Group API Key
A Group API Key is required to register a Connection Manager to a Connection Manager group and the Guardian appliance itself. The API key is unique to each Connection Manager group and must be stored within the Connection Manager's configuration files. The following topic describes how to access and regenerate a group's API key from within the Connection Managers tab (
Tip: If a Connection Manager's configuration file does not contain an up-to-date Group API Key, or it is removed for any reason, the connection to the Guardian appliance is severed. To resume the connection and continue scanning, you are required to provide a new Group API Key within the configuration file. For all Connection Manager types other than the Self-Contained Linux Connection Manager, this can be done manually.
Access Group API Key
To access an existing Connection Manager's Group API Key for the purpose of adding a new Connection Manager to it, complete the following steps:
-
In the Connection Managers tab, select the required Connection Manager group from the Groups drop-down menu.
-
Click the Add Connection Manager button. The Group API Key for the selected group is displayed.
Then, you can add the API key to the Connection Manager's configuration file and restart the service to begin scanning nodes via your newly added Connection Manager.
Regenerate Group API Key
To regenerate an existing Connection Manager's Group API Key for security purposes, complete the following steps:
Tip: Regenerating the Group API Key on a regular basis helps maintain the security of your environment and also has the added benefit of regenerating the associated private key(s).
-
In the Connection Managers tab, select the required Connection Manager group from the Groups drop-down menu.
-
Click the Add Connection Manager drop-down, then select Edit Group. The Edit Connection Manager page is displayed.
-
Click the Regenerate Key button to regenerate the API key for the selected group.
If you choose to regenerate the API key for a Connection Manager group you will need to change the existing API key in the configuration file to the new value for each of the group's Connection Managers. Then, restart the service. Otherwise, the Connection Managers will lose their connectivity to your Guardian instance and be unable to scan nodes. For all Connection Manager types, other than the Self-Contained Linux Connection Manager, this can be done manually.
Warning: If you regenerate the API key for a group that contains a Self-Contained Linux Connection Manager, the connection is permanently severed and you are required to re-install and deploy the Connection Manager using the regenerated API key.
Additionally, when creating a new Connection Manager group, an associated Group API Key is generated. For more information, see Add Connection Manager Group.