How to manage certificates and automate certificate fulfillment with a single platform
[Music] [Music] [Music] [Applause] [Music] [Music] [Music] [Music] all right let's get started so good morning good afternoon and good evening everyone and welcome to our webinar today thank you for being here today we're going to cover how to manage and automate certificate fulfillment with servicenow this is part of our item visibility and governance webinar series that we are hosting on the third tuesday of every month so at the same time so as you are here today we will invite you back to one month from today for the next session now this webinar is part of the live on servicenow webinar series on the community uh this is a curated series of events across multiple servicenow areas right not just itom for what you're here for today but certainly also for itsm hr i tom itam and much more so we invite you to please attend these to learn how you can easily implement and adopt more features that you are entitled to just a bit of a you know of a few housekeeping rules here everyone's line is muted so we ask that you please use the q a feature to ask questions throughout today's session and when you do ask a question uh please feel free to introduce yourself who you are what company you're with so we'd love to get to know who you are we're going to have two polls today so we ask that you please participate in those polls we are recording today's session and it will be posted um on the community as a follow-up and then finally after our this session ends today you'll be prompted to fill out a survey we always appreciate your feedback on how we can improve these sessions for future so a little bit about me my name is steve emerson i'm the outbound product manager for itom visibility here at servicenow and as an outbound pm i wear many hats right product evangelism um you know help customers with their you know value realization as well as i do some internal sales enablement but that's just to name a few things right but what i love most about my role is being able to speak with customers and hear how you're using our products and i get to share how we you know how you can use our itom products to help you achieve your business goals i've been at servicenow for five years now but i spent the bulk of my career working across a multitude of disciplines in i.t uh in large it organizations so i know what it's like to be in your shoes i have managed certificates before as a customer and it wasn't a fun job i'd like to kick it off first with a poll what we'd like to understand is today we're going to be talking about certificate inventory management right can you just tell us what is your experience with this application right and just choose one answer if you could launch the pulse meal so first you know response would be oh servicenow does that we've looked at it we're in the process of of implementing it or we're using it in production let's just take the next 10 or so seconds to answer that poll and i see a lot of ventures coming in and really thank you guys for your support here this just helps us get to know the audience and how we can structure this webinar better all right associate answers coming in i think we're good chamia we can end it now so it looks like um you know a lot of you didn't know that we do certificate management so it's good you're here today you'll learn all about how we do that uh somehow you have looked at it about you know the most of you actually have looked at it uh some of you are in the process of implementing it and we have a you know a few customers that are in production so thank you for your responses there and we'll go ahead and proceed with uh presentation here all right so why are we here today right the challenge of certificate management and i can tell you this myself right because i've done it before is you know across any organization there's just increasing number of certificates right and they're typically purchased or maybe even managed by separate businesses right you know business units or departments they all own their own applications and it's very difficult for the central i.t team to keep track of all the certificates because obviously when they expire you've got some big challenges there which we'll talk about in a second right so it's a cumbersome process for tracking all that and you know whether or not you have active ones or or or inactive ones i personally used to use spreadsheets and i was only told you know about certain certificates from from other departments i had a good understanding of what i had but necessarily get you know gathering data from others was a very big challenge and it was always that manual process for renewing the certificates when they were about to expire right so what happens when a certificate expires right you could uh look in the news any day and you'll see updates about you know security risks or or outages because of certificate expirations right um huge it's a huge issue across the industry today and of course for the it staff it introduces a lot of manual and complex processes to take care of so servicenow has a solution for this it's called certificate inventory and management and really helps customers prevent outages from expired certificates and if you're familiar with servicenow discovery right this is a layer on top of discovery that helps you to discover your entire certificate of state via three methods and we'll go into details about all these methods as i go throughout you know today's presentation uh port based uh certificate authority based and url based for the certificate authorities we have five that we support out of the box which are digicert and trust godaddy sectigo and microsoft and we we then populate all those certificates into the cmdb so that you have an accurate record of that and if you discover with a port-based