Each box contains information (metadata) required to manage the secrets within the box, and a collection of secrets. The metadata can include: 

  • Name—The name of the box.
  • Description—The description of the box.
  • Tags—A list of name and value pairs.
  • Max Secret Version—The maximum number of secret versions to keep. Changing a secret value creates a new version, and the previous secrets are kept according to the maximum number of versions that you configure.

    This field only takes into account non-staged Secret versions that would be persisted. For example, if Max Secret Versions is set to 5 and a Secret has 7 Secret versions but two are non-staged versions CURRENT and PENDING, 5+2=7 versions are kept.

    If the administrator changes the value of Max Secret Versions and some old versions that have been kept have to be deleted to keep the count consistent with the new Max Secret Versions value, deletion will only happen when a new Secret version is created. For example, the previous Max Secret Versions value was 10 and the administrator reduces it to 5. If a Secret had 10 non-staged versions and 2 staged versions, secret versions are not deleted right away and Cryptographic Security Platform Vault for Secrets webGUI continue to show the 10 non-staged + 2 staged, 12 versions, in total until a new Secret version is created. At that point, the older non-staged versions are deleted and 5 non-staged + 2 staged will be shown, 7 in total.

  • Checkout Duration—The default leasing period for secrets. Secrets are leased when a user or an application wants to use the secret to access the resource. The secret must be checked-in before the lease expires.
  • Secret Rotation Duration—How often the secrets must be rotated. Applies only to managed secrets.
  • Secret Duration—The default expiration period for the secrets.