logo

NJP

How to automate fulfillment of Entrust certificates with ServiceNow

Import · May 05, 2022 · video

hello everyone my name is steve emerson and i'm the outbound product manager for itom visibility here at servicenow today i'm going to demonstrate how you can automate certificate fulfillment requests for end trust certificates with servicenow servicenow's certificate inventory and management provides a holistic solution for discovery life cycle management and fulfillment of entrust tls certificates before i show you the demo here is a quick overview of how it works first we provide you with a single pane of glass for you to visualize certificate workflow automation which enables you to track automation value over time automated workflows begin by submitting requests in the service catalog for new renew and revoke next a routing policy processes the requests to the entrust ca gateway with the option of having an approval before being processed after that workflow automation sends the request to the ntrust ca gateway for processing once the request is completed a change request is created to ensure governance of the process once processed by the nsca gateway the requested certificate and corresponding certificates from the chain are stored in the cmdb by automating certificate fulfillment requests for end trust with servicenow you will be able to reduce time and effort with automated processes establish governance procedures and reduce security risk and improve the customer experience now on to our demo we will start with the single pane of glass dashboard that enables you to see the automation value over time here you can see up top the number of open requests we have for new renew and revoke tasks now as you can see they're all zero because we are automating processes here the only reason why these things would be larger than zero would be a situation where we are waiting for approvals before these requests can be processed the whole idea behind automation is you submit a request and there's automation behind the scenes that processes it and it closes out here we see certificate task automation trends now i'm only showing one month here but as as you can imagine as we start to use this product over time you'll start to see trends as to how many new certificate requests how many renews how many revokes you're tracking over time and then of course down below here we can see our task state by the last 30 days as well as our tasks by certificate authority let's go ahead and request a new certificate we'll click on our service catalog and we have a category for certificate management and we have a category for automated flow these three requests here are the ones that you would use if you want to request automated fulfillment for your certificates through servicenow we have a new renew and revoke the revoke catalog item here is only available or shown to those individuals that have the pki admin role because we don't want just anyone to request a certificate revocation let's go ahead and request a new certificate the purpose of this certificate is external we'll paste in the certificate signing request as soon as you click out of that field you can see validation on the right hand side about the subject common name and more details about the certificate this gives the requester the option to back out if he or she believes that this is an invalid data here i'm okay with this i'm going to proceed you can choose the maximum validity period by default we set it the maximum of 365. for each certificate you could set this number lower if you'd like maybe you're only requesting it for a temporary project for example here we can relate this certificate to an application an application service or application server by clicking these these little icons here and and then searching the cmdb for the relevant information here we're going to choose a certificate owner group i have one called certificate owners as well as an owner of the certificate i'll choose myself this information here gets stored on the samedb and will be used later for tracking ownership as well as generating the automated renewal tasks which i'll talk about next first we'll choose the environment i'll choose development but you can certainly choose any other environment here and you can even update this form to your own needs as well as renewal tracking by default servicenow generates a certificate renewal task 60 days prior to expiration that number can be set by you as well but there's two types of tasks that get created priority one these would be for your most business critical certificates those can be tracked separately and can be reviewed on a more regular basis than all of your other certificates which would be more of a priority three task or if you're just requesting this certificate temporary purposes maybe it's for a project and you don't want to renew it you could say do not care do not create renewal tasks we'll go ahead and submit this request and as soon as we do we will start to see some information here in the activity log we've triggered the automated flow we've received the serial number id and right now it is communicating with the ntra ca gateway to process the request and it is already completed now if we refresh this task we will see that the requested certificate along with the certificate chain are attached here to the task as well as stored in the cmdb the person can then take these certificates and apply them to the specific system to the server or to the host and if we scroll down we can see that a change request was created as well this was a normal change request created for tracking the the request for that certificate that'll go through normal change management process now this was processed by a routing policy let's take a look at the routing policy the routing policy and you could have one to many of these it's basically a set of criteria that is tried to match up against the request that you've just submitted this here points to an entrance ca gateway if i look at this i can see that it points to the base url that is going to process the end trust request entrust also requires the certificate authority identifier as well as the certificate profile you can get that from the intro ca gateway and then you can choose the purpose of the certificates if this is external right you'll set a credential alias in servicenow you need a credential in order to connect from servicenow to entrust for authentication purposes here we can choose the environment that this is for so development disaster recovery production sub production as well as the assignment group for any manual tasks tasks that could get created as part of the process here's the maximum validity period we can set this number to a max of 365 or anything lower than that now when i say that you can have multiple routing policies per ca it really comes down to setting this information at the bottom the subject common name the alternative name and all the certificate data most organizations don't like to use wild cards which are what i'm showing here it's not a best practice at all but you can certainly set specific information in these fields and then when you submit a request on the service catalog it attempts to match up that data to data on a routing policy once it matches it gets processed by that specific routing policy and you may choose to require approvals which is actually also an industry best practice for each request that goes through now i have set this to not approval so we can streamline the automation during this demo now that i've showed you the routing policy let's take a look at the service catalog once again and we'll go into the automated flow now the renewal i will show you the form but i'm not going to process this because it's pretty much the same the only thing missing is the creation of the tasks do we want to create priority ones priority threes or do not renew we carry over whatever was selected when when we requested it originally in the course here you'll have to choose the certificate rather than just pasting in the csr and creating one from scratch but let's go through and process a certificate revocation here we have to choose an issued certificate so i will search for one that i just created domain.com and i will choose a reason why we do why we want to revoke this no longer needed we'll submit it and we get this one more box that just confirms that we want to do it just just make just to make sure we're not picking the wrong thing here because once you revoke a certificate of course that can cause it to stop working which would not be a good thing so let's go into that task it is currently being processed and then now it has completed let's take a look at the status of the certificate here we can see that the certificate is now revoked it's revoked here in servicenow and the cmdb as well as on the interest ca gateway and if we scroll down here we can see that a change request was created as well and as we create an emergency change request for a certificate revocation so that it can go through um a different change process may this is not to you know to be taken lightly okay let's go back to our certificate management dashboard and we are looking at our automated flow tab which is that single pane of glass that helps you visualize your certificate workflow automation trends here we can see that the number of new requests went up the number of revoke requests went up the total number of requests went up however we still have a bunch of zeros across the open requests that is because we use automation to increase certificate fulfillment efficiency so by using servicenow within trust you'll be able to reduce time and effort with automated processes establish governance procedures as well as reduce security risk and improve the customer experience if you have any further questions about our certificate management solution please leave a comment below or reach out to your servicenow account team thank you for watching and have a great rest of your day

View original source

https://www.youtube.com/watch?v=blV58N9PuOs