method we'll be able to tell you exactly where that certificate is installed and be able to also see the under the underlying relationships back to other dependencies right we provide customers with an option to use standardized request forms for requesting new or renewed certificates uh this really helps you standardize on the data that you collect and the process that is followed for that with tasks we help you visualize your entire inventory with a single pane of glass dashboard we generate proactive renewal tasks up to 60 days prior to expiration uh by default and we'll talk about how you can change that if you want at the same time we also integrate with you know natively with our incident process and also with our event management process to generate uh you know events and alerts for expired certificates and we also integrate with slack for notifications as well but you know as part of itom visibility which is where certificate management lies you also have access to service mapping so if you have your services mapped which is where you understand how your components impact the you know are you know support the business you'll be able to tell how a certificate supports the business right so if certificate abc is going to be expiring 60 days you can understand which how that impacts my business right so this solution is going to help you overall you know reduce risks improve your processes speed up the process and help you prioritize as a follow-on to that we also introduced automation back about a year ago we introduced the you know the ability to automate certificate fulfillment to specific certificate authorities we continue to grow that list of cas but today we support digicert and trust out of the box and for this it i'll explain how it works but i'll show it to you of course we help you visualize the workflow automation trends in a single pane of glass dashboard so you can understand what is the value of this solution that i have invested in right you can understand you know we have we provide out of the box catalog items for new renew and revoke right to start the automation process to collect the data needed to process the request we then have a routing policy that processes that request to the certificate authority and then automation kicks in for new renew and revoke requests to execute the automation directly to the ca at the same time we create a change request to ensure governance of that process and then uh finally right of course the seem to be is updated we we pull back the certificates from the those two cas the certain interest we attach them to the task records and we also store a copy of those certs in the cmdb and of course you know here you're going to be able to speed your time to fulfillment you're going to have governance processes and you're going to reduce risk of human error last poll before we get into our demo here we'd like to understand which of these certificate authorities does your organization use and this is a multi-select here so please go ahead and select which ones you use there may be others that you use but we're specifically focusing on these here today all right keep it coming thank you all for your for your participation here guys uh all right shamil you can go ahead and in that poll so it looks like the bulk of you are using microsoft followed by digicert and entrust right and then godaddy section global sign and let's encrypt all have some usage so thank you guys for filling that out and we can stop sharing that poll and i'm going to go ahead on to our next section here so how do we get started you go to our certificate inventory and management application like a lot like most of the itom applications are available now via the servicenow store we have shifted to the store for new applications and and feature updates because uh it allows us to be more agile and get products and features into your hands faster so go to the store at servicenow.com do a search for certificate inventory management and basically you click on get and you tell the instance you want to put it on and then it validates whether or not you have an entitlement of course and then once you have that that approved in your instance you'll be able to search for it if you go to applications all search for certificate inventory management and then you'll be able to click install or update my was already installed so mine says installed but yours will say install or update and once the app is there you're ready to start using it and now i'll get into the actual demo so i'm going to go through these areas here and as you guys have questions please feel free to ask we have uh sri who's my colleague uh he is the product owner for certificate infrared management he's going to be answering your questions online if there's anything you guys feel uh shri that needs to be kind of brought up to the whole team please let me know so we're gonna i'm gonna walk you through how to set up discovery of your certificates uh for port-based ca based as well as url based i'm going to show you how to configure the the life cycle notifications i'm going to kind of walk you through working through tasks for certificate renewals i'll walk you through how to set up your instance for automated certificate fulfillment and then finally i'll walk you through how to request and fulfill certificates with automation so let's get into the instance okay um so for certificate for port-based discovery this is the method that uh during your regular discovery scans you can turn on a port probe it's essentially a switch to start discovering your certificates so any certificates listening on ports your discover our discovery scan will pick that up it's not reliant on credentials right as long as we it's listening on a port we can query that and pull back the certificate information so it's this tls ssl search ports probe