint (e.g., https://kms.duokey.com)Yes
Tenant IDYour organization's tenant identifierYes
Client IDOAuth client IDYes
Client SecretOAuth client secretYes
UsernameKMS usernameYes
PasswordKMS passwordYes
ScopeOAuth scopeNo (default: default-api)

Authentication Flow​

The scanner uses OAuth 2.0 Resource Owner Password Credentials flow:

OAuth 2.0 password flow
PQC Scanner
1. POST /connect/token — grant_type=password, client_id, client_secret, username, password, scope
DuoKey KMS
2. Access token — token_type Bearer, expires_in 3600
PQC Scanner — authenticated
3. GET /api/keys — Authorization Bearer token
DuoKey KMS
4. Key inventory — cryptographic assets with risk scores
PQC Scanner — key inventory

The scanner exchanges KMS password credentials for a bearer token, then pulls the key inventory with risk scores.


8. GitHub​

GitHub

Scan GitHub repositories for cryptographic usage in source code, including GitHub.com and GitHub Enterprise.

Features

Public & private reposFull repository scanning
GitHub EnterpriseSelf-hosted support
Branch-specific scanningScan any branch
GitHub ActionsAutomated CI/CD scanning

Configuration​

Via CLI:

# Scan GitHub repository
dke-scanner-agent source-code \
--github-repo owner/repository \
--github-token $GITHUB_TOKEN \
--branch main \
--output scan-results.json
ParameterDescriptionRequired
--github-repoRepository in format owner/repoYes
--github-tokenPersonal Access Token (PAT)Yes (set GITHUB_TOKEN env var)
--github-urlGitHub API URL for EnterpriseNo (default: https://api.github.com)
--branchBranch to scanNo (default: main or master)

Personal Access Token Setup​

  1. Go to GitHub Settings → Developer settings → Personal access tokens
  2. Click Generate new token (classic)
  3. Select scopes:
    • repo (Full control of private repositories)
    • read:org (if scanning organization repos)
  4. Generate and copy the token
  5. Set environment variable: export GITHUB_TOKEN="ghp_xxxxxxxxxxxx"

9. GitLab​

GitLab

Scan GitLab repositories, including GitLab.com and self-hosted GitLab instances.

Features

GitLab.com & self-hostedBoth supported
Project & group scanningScan at any level
Branch & MR analysisMerge request integration
CI/CD pipelineGitLab CI integration

Configuration​

Via CLI:

# Scan GitLab project
dke-scanner-agent source-code \
--gitlab-project group/project \
--gitlab-token $GITLAB_TOKEN \
--branch main \
--output scan-results.json
ParameterDescriptionRequired
--gitlab-projectProject in format group/projectYes
--gitlab-tokenPersonal Access Token or Project Access TokenYes (set GITLAB_TOKEN env var)
--gitlab-urlGitLab instance URLNo (default: https://gitlab.com)
--branchBranch to scanNo (default: main or master)

Access Token Setup​

Personal Access Token:

  1. Go to GitLab User Settings → Access Tokens
  2. Create token with scopes: read_api, read_repository
  3. Copy token and set: export GITLAB_TOKEN="glpat-xxxxxxxxxxxx"

Project Access Token:

  1. Go to Project → Settings → Access Tokens
  2. Create token with role: Developer or Maintainer
  3. Select scopes: read_api, read_repository

10. Azure DevOps​

Azure DevOps

Scan Azure DevOps repositories with full support for Azure DevOps Services and Server.

Features

Cloud & on-premisesServices and Server support
Org & project scanningMulti-repository analysis
Pipeline integrationAzure Pipelines support
Work item creationCreate items for findings

Configuration​

Via CLI:

# Scan Azure DevOps repository
dke-scanner-agent source-code \
--azdo-org myorg \
--azdo-project myproject \
--azdo-repo myrepo \
--azdo-token $AZDO_TOKEN \
--branch main \
--output scan-results.json
ParameterDescriptionRequired
--azdo-orgOrganization nameYes
--azdo-projectProject nameYes
--azdo-repoRepository nameYes
--azdo-tokenPersonal Access Token (PAT)Yes (set AZDO_TOKEN env var)
--azdo-urlAzure DevOps URLNo (default: https://dev.azure.com)
--branchBranch to scanNo (default: main)

Personal Access Token Setup​

  1. Go to Azure DevOps User Settings → Personal Access Tokens
  2. Click New Token
  3. Select scopes:
    • Code (Read)
    • Project and Team (Read)
  4. Create and copy the token
  5. Set environment variable: export AZDO_TOKEN="xxxxxxxxxxxx"

Data Source Workflow​

Data source workflow
1. Configuration
Setup
2. Connection Testing
Verify
3. Data Synchronization
Monitor
4. Real-Time Monitoring

Each data source moves from initial setup through verification to continuous monitoring.

1

Configuration

Configure the data source via dashboard or CLI:

  • Navigate to Settings → Data Sources
  • Click Configure on the desired data source
  • Enter connection parameters and credentials
2

Connection Testing

Verify connectivity and authentication:

  • Click Test Connection button
  • Scanner validates credentials and permissions
  • Review connection status
3

Data Synchronization

Run scans and sync cryptographic assets:

# Run a scan
dke-scanner-agent agent --output scan.json

# Sync to data source
dke-scanner-agent servicenow --input scan.json
4

Real-Time Monitoring

The dashboard provides continuous monitoring:

  • Last Sync: Timestamp of last successful synchronization
  • Assets Synced: Total number of cryptographic assets synchronized
  • Status: Connection health (Connected / Disconnected / Error)
  • Errors: Any synchronization errors or warnings

Data Source API​

The dashboard exposes an API for listing configured data sources, saving a data source configuration, and testing a connection — so you can manage data sources programmatically instead of through the UI.

API reference

Detailed API endpoints are documented separately in the Developer Docs.


Security Considerations​

Security Best Practices

Credential Storage

Use environment variables, never hardcode credentials

Network Security

HTTPS/TLS 1.2+ for all connections

Access Control

Minimal privileges for service accounts

Token Rotation

Rotate credentials regularly


Best Practices​


Troubleshooting​



Support​

For additional help with data sources, contact DuoKey Support.