Automating manual tasks like requesting a new certificate and renewing expired certificates can increase the productivity of the public-key infrastructure (PKI) team by approximately 30% and help digitize manual workflows.
The ServiceNow Certificate Inventory and Management store application provides a platform-based approach to the lifecycle management of TLS certificates. This solution, combined with task fulfillment, can provide a methodical approach to the request management and renewal management process.
Compliance and security hygiene go hand in hand, and strong TLS management is a priority. A lack of visibility to deployed TLS certificates and expiry of TLS certificates can result in service outages and data breaches. The largest consumer credit reporting company commented on how “TLS certificates had expired about 10 months before the breach occurred, meaning that encrypted traffic was not being inspected throughout that period.”
Key features
- Workflows for the request to fulfill/renew certificates via a Service Catalog.
- Policy-based framework to route digital certificate request/renewal and revoke workflows.
- Auto-discovery of TLS certificates in CMDB common service data model using IP/port scans and URL-based methods.
- Single pane of glass dashboard provides insights into workflow task management for the PKI team and provides comprehensive visibility to the deployment of certificates.
- Expiry pipeline view provides visibility to TLS certificates expiring in 30, 60, and 90 days.
- Automatic incident creation for expired TLS certificates.
- Discover, relate, and reconcile cloud certificates (AWS/Azure/GCP certificate manager) to your cloud apps and compute.
- Get Automatic Certificate Management Environment (ACME) protocol support for multiple certificate authorities with validation.
Note: The ACME protocol is a communications protocol for automating interactions between certificate authorities and their users' servers, allowing the automated deployment of public key infrastructure.
New
- Extended ACME capabilities: Request, renew, and revoke certificates via DigiCert, Sectigo Universal, and Sectigo Public ACME CAs. If your organization uses a different CA that is compatible with the ACME protocol, you can add it and use it to extend automated certificate management to that CA.
- CyberArk PVWA private key storage: Store private keys in CyberArk PVWA for automated certificate operations, alongside HashiCorp Vault and Azure Key Vault.
- Certificate format support: Receive issued certificates in DER or PKCS12 format, instead of PEM.
Fixed
- Fixed issues in the Microsoft CA certificate request flow when the root CA is the in the Trusted Root store.
- DigiCert certificate order status tracking now processes issued orders correctly and displays clear error messages in logs when credential alias types are mismatched.
- Duplicate POST/PUT requests to DigiCert are no longer sent on non-429 HTTP errors, preventing unintended certificate operations.
- Certificate Inventory and Management discovery now correctly links server/domain certificates to the root level when only the server certificate is retrieved during port scan discovery.
- Certificate Task Status Update notifications are no longer sent to large numbers of users.
Required plugins and products
- ITOM Visibility subscription
- Configuration Management for Scoped Apps (CMDB) (com.snc.cmdb.scoped)
- Discovery plugin (com.snc.discovery)
App dependencies
- CMDB CI Class Models