port probe and i'll change my scope here for a second to be able to edit this what you'll do is you'll click active because it's it's it's not active by default when you install it activate it and then here you have an option to select which ports are are discovered by default out of the box we provide the common ones or we enable the common ones but you have the option to uh turn on any of these 139 out of the box and then if you don't see the port number here that you have assert listening on you could certainly add it to the ip services table so that's how you set so that's how you turn it on right that's very simple straightforward now let's look at a discovery schedule so in your i'm first i'm going to pull up a regular discovery schedule that discovers configuration items right which is something that customers run on a regular basis um these these configuration item discoveries look at an ip range they go out there and scan a subnet or multiple subnets looking for specific you know devices that are you know that are there right so we turned on the port probe and now when we run this discovery it will start to look for certificates as well so as you can see here this one runs daily at 3am and there's no other settings here for certificates right so if i take a look at a most recent discovery run from last night i can see here in the log that it has captured certificate information right capture certificate chain populating four certificates right so so this is what we like you know you know we encourage you if you haven't tried this yet download the app install it uh you know in your instance turn on the port probe start discovering certificates in sub production just to get a you know a look and feel get the certificates in the same db start to see the value that you start having there so that was a simple straightforward for um you know setting up the port based discovery for the cr for the certificate authority discovery uh the first thing we need to do is create a credential for those of you familiar with credentials in servicenow we have a credential type called certificate management credentials right this is the credential that you will use to connect to your provider now in this case here i'm going to show you an example of digicert now for each ca that you choose there'll be different values on these fields on these forms depending on what your provider requires um so here the ca type is digicert and it needs an api key okay we get the api key from our digisearch system i'm going to show you an interest one later as well so we also created something called the credential alias which allows us to choose to use this credential specifically in other areas of the platform which i'll which i'll touch on as i go out this this demo so we have the credential we have the credential alias now how do we discover the ca if we go into my certificate discovery schedules again i'm going to look at the digicert ca discovery schedule now this discovery schedule we're not discovering configuration items like we were in the previous one we're discovering certificates then there is a choice of certificate discovery type right there's a there's a few options here right but url discovery i'll touch on in in just a moment uh but ca discovery is is what you want to choose here uh this one als is also running every day now but how do we tell it that to discover a specific um certificate authority on the bottom here there is an option for serverless execution pattern now servicenow uses patterns when it discovers things in servicenow right so not in servicenow but in your environment right so and to quit it is essentially a set of instructions to query for additional information to gather the configuration of those devices so this pattern that we want to use for this one is the digicert pattern and within the digicert pattern configuration you can specify the credential alias to be used this tells us that this we want to use we want to discover digicert with this schedule and use this credential to do that and there is one more area that you should know about is your mid server in order to do ca discovery it needs access to these urls right so depending on which one you're discovering these are the public urls so make sure that you know in addition to the credential setting up the discovery schedule your mid server has access to these urls because it's not going to work otherwise so let's take a look at a how we discover what comes back in discovery when we do a ca discovery so here we said we're running this every day so i will look at last night's discovery schedule and there's a log of course that shows us information about certificate information but here we are there's actually a tab where we're actually showing you which certificates were discovered now we have 46 that were discovered directly from the ca last night the difference between discovery the port-based discovery and this ca discovery is the ca discovery will just pull in every certificate that you have on your ca so that you can start tracking life cycle information what ca discovery does not do is it does not tell us where it's installed that is the real that's the reason why you want to run port-based discovery so that you can understand where it's installed because certain certificates are installed across multiple systems right so if you have a renewal coming up you need to know where exactly that's installed and i'll touch on that in just a moment as well on how we can see that so pretty straightforward that was the how you set up the certificate authority based discovery now let's look at the url based discovery the first thing that we do is we need to create a record in the certificate source url table and i've created some already amazon walmart netflix servicenow and i'll show you what you need to do it's very straightforward all you