Key Management (KMS)
Entry: /kms, then Keys & secrets or Certificates. KMS stores Group-scoped credentials, private keys and certificates. You need an enabled, licensed Module and the appropriate Group access. Reading metadata, managing records and revealing secret material are separate permissions.
Store a credential or certificate
- Select the correct Group and open the appropriate inventory. Choose Add secret.
- Select Secret type and enter Name, optional Target / device, Username and expiry. Names, targets, usernames and notes are readable metadata: never put a password in these fields.
- Enter the value in Secret value, or use the dedicated private-key/certificate fields. For a certificate chain, place the leaf certificate first. A supplied private key must match it; expiry comes from the certificate.
- Choose Add secret and confirm the new metadata row. The stored credential does not change the target system.
Reveal and replace a value
- Open the record's Settings → Reveal secret. Confirm the reveal action only when you need the current material.
- Read the value in the reveal dialog. Access is recorded; the displayed material clears after 30 seconds, or when the dialog closes or the page is hidden.
- To replace stored material, choose Settings → Replace secret and provide the complete new value or bundle. Review the target and submit.
- Update or rotate the credential on the actual target through your approved operational process, and verify that the stored value matches the intended target state.
Retire a secret deliberately
- Use Edit metadata for descriptive changes; it does not replace secret material.
- Choose Archive secret when the record should no longer be revealed or replaced. Revoke target access separately if required.
- An archived record can be deleted using Delete secret and its exact name. Review this carefully: live material is removed, while backup and audit retention follow their separate policies.
Blockers and limits: missing reveal permission, an archived record, a stale version or unavailable installation encryption custody can block the action. Ask the responsible administrator to investigate without sending them the secret in a support message. KMS permits 1,000 retained records and 8 MiB of material across the installation, including archives, with 64 KiB per record; over-limit writes are rejected. KMS does not provide automatic target rotation, certificate renewal, secret-history recovery or secret export.