Certificates on Symantec SSL Visibility

How a managed certificate gets onto a Symantec SSL Visibility appliance (Blue Coat SSLVA) with Monopam, which route to use, and what each one needs. This appliance is different from the other devices in this space: Broadcom does not offer its remote API as a generally available, supported interface, so the route that always works is the appliance's own documented import, and Monopam's job is to produce exactly what that import reads.

Route

What it needs

Status

Keydata for import (recommended)

Nothing from the appliance but its own import screen

Produces the file the appliance documents; verified end to end inside Monopam

Console automation (AI)

A gateway that can reach the appliance's web console

Built and verified against a stand-in console; not yet run against a real appliance

Management API

A REST API on the appliance that answers and accepts a session

Expected to fail on most appliances: HTTP 405 from the web interface is the usual answer

Before you start

  • The certificate must be in Monopam with its private key (an SSL Visibility keyring is a certificate and its key). A certificate that was only discovered by a scan cannot be used.

  • The appliance's management address, and an administrator account on it.

  • Decide who does the import: a person on the appliance's own screen (Keydata), or a gateway driving that screen for you (Console automation).

1. Add the target

Open the certificate → Deployment tab → Add Target, and set Server Type to Symantec SSL Visibility (Blue Coat).

Field

What it means

Appliance Resource or Management host / Management port

Where the appliance is. The call leaves the Monopam application server, not a gateway

Username / Password

The appliance's management credential. A literal value or a Vault reference such as {{Vault.<name>.Password}}

Appliance version

Detect from the appliance by default, or 4.5 / 5.x / 6.x. It selects which REST paths Monopam would use

Keyring Name

The known-certificate-and-key (keyring) to create or replace, for example www_example_com

Inspection Policy (optional)

The resigning or inspection ruleset to point at that keyring

Apply the staged change

Whether the change is applied on the appliance or left staged

Deploy through the appliance console (AI)

Switches to the console route, with an optional Console address when the console is not at https://<management host>:<management port>/

2. Detect: find out what this appliance actually answers

Press Detect on the target. It signs in and reads, writes nothing, and lists every path it tried:

✓ keyrings: GET /api/v1/... → 200
✗ rulesets: GET /api/v1/... → 404

Three outcomes, and all three are useful:

  • Something answers. The keyring and policy names it read become pickers on the fields above, and the REST route is worth trying.

  • Sign-in fails with HTTP 405. Expected. It means the appliance's web interface answered the API path and refused the method: there is no remote API listening there for Monopam. The attempt list carries each answer's Allow and Server headers, which is the evidence.

  • Nothing answers at all. Either the management port is different, or REST is not enabled or licensed on this appliance.

Whatever it shows, send the list to Monofor support: it is what tells us the appliance's real contract, and it is the only way the guessed paths ever become confirmed ones.

3. Keydata for import: the route that does not need an API

This is the appliance's own documented import, and the one to use unless Detect proved otherwise.

Save the target first, then press Keydata for import. Monopam builds the keydata file this target's certificate makes (#keyring:, #visibility:, the private key, the certificate), encrypts the key under a fresh passphrase, and shows:

  • a single-use address the appliance fetches the file from, valid for 15 minutes,

  • the passphrase, shown once and stored nowhere,

  • the steps to follow on the appliance.

On the appliance:

  1. PKI → Keyrings → Import (or Add → Import).

  2. Paste the address, enter the passphrase, import. The keyring now holds the certificate and its key.

  3. Policies → Rulesets → your ruleset: set its resigning keyring to that keyring.

  4. Apply the change.

If the appliance cannot reach Monopam (a management network that does not route to the platform is normal in the places this appliance lives), press Download the file in the same panel and either put it on a web server the appliance does reach, or use PKI → Known Certificates and Keys → Add → Paste Text and paste its contents. Delete your copy afterwards: it carries the private key. The unused address simply expires.

What is audited. Preparing the link passes the same approval gate as a PFX export, and both the preparation and the appliance's fetch are recorded as Certificate Private Key Exported. The address works exactly once; a second fetch answers 404.

4. Console automation: the same import, driven for you

Switch on Deploy through the appliance console (AI) and the deployment becomes unattended without needing an API: Monopam prepares the keydata, a gateway opens the appliance's own web console, signs in with the management credential, imports the file (by the single-use address, or by pasting its contents when the appliance cannot reach Monopam), repoints the inspection policy and applies the change.

  • The instruction is a goal in words, not a recorded click path. The agent reads the console it is looking at and finds the screens itself, so a firmware upgrade that moves a menu does not break it: the path it finds is replayed on the next renewal and re-learned when the console changes.

  • The values it types (the address, the passphrase, the management password) travel as placeholders and are substituted on the gateway, so they never reach the model.

  • The gateway needs network access to the console; Monopam itself does not.

Status, plainly. This route is complete and was verified end to end against a stand-in console page (sign in, fill, click, wait for the confirmation, and a failure that names the step it stopped at). It has not yet been run against a real SSL Visibility appliance. The first run on a real one is worth watching, and the goal sentence can be adjusted to that console's own menu names without any code change.

5. The management API route

If Detect showed a working API, the ordinary deployment applies: press Deploy on the target and Monopam imports the keyring and repoints the policy over REST.

Two things to know before relying on it:

  • Broadcom's position. The SSL Visibility remote API is not generally available and is not supported through technical support; the appliance's documentation describes importing key material through its own interface. A customer appliance that refuses every REST path is behaving as expected, not misconfigured.

  • Every run is recorded in full. View output on the run holds the appliance address, the path set used and whether it is confirmed, every request with method, path, status and timing, the field names sent, and the appliance's answer with keys, tokens and passwords removed. A failure names the step, the request, the status and what that status usually means. This is deliberate: these tests cannot be repeated often, so one run has to carry its own evidence.

When something goes wrong

What you see

What it means

HTTP 405 on sign-in

Something answered and refused the method: the management web interface is on that port, not a REST API. Use Keydata for import or the console route. The failure carries the answer's Allow and Server headers

Sign-in fails with 401 or 403

The management credential was refused, or the account may not use the API. Check it on the appliance's own login first

Detect answers nothing at all

Wrong management port, or REST is not enabled or licensed. The attempt list shows what was tried

The deploy succeeded but the appliance does not show the keyring

Check the Appliance version: a path set that belongs to another generation can answer without doing what you expect. Run Detect and use the generation it reports

The import on the appliance rejects the file

The passphrase is per link: a new Keydata for import press produces a new file and a new passphrase. Use the pair from the same panel

The address says it has already been used

It works once, by design. Press Keydata for import again

A rollback deleted nothing

A keyring counts as absent only on HTTP 404; any other failed read stops the capture, so a rollback can never delete a keyring whose existence was not established

What this target type does not do

  • It does not require, and should not be assumed to have, a supported REST API on the appliance.

  • It does not reach the appliance through a gateway on the API route: that call leaves the Monopam application server. Only the console route uses a gateway.

  • It does not create rulesets. It points an existing one at the keyring.

  • It does not touch the appliance's credentials, users, network settings or power state, and the console agent is told so explicitly.


Monopam Certificate Manager. Addresses, names and keyrings on this page are examples.

Device guides: F5 BIG-IP · FortiManager · NetScaler · Panorama · Apple Developer · SSL Visibility