need to do is put in the url that you want to discover right so what i usually do is i go to my browser open up the website copy exactly what it says there and i pop it into that url field so you've created a record that this is something that i'd like to be able to discover with servicenow and then we also have to create a discovery schedule in order to do that so i'll go back to my discovery schedules i have one for url cert discovery so you know once again we are discovering certificates we are choosing the type of url certificate discovery now note that this does not require credentials right so you could discover any public website that you want you could discover any of your public websites or internal sites you don't need to have credentials for you could also include urls from the endpoint table so if you have your if you have entry points that you're mapping services from you can also click that button you'll start to see all them populated automatically so here we have a urls tab where we would edit which urls we want to include in in in the run right you may have multiple schedules that you want to discover different urls in different times so we give you the option to only select a subset now here i have all four of them already loaded in there so i'll cancel out of here and i will look at a prior discovery run from last night and we can see here that we have discovered if i look at this certificates tab i've discovered the four certificates for the urls that i've added right so i'll briefly before i do that i want to show you here the netflix website every website if you click on the little um you know lock icon you can gather information about the certificate here we see that theirs is by digicert it um it expires on january 14th 2023. so if we go back to our servicenow instance and we look at the ci that was created for the certificate record we see the issuer was digicert we see the valid to date is january 14 2023 right we also you know collect a bunch of other you know relevant information subject alternative names organization all the standard things you would have in a certificate right we see also that as soon as a certificate is discovered you have the option to assign it to somebody right and i'll talk about you know assignment in just a moment as well but the other option here you have here is to choose what type of renewal tasks are created priority one tasks should be used for those that are most important for your organization right so enough so if i'm netflix.com i mean if i'm working at netflix netflix.com is a priority one you know task for me so i could set that there and i can save it and from you know going forward anytime 60 days prior to expiration on netflix.com i'm going to receive a priority one task not a priority three task you could also choose to not create renewal tasks let's say you have a certificate that you've acquired for one-time use or maybe something that is like self-signed and they automatically renew themselves you don't have to create renewal tasks for those so that was certificate url discovery in a nutshell we also have an option for you if you'd like um let's say you have certificates that are not discoverable for whatever reason they don't listen on ports they're not part of a ca you can manually import those into servicenow so we provide a bulk upload feature where you can download a template file open up the template here it's a sample data you could certainly clear this out and populate your own data in here but it gives you all the information that you would need all the fields i should say in order to what we need to create the record in servicenow right so at least you know it's not going to be real-time data but you know it's going to be accurate data and you're going to be able to track the life cycle of that certificate uh inside of servicenow along with everything else that you're doing so that is uh that is a way to solve that challenge of non-discoverable certificates now once once you discover certificates where do they go right there's a table called the unique certificates table for those of you who like to know cmdb table names is the cmdb underscore ci underscore certificate table in this table there is one record for each unique certificate now that's important to note because you know this is where we we generate the renewal tasks from this is where we track the lifecycle right this one certificate might be installed on five different systems but there's one record of it in this table now as you can see here we track life cycle state so if i group it by state i see that we have revoked issued and installed right installed means that we've discovered it with with port-based discovery or a url-based discovery typically and we know where it's running um issued me you know could be an example of something we've ingested from the ca that we don't know if it's installed or not so you would have to set those two installed yourself if you know that there and they are in fact installed somewhere and then also there's revoked right which are ones that we have decided that we no longer need right and with the automation process i'll show you later that process becomes automated as well now installed there's a table for that as well so there's a another with installed certificates these this is a table that shows you where a particular certificate is installed now i've got a bunch of empty stuff in here i've got some demo data in here that doesn't really look that accurate but in some cases we do have very accurate data so for example here this you know ngix 3 you know 636 we have this installed on this ci right so you're able to understand where it's installed and then be able to if you had one certificate that was installed in multiple places you would have one record in one entry in this table for every instantiation of that installed