Migration from Credentials to Secrets

For the Imprivata CPAM 26.1.8 release, the platform enables the migration of Legacy Credentials into the Vault as secrets. The migration runs automatically during the scheduled database upgrade.

The migration preserves existing credential values, associations, permissions, and service bindings. After migration, credentials become secrets and can use new capabilities such as checkout, approval workflows, and enhanced audit history.

Change Reference

The following table contains the key changes from credentials into secrets:

Area Before Migration After Migration
Storage Model Global Credential Pools

Vault-based secret management

Checkout Not available Available with optional approval workflows
Audit History Basic tracking Detailed audit trail with timestamps
External Providers Supported with limited scope Full integration with providers
Categories Credential categories Secret categories
Data Preservation Credential data, integration to applications and services are preserved. Secret data is preserved

During the migration, the following data is preserved:

  • Values, including passwords, SSH Keys, and API tokens.

  • Site, service, and user associations.

  • User and group permissions.

  • Access rules.

  • Service bindings.

  • Existing API and third-party integrations.

Migration Process Considerations

Use the following sections to plan the migration:

FAQs