Server settings screen

The Server Settings screen groups the General, Access & HTTPS, SMTP, Maintenance & Logs, and Sign-in security tabs.

Use Server settings to define the common generated-password policy, choose runtime log detail, manage recovery tools, save HTTPS and SMTP configuration, and perform controlled maintenance. Top-bar refresh reloads only the active tab’s data; it does not reload the browser page or every Server Settings tab.

Access and authority

  • Owner, Admin, and Auditor roles can read the system tabs. A User is directed to personal Sign-in security instead.
  • Only an Owner can save Access or SMTP settings, upload a certificate, send an SMTP test, import a server backup, restart the service, or run and restore maintenance backups.
  • A read-only license does not disable these Owner-only server actions. It does block migration into a vault because that flow requires an unlocked writable vault and Editor or Manager access.
  • Admin and Auditor can only view. The server refuses these changes from anyone but the Owner.

General

Generated password policy

Manual Active Directory password assignment and automated rotation use the same policy. Length is 16–128 characters. Lowercase, uppercase, digits, and symbols are independent choices, and generation guarantees at least one character from every selected class. Symbols use a Safe or Extended profile, with an option to omit visually ambiguous characters. Each run keeps the policy it started with, so a later change does not alter work already started.

Runtime log level

Choose DEBUG, INFO, WARN, or ERROR; the effective level is shown separately. This changes how much the service logs but never reduces audit evidence. Even DEBUG never writes passwords, tokens, vault keys, or plaintext secrets. Keep higher-detail logging enabled only for a controlled investigation window.

Encrypted Quick Recovery

Only an Owner can choose Create quick recovery package. The server prepares the profile and the vaults you can access; the browser encrypts every record except files with a separately generated key. The result is a .vpr.json file. The key is masked, can be revealed or copied, and is cleared from the screen after five minutes; keep the file and key in separate locations.

The package excludes file records and their contents, revision history, audit history, license, server configuration, and runtime logs. Its purpose is to bootstrap an empty server profile; import closes every session. It does not replace a full VaultPilot Backup Tool backup.

Administrative tools, full backup, and service

  • The Backup Tool download is VaultPilotBackupTool.exe version 3.0.0; Log Collector is VaultPilotLogCollector.exe version 3.0.2. Both tools have independent version lines and do not inherit the server version. Older PassMan tool names are still accepted.
  • Owner-only download works only when the packaged tool exists on the server; otherwise the screen reports it as unavailable.
  • Backup Tool creates a full-server recovery ZIP. The ZIP container itself is not password protected; even when payload data is encrypted, keep the archive offline and access-restricted.
  • Import server backup restores an approved Backup Tool ZIP or supported encrypted JSON backup with integrity and legacy-format confirmations. It is not a merge and closes every session after success.
  • Restart server service is available only with no unsaved settings. It applies saved configuration and does not wait for a full health check; after connectivity returns, verify service state, HTTPS endpoint, and a fresh sign-in.

Access & HTTPS

Public address or domain and Public port describe the address users should open. VaultPilot always builds an HTTPS address from them. There is no HTTP/HTTPS toggle on this screen.

Choose one certificate source:

  • Automatic certificate keeps the managed-server certificate source.
  • Enterprise certificate accepts a .pfx or .p12 package up to 2 MB and a separate PFX/P12 source passphrase. A saved passphrase is never read back into the UI; leaving the field blank keeps the existing value, and a new one is stored encrypted on the server.

Choose Validate bundle first. The server opens the PFX/P12 with its passphrase, verifies certificate/private-key matching and validity, test-loads it for HTTPS without touching the live service, and shows Subject, issuer, validity dates, and SHA-256 fingerprint. Validation does not replace the live certificate; the validated package can be saved once, by the same Owner, within ten minutes. It goes live only through Save settings. If the save fails, the previous settings and certificate stay in place.

This validation does not certify corporate-CA trust or every required SAN on behalf of the organization. Verify the source and expected hostnames through a trusted channel, then test the real HTTPS address from a separate client after save and service restart.

Changing the public address, port, or enterprise certificate can interrupt browser access after restart. Keep the current working URL and an approved console or server recovery route available before saving.