certificate so that's the difference between unique certificates and install certificates tables just just remember that everything is driven like the task creation the lifecycle management that's all driven off of the unique certificates table then the next thing we wanted to talk about today was configuring the lifecycle notifications so we will do that in discovery definition properties at the very bottom of this so you know these are all your standard discovery properties that you have uh choices to set right but towards the bottom um you we added the certificate management discovery properties i'll talk through all these here so here is where you set the option to whether or not you automatically generate a task for discovered certificates that are going to be expiring uh so if you first install this you may want to disable this feature to get a handle on your certificates maybe you don't want to start creating you know renewable tasks right away but you want to just get a handle on your your life cycle what that looks like i mean and then also the next one is creating incidents for all expired search so when you first turn this on you may find that you have a lot of expired sorts and that's okay right um in some cases it it it will be okay but in others it might be a problem i guess right but you could turn this off as well by default they're both on here i mentioned earlier about select channel integration so if you have slack you can configure an integration between servicenow and slack and you can set up a channel to be notified of upcoming certificate expirations or any notifications at all for for certificates beyond setting up the notifications here is where you would set the number of days prior to where you generate the renewal task so 60 days prior is what we defaulted to you could set it to whatever you'd like down here we have the admin the the user id that will be used for when you create a incident record who the caller field is for that so by default we give you a certificate administrator you can change that if you'd like so the other area is if you have event management we can we we also automatically integrate and create alerts so this is if you go into flow designer go into subflows search for anything that contains cert and there's a there's a subflow called cert event management that is active if you deactivate this it will not create alerts but if you wanted to create alerts just leave it as active and you could certainly go in here and look at the details of that process flow we're not going to do that here because of time but so far we've talked about how to set up discovery how to run discovery how to set up notifications now that we're all set up right let's start to work through some of the task records so i'm a pki administrator and my this is the dashboard that i'm going to use on a daily basis right there's multiple dashboards here actually right um the task records will automatically be of course emailed to folks if you have email notifications enabled in your instance which i believe most customers probably do right but you may get push notifications as well but this dashboard is a great way for those who are responsible for certificates uh can manage them right and of course everything in servicenow is role-based so you can configure this to only see the ones that you're responsible for this first tab talks it's focused on the tasks right here i see that i have 31 uh upcoming i'm sorry in the past renewals right so i've got 31 expired certificates that i have to address maybe they're not all legitimate right but i have to kind of address them all i have one priority task one one priority one task right now that i should be actioning and then 36 total renewal tasks so this is what i was telling about earlier right when you set the task priority you got priority one priority three that's everything else so the ones that are most important set them as priority one so that you could track them very easily in this tab here in this widget and i've got um 36 in total like i said and zero open new request tasks this is my upcoming expirations which you know but it also includes some stuff that's already expired but as you can see here it breaks it down by critical versus moderate so p1 versus p3 the next dashboard uh a tab is your um inventory so this is these are all the certificates that i have in my instance that i'm tracking typically in your whole environment not just your instance right so i've got 236 certificates that i'm tracking uh i'm sorry that i have discovered 236 that i'm tracking for renewal right remember i said earlier you can turn off renewal tracking um you may want to do that but right now i've got it turned on for all for all of them um i've got two that i'm tracking with priority one right and this guy and i've discovered 75 in the last 30 days and i could see by root issuer what are the biggest root issuers that i have right um here i could see that other is my most common one but excuse me one second but now i'm gonna go back to working through a task so i've looked at my dashboard i know what's going on i'm going to go into this priority one task because this is the first thing that i should do now like any other task record in servicenow you know it's got an it's got an assignment group it's got a priority it's got a state and as you can see here this task number was created for this unique certificate and it's a renewal type it's got an assignment group and an assigned two right i'll show you one second where the where that comes from and the priority is party one if we look at the certificate record we can see where certain fields came from on that task we can see that the assigned to is steve emerson we can see that the change group is certificate owners right so when you run your certificate discovery the first time all this is going to