How a managed certificate gets onto a Symantec SSL Visibility appliance (Blue Coat SSLVA) with Monopam, which route to use, and what each one needs. This appliance is different from the other devices in this space: Broadcom does not offer its remote API as a generally available, supported interface, so the route that always works is the appliance's own documented import, and Monopam's job is to produce exactly what that import reads.
|
Route |
What it needs |
Status |
|---|---|---|
|
Keydata for import (recommended) |
Nothing from the appliance but its own import screen |
Produces the file the appliance documents; verified end to end inside Monopam |
|
Console automation (AI) |
A gateway that can reach the appliance's web console |
Built and verified against a stand-in console; not yet run against a real appliance |
|
Management API |
A REST API on the appliance that answers and accepts a session |
Expected to fail on most appliances: |
Before you start
-
The certificate must be in Monopam with its private key (an SSL Visibility keyring is a certificate and its key). A certificate that was only discovered by a scan cannot be used.
-
The appliance's management address, and an administrator account on it.
-
Decide who does the import: a person on the appliance's own screen (Keydata), or a gateway driving that screen for you (Console automation).
1. Add the target
Open the certificate → Deployment tab → Add Target, and set Server Type to Symantec SSL Visibility (Blue Coat).
|
Field |
What it means |
|---|---|
|
Appliance Resource or Management host / Management port |
Where the appliance is. The call leaves the Monopam application server, not a gateway |
|
Username / Password |
The appliance's management credential. A literal value or a Vault reference such as |
|
Appliance version |
|
|
Keyring Name |
The known-certificate-and-key (keyring) to create or replace, for example |
|
Inspection Policy (optional) |
The resigning or inspection ruleset to point at that keyring |
|
Apply the staged change |
Whether the change is applied on the appliance or left staged |
|
Deploy through the appliance console (AI) |
Switches to the console route, with an optional Console address when the console is not at |
2. Detect: find out what this appliance actually answers
Press Detect on the target. It signs in and reads, writes nothing, and lists every path it tried:
✓ keyrings: GET /api/v1/... → 200
✗ rulesets: GET /api/v1/... → 404
Three outcomes, and all three are useful:
-
Something answers. The keyring and policy names it read become pickers on the fields above, and the REST route is worth trying.
-
Sign-in fails with
HTTP 405. Expected. It means the appliance's web interface answered the API path and refused the method: there is no remote API listening there for Monopam. The attempt list carries each answer'sAllowandServerheaders, which is the evidence. -
Nothing answers at all. Either the management port is different, or REST is not enabled or licensed on this appliance.
Whatever it shows, send the list to Monofor support: it is what tells us the appliance's real contract, and it is the only way the guessed paths ever become confirmed ones.
3. Keydata for import: the route that does not need an API
This is the appliance's own documented import, and the one to use unless Detect proved otherwise.
Save the target first, then press Keydata for import. Monopam builds the keydata file this target's certificate makes (#keyring:, #visibility:, the private key, the certificate), encrypts the key under a fresh passphrase, and shows:
-
a single-use address the appliance fetches the file from, valid for 15 minutes,
-
the passphrase, shown once and stored nowhere,
-
the steps to follow on the appliance.
On the appliance:
-
PKI → Keyrings → Import (or Add → Import).
-
Paste the address, enter the passphrase, import. The keyring now holds the certificate and its key.
-
Policies → Rulesets → your ruleset: set its resigning keyring to that keyring.
-
Apply the change.
If the appliance cannot reach Monopam (a management network that does not route to the platform is normal in the places this appliance lives), press Download the file in the same panel and either put it on a web server the appliance does reach, or use PKI → Known Certificates and Keys → Add → Paste Text and paste its contents. Delete your copy afterwards: it carries the private key. The unused address simply expires.
What is audited. Preparing the link passes the same approval gate as a PFX export, and both the preparation and the appliance's fetch are recorded as Certificate Private Key Exported. The address works exactly once; a second fetch answers 404.
4. Console automation: the same import, driven for you
Switch on Deploy through the appliance console (AI) and the deployment becomes unattended without needing an API: Monopam prepares the keydata, a gateway opens the appliance's own web console, signs in with the management credential, imports the file (by the single-use address, or by pasting its contents when the appliance cannot reach Monopam), repoints the inspection policy and applies the change.
-
The instruction is a goal in words, not a recorded click path. The agent reads the console it is looking at and finds the screens itself, so a firmware upgrade that moves a menu does not break it: the path it finds is replayed on the next renewal and re-learned when the console changes.
-
The values it types (the address, the passphrase, the management password) travel as placeholders and are substituted on the gateway, so they never reach the model.
-
The gateway needs network access to the console; Monopam itself does not.
Status, plainly. This route is complete and was verified end to end against a stand-in console page (sign in, fill, click, wait for the confirmation, and a failure that names the step it stopped at). It has not yet been run against a real SSL Visibility appliance. The first run on a real one is worth watching, and the goal sentence can be adjusted to that console's own menu names without any code change.
5. The management API route
If Detect showed a working API, the ordinary deployment applies: press Deploy on the target and Monopam imports the keyring and repoints the policy over REST.
Two things to know before relying on it:
-
Broadcom's position. The SSL Visibility remote API is not generally available and is not supported through technical support; the appliance's documentation describes importing key material through its own interface. A customer appliance that refuses every REST path is behaving as expected, not misconfigured.
-
Every run is recorded in full. View output on the run holds the appliance address, the path set used and whether it is confirmed, every request with method, path, status and timing, the field names sent, and the appliance's answer with keys, tokens and passwords removed. A failure names the step, the request, the status and what that status usually means. This is deliberate: these tests cannot be repeated often, so one run has to carry its own evidence.
When something goes wrong
|
What you see |
What it means |
|---|---|
|
|
Something answered and refused the method: the management web interface is on that port, not a REST API. Use Keydata for import or the console route. The failure carries the answer's |
|
Sign-in fails with 401 or 403 |
The management credential was refused, or the account may not use the API. Check it on the appliance's own login first |
|
Detect answers nothing at all |
Wrong management port, or REST is not enabled or licensed. The attempt list shows what was tried |
|
The deploy succeeded but the appliance does not show the keyring |
Check the Appliance version: a path set that belongs to another generation can answer without doing what you expect. Run Detect and use the generation it reports |
|
The import on the appliance rejects the file |
The passphrase is per link: a new Keydata for import press produces a new file and a new passphrase. Use the pair from the same panel |
|
The address says it has already been used |
It works once, by design. Press Keydata for import again |
|
A rollback deleted nothing |
A keyring counts as absent only on |
What this target type does not do
-
It does not require, and should not be assumed to have, a supported REST API on the appliance.
-
It does not reach the appliance through a gateway on the API route: that call leaves the Monopam application server. Only the console route uses a gateway.
-
It does not create rulesets. It points an existing one at the keyring.
-
It does not touch the appliance's credentials, users, network settings or power state, and the console agent is told so explicitly.
Monopam Certificate Manager. Addresses, names and keyrings on this page are examples.
Device guides: F5 BIG-IP · FortiManager · NetScaler · Panorama · Apple Developer · SSL Visibility