SMTP

SMTP enabled exposes account name, host, port, sender email, TLS/STARTTLS, authentication, username, and password-or-token fields. SMTP disabled pauses email delivery while in-app notifications and audit logging continue; saved SMTP details remain unless authentication is explicitly turned off and the form is saved.

Important boundaries:

  • SMTP host is a hostname only. Do not enter a URL, credentials, a port, a path, or query data in that field.
  • When authentication is enabled, TLS/STARTTLS, a username, and either a new or already-saved password/token are required.
  • A blank password field preserves an already configured credential. The UI never reads the saved secret back.
  • Recipients and event rules are managed on Notifications, not on this tab. Enabling SMTP requires at least one recipient and one notification event.
  • Send test uses the values currently visible on the screen before they are saved. It requires a test recipient and does not save the draft.
  • A successful test is recorded in the audit history without the password or token.

Shared save and reset behavior

General, Access, and SMTP look like separate tabs, but their server-policy fields share one form and one draft:

  • Save settings submits password policy, runtime log level, public address, certificate selection, and SMTP configuration together.
  • An incomplete enabled SMTP configuration can therefore block a save started from Access & HTTPS. An invalid public host or port can block a save started from SMTP.
  • Reset form discards the unsaved draft across all three tabs and reloads the last settings returned by the server. It is not a server rollback.
  • The Operations tab runs its own actions and has no Save or Reset footer.
  • Save success means the settings were stored. The UI instructs the operator to restart before relying on new values.

When an enterprise certificate is selected, the save uses the package you validated. The certificate, its passphrase, the settings and the audit entry are saved together; if any part fails, the previous certificate and settings stay active. If the validation expired or was already used, validate the file again.

Maintenance & Logs

This tab shows the current database path, database-protection status, service log path, migration import, and category-scoped maintenance backups. Server-backup import and service restart cards live under General, where runtime log level is also selected.

Import server backup from General

Import server backup accepts a VaultPilot Backup Tool ZIP archive or encrypted JSON export. It is a whole-profile recovery operation, not a merge:

  • The Owner confirms the operation before upload.
  • Integrity and authenticity information is checked. A legacy or foreign backup requires a separate downgrade confirmation.
  • The existing organization, users, vaults, encrypted records, file chunks, and audit history are replaced in one step.
  • Imported 2FA bindings are cleared. After import, all sessions are closed and the operator must unlock with the master password from the backup profile.
  • The audit history of the restored profile records the import, its counts, and whether a legacy backup was accepted.

There is no browser-console button here to create or export a full server backup. Create that recovery artifact with VaultPilot Backup Tool.

Import & migration

Choose export file reads supported exports in the browser and opens a preview on the Passwords screen. Bitwarden CSV/JSON, LastPass CSV, KeePass XML/CSV, 1Password CSV, and Chrome/Edge CSV are represented. A .1pux archive is not imported; use the 1Password CSV export. VaultPilot template downloads the product template.

Preview saves nothing. The final import requires an unlocked active vault, a writable license, and Editor or Manager access. Rows are then created or updated sequentially according to the chosen conflict rule, so a later row can fail after earlier rows were saved. Compare the result counts with the audit history before retrying.

Restart server service from General

Restart is enabled only for an Owner with no unsaved Server settings draft. After warning confirmation, VaultPilot restarts the VaultPilotServer service (the legacy PassManServer on older upgraded hosts). It does not wait for a completed health check. The console may disconnect briefly, and only saved settings are eligible to take effect.

The restart request is recorded in the audit history. Verify the service, effective HTTPS URL, and a fresh sign-in after connectivity returns.

Maintenance records

The only cleanup mode exposed is Back up & clear. It works on one category at a time:

CategoryScope
Audit logAudit screen history, chain-check records, and dashboard audit history.
DiscoveryDiscovery jobs, findings, suppressions, and scan policies.
ExecutionsExecution history and finished background jobs; active executions and running jobs are retained.

After warning confirmation, VaultPilot writes a maintenance backup file on the server, records its record count and SHA-256 digest, and then clears that category. Vault secrets, source files, service log files, and the other maintenance categories are not part of this cleanup.

The archive table shows file name, category, creation time, record count, size, digest, and Restore. Restore replaces only the selected category with its backup state. Live records created after that backup can change or be lost; other categories remain unchanged. Both cleanup and restore are recorded in the audit history with category, counts, backup file name, and digest.