be blank right you're going to have to fill in or assign your search to owners and also groups because if you don't then you know all your renewal tasks going to go to one bucket and that's fine if your organization operates that way but you likely want to get down to some level of granularity with assignment here i can see on this certificate the subject common name the issuer the state right but the valid from and the valid two right this is actually already expired in the past but right when i talked earlier about certificate discovery and understanding where it's installed i already see some downstream relationships here i see that it's used by nha proxy and this host but let's look at this more in a dependency view here we see the unique certificate and then we see the relationship to the linux server and then we see the relationship from the linux server to all of its components as well as dha proxy to the relationships to its components right here's you know um and if i were to expand the number of um levels in this map you would see that it goes out to different applications different application servers things like that i mentioned earlier about having your services mapped if you have your services mapped you can understand the impact of this cert on your business so there's this related services tab when i click details it shows me that if i don't renew this certificate it's going to impact this locomotive maintenance service and this partner event production service right so i know that these are the services that are impacted by this certificate because i have invested the time to automatically map the services right and once again mapping services means that you started it at an entry point typically and you understand exactly uh what what components are part of that service we could certainly have another we have a topic coming up on this later this year but you'll be able to you know we have videos on service mapping and get a better understanding so that is how you work through certificate tasks right the kind of the day in life of a pki pki admin looking at the dashboard working through tasks understanding you know how does this certificate impact not only uh just you know other systems but maybe other you know what my business services for example so that's how we work through certificate tasks the next step i'm going to show you is how you set up automated certificate fulfillment we don't need this dashboard anymore or this one or this one all right so the first thing we have to do is go into a property to set up the um this automated approval group i'm sorry this default approver group right so if there's any tasks that get created as part of the automated process that require um and you know an approver this is the default group that will be used but you also have the option to set that as part of the um as part of the process when you actually you know request a new uh certificate which i'll show you the next thing we need is a credential so i'm going to show you this end trust credential and once again it's the the certificate type is a certificate management credential now we chose the ca event trust and for entrust we need this information right the password the key store and we also created a credential alias which we'll use very surely the next step is to create a certificate authority record which essentially all it has and and you know you you can name this whatever you'd like this is the certificate authorities table and all this these tables and all these instructions are also documented guys so i know i'm going through this kind of fast but you know reference the documentation for where these things are specifically but anyway here is the base url that is going to process the end trust automated fulfillment requests okay that all that is needed for to set up that routing policy which i talked about in in the flow chart the routing policy and you could have multiple routing policies per certificate authority dependent on the criteria that you see here on the screen now here is where that credential alias comes into play we're saying that this routing policy needs this credential alias to authenticate to end trust right the certificate authority we created that record earlier as well the interest ca gateway right it this is where it's going to process that request and then interest requires you know this authority identifier this certificate profile right so that's information you would get from the interest console the assignment group i've left it as the pki approver group like i said you could change that for specific uh routing policies um but i've chosen to leave it the same what's important here is that you you know for pki standards right you don't want to set the maximum validity period more than 365 days it's the best practice right now and also right you also probably want to turn on approvals so that pki admins are processing or reviewing requests for new cas or i'm sorry new certificates or renewed certificates just as a best practice right i don't have it turned on for demo purposes you know for the approvals but you get the idea and then down here is where you would set up the common name information all the details about what common names are going to be processed by this routing policy this is more of a wild card but you could certainly set up individual writing policies for different subject common names and then that is where i mentioned you could have multiple routing policies per certificate authority all right so we've set it up now let's go through the process of requesting new renew and revoke so like anything else like any other request in servicenow we start in the service catalog there is this is a very blank catalog the only thing it has in here is certificate management yours is going to have a lot more obviously but there's a category called certificate management and then within there we have two subcategories we've got manual which is the manual process that i described first and then we've got automated flow right the manual there's just the new and renew right there's no automation behind those those are just standardized request forms that you can use um to set up if you're not using automation you can still use those to set up a process to request certificates in your organization but we're going to go through automated flow here today so we have these three catalog items for requesting automation new renew and revoke this bottom one here revoke is only accessible or visible to those that have a pki admin role in servicenow so that we don't just enable anybody to ask for a certificate revocation there's got to be some kind of oversight to that process right so i'm going to go through a requesting of a new certificate and to do that i'm going to copy a csr so typically when you request a certificate these days or or not just these days but any day you need a csr right i was doing this back when i worked in corporate i.t when i was a server admin um as soon as you click out of the box there's validation as to what that is if it doesn't look correct you can just stop right here and go back to the drawing board and figure out what went wrong but let's just assume this csr the data looks correct i'm going to go ahead and keep going here you can choose to change the validity period to something less than 365 days if you like but we recommend you don't set it higher than 365. you have the ability to [Music] uh select applications application services or application servers that this certificate will support and they'll be added to the certificate record in the extensions table but these are the important fields here this is where you choose the owner group so i've set up a group called certificate owners and then i'm going to assign it to myself so i've got owners myself and then you can choose what you know what environment this is for i'm going to leave it as development and then what what type of task do you want to create when this is up for expiration so i'm going to say i'm going to create priority ones so as soon as i click submit it's being processed by the end trust routing policy that's because the data that was on the form matched the routing policy and there's automation happening right now that's going out to entrust to make that happen states completed if i refresh the form you will see that the certificate record along with the the chain of certs needed for this are attached to the form the task form and they're also stored in the cmdb now if i'm the person who requested this i can download these and go and install them on the actual host right we don't deploy to the actual hosts and as i mentioned about the change request change requests automatically created and related to the task record to ensure governance so now your change pro your change management process can take over so that's the new request let's go ahead and do a renewal request i'll get the csr for that so here we have to choose an existing certificate right so i know that it's assigned to steve here's the one i just requested and then uh it tells us when it expires right and then we put in the csr click out once again there's validation on the right hand side the maximum validity period so all the fields are the same except we don't ask again what type of tasks you want to create because we carry that over from the original certificate but we will put in here the owner group and the owner i'll submit that and it's beginning to do the process behind the scenes to end trust it's completed once again i refresh it and here are the here are the new certs simple as that now you can go ahead and deploy these to the hosts the change request was created the final one is the revoke request so here we don't need a csr of course we need to select an existing certificate i'll pick one that's assigned to me this is the one i just processed and we've got to put a reason in no longer needed here we get an additional prompt that asks do we really want to revoke the certificates say yes automation kicks in it's already completed so it's going out to entrust it's revoked assert if you look at the certificate details state is now revoked right the and then it's also now revoked on end trust so and then we also have if i refresh the form change request was created just note that for for revocations we create a emergency change rather than just a normal change the final thing i'll show you with this is the dashboard where you can where you can track your automation over time now we've only started to use this instance in july so i i only have july data but as you can see here all the open requests are all zero that's intentional right because we're using automation you would have open requests here if you were waiting for approvals but that should really be the only reason why you are processing things automatically and over time this middle chart here will start to show you how many you're processing through there and being able to actually move away from manual requests and then we can see here the number processed by interest and by digicert we are adding more cas to this in the future so stay tuned um so let's go back now and finish up with a couple of resources so shamil if you can paste these resources in there that'd be great we've got a youtube channel um servicenow community youtube that has tons of great information about how to um these are just three videos that are around certificate management this one that we're doing today will also be put there so you'll have this video as well um but uh we'll we're going to attach this slide deck to the community page as well we encourage you to submit your ideas right so and if you have a certificate authority that you want to