logo

NJP

How to automate fulfillment of Microsoft certificates with ServiceNow

