Vault
Vault
Inventory keys held in a vault registered in the Cockpit and assess their algorithms
The Vault source is the preferred way to inventory key-management keys. It supersedes the legacy Cloud source.
Overview
The Vault source inventories the keys held in a vault that is already registered in the Cockpit. Because the vault connection is configured centrally, the scan reuses that registration to enumerate keys and assess each key's algorithm for quantum vulnerability. Supported vault types include Securosys HSM, AWS KMS, and Azure Key Vault.
What It Scans
| Item | Details |
|---|---|
| Vault types | Securosys HSM, AWS KMS, Azure Key Vault |
| Keys | Keys enumerated from the registered vault |
| Algorithms | Algorithm and key parameters for each key |
| Quantum risk | Per-key quantum vulnerability assessment |
When to Use
Managed Key Inventory
Assess the keys held in your HSM or cloud key-management service
Preferred Over Cloud
Use this source instead of the legacy Cloud source for key-management inventory
How to Run
Run a Vault scan from the Cockpit scan wizard:
Register the vault
Ensure the vault is already registered in the Cockpit.
Open Run a Scan
In the Cockpit, go to Run a Scan.
Select the source
In Step 1 (Source), choose Vault, pick the registered vault, then start the scan and review the findings.