see added for automation you know add it as an idea when something gets 10 upvotes by 10 different unique customers our product managers start to take action so please go to the idea portal on the community and begin to uh you know add your ideas or upvote existing ideas icon visibility right i showed you today we talked about certificate inventory and management it's part of the suite of applications that help you gain visibility across your entire state and over the next um several months we're going to be doing demonstrating i'm sorry um webinars on all these different topics last month we did one on um acc which is our agent client collector right this month we're doing certificate management and then i'll show you in a moment what we're doing next month but uh with that said um are there any outstanding questions team that we need to address here live or were there any uh shree were there any press or you know were there any common questions that you feel that we should um kind of bring up to the entire or you know team here yeah i see two prominent questions steve firstly fantastic session thank you there's a lot of questions around licensing if you go back to the previous slide you need item visibility subscription in order to unlock certificate management please reach out to know your servicenow contract to validate what kind of subscription you have if you still have the old node based discovery sku talk to your account rep know and upgrade to the modern skews that will unlock all those capabilities there's another question on the certification certificate relationships so if you can open up the relationship record sure so the discovery of certificates can happen with multiple methods as steve showcased a tcp ip port base scan url base can connect you know connecting to your f5 load balancer and identifying all the deployed certificates there or even using patterns that will allow you to directly connect to the certificate authority vendors for the data collection and we have created two different uh schemas uh i would say uh where if you show me the recorder right click and show me the record of the unique certificates so the first table that you're gonna see is the unique certificate table which actually identifies the record then you'll also see an install certificate table so if you use multiple techniques to discover the same certificate you're going to see multiple records created at the install certificate table but we will still have one unique certificate record so that you can use no multiple techniques for the discovery and inventory data collection but for your task automation for your uh pki uh no life cycle management activities you still need to work with the unique certificate record so all our workflows of notifications everything happens via this table uh can you also show me show that dashboard of uh the pipe no the expiry pipeline there's another question around how do we track the expiry 60 days if you show me the dashboard yep i'm getting to it yes the third management uh properties will allow you to set up uh proactive notifications or reactive notifications the proactive notifications are are primarily geared towards like uh no 60 days or 30 days before the expiry you wanted to send a slack or you wanted to create a workflow task for the requester to know to submit their csr request so that's something that you should encourage your uh no pki team to do but if uh so steve if you show me the second tab of the no the dashboard sorry yeah yeah second time so here you see this upcoming certificate expiration which again will show you the expiry pipeline for the next 12 months and you can click any of those months and you'll be able to see the list of certificates that will be expiring for that specific month and if you have set the priority one versus priority three right that also gives you more credible ways to work with the critical certificates that is super important for your customer facing external facing infrastructure compared to maybe a certificate that is deployed into a test lab or r d lab and no way you can still like know track them with the priority three tasks so the workflow itself provides you complete flexibility to configure uh know these uh settings and also as i said on the reactive side if the life cycle state of the certificate has not renewed and if the certificate has expired then if you have event management plugin then we will create a critical alert and then critical incident if you don't have event management plug-in we will just create a critical incident so the incident records will be automatically created if the certificate is still there in the server and if the certificate life cycle activity has not changed it is still an installed state and the certificate has expired so with that steve i'll hand over the floor to you thanks shree and thanks everyone for your questions so call to action today so visit our store download the certificate inventory management try it out in sub prod you know it's very easy to turn on as you saw use this video as you know as your way to do it showcase the value that you see to your stakeholders you just get them excited about it right and we're here to help right if you have any questions ask your you know ask us on the community page we'll get in touch with you and then finally share your success story with us you know tell us what you've done and then if you have an prod we'd love to know what your you know what value that that you're realizing and finally we'd like you to join us next month um august 16th uh same time 9 a.m pacific 12 a.m until 12 p.m eastern where we're going to be talking about cloud center of excellence part 1 how to gain business context of your cloud resources thanks everyone have a great rest your day and we'll talk to you again soon you
https://www.youtube.com/watch?v=oUK8-yGfRv4