Sign-in security context

Sign-in security is a personal-security panel embedded in the Server settings shell, but it is not part of the shared server-settings form. It manages the current user’s master password and 2FA binding. Only an Owner additionally sees the active-session table and can revoke non-current sessions.

While this tab is active, the topbar ? opens Sign-in security, not this page.

Audit and partial-completion boundary

Some of these actions take effect before their audit entry is written. An error response does not always mean that nothing happened:

  • An enterprise certificate goes live only through a validated save; a failed save keeps the previous certificate.
  • Settings can be written before their audit event is appended.
  • A test email can be delivered before its audit event is appended.
  • A service restart can be queued before its audit event is appended.
  • A maintenance backup and category clear or restore can finish before the final maintenance event is appended.
  • A profile import can replace the database before session cleanup completes.
  • A migration import can commit some rows before another row fails.

After an ambiguous error, do not immediately repeat the action. Refresh the relevant screen, check the effective state, review the audit history, and check any maintenance backup it created first.

Screen states

StateOperator response
Waiting for server APIWait for the settings to load. If it persists, verify the current session and server reachability.
CurrentThe loaded draft matches the saved settings returned by the server. This is not proof that an external HTTPS or SMTP endpoint works.
Unsaved changeSave or reset before leaving the task. Remember that the draft spans Access and SMTP.
Restart after save / Restart requiredPreserve a working recovery route, save first, then use the Operations restart action in an approved window.
SMTP disabledEmail is paused; in-app notifications and audit logging continue.
Password saved / No passwordA credential is present or absent on the server. The saved value is never displayed.
Test sendingWait for the result and confirm the destination mailbox before sending another test.
Owner role requiredContinue read-only review or transfer the change to an Owner.
Reading maintenance archiveWait for the backup list to load. Do not infer that no backup exists yet.
No maintenance backupRun Back up & clear only if clearing the selected category is actually intended.
Category maintenance runningDo not start another maintenance category or restart the service.
Importing backupKeep the browser and server available; do not refresh, restart, or upload the file again.
Action returned an errorVerify whether the side effect already occurred before retrying.

Before you act

  • Confirm the active role, license state, tab, and exact intended scope.
  • For Access changes, record the current working URL and arrange server-console access before restart.
  • Validate an enterprise certificate’s origin, hostname coverage, expiry, private key, and recovery copy outside the browser console.
  • For SMTP, confirm the sender, test recipient, recipient list, event rules, and whether the blank password field should preserve the saved credential.
  • Use VaultPilot Backup Tool to create a full recovery backup before whole-profile import or other high-impact server work.
  • Before maintenance cleanup, name the category, capture its visible count, and confirm that the automatic maintenance backup—not a full profile backup—is the intended recovery scope.
  • Before restore, compare the backup category, creation time, record count, and digest, and identify newer records that can be replaced.
  • Before migration, unlock the intended vault, clear unrelated selections, choose the conflict rule, and review every invalid or duplicate row.

Safe evidence

  • Safe to share: the tab name, general state, broad time window, redacted host such as <SERVER_HOST>, public port, certificate source and file extension, SMTP enabled/TLS/auth flags, recipient and event counts, maintenance category, and aggregate success/failure counts.
  • Keep private: exact internal hostnames or IP addresses, database and log paths, PFX/P12 contents, certificate passwords or private keys, SMTP username/password/token, sender and recipient addresses, session IDs, backup ZIP/JSON files, migration exports, record names, raw logs, and copied audit metadata containing customer context.
  • Share exact backup file names or full digests only with support@vaultpilot.io, and only when they are needed for reconciliation.

When to stop

Stop if the current working URL is not recorded, server-console recovery is unavailable, certificate ownership or private-key coverage is unclear, SMTP would send to an unapproved recipient, the active vault or conflict rule is uncertain, a backup category or timestamp does not match the intended restore, the maintenance archive cannot be read, newer category records have not been assessed, or any previous attempt returned an ambiguous error. Confirm the last saved state before continuing.

Operator notes

Do not describe Save as an immediate runtime change, Restart as a completed health check, SMTP test failure as proof that no message was delivered, maintenance backup as a full vault backup, migration preview as a completed import, or category restore as a whole-server rollback. Never share certificate packages, credentials, recovery archives, local paths, or raw logs.

Back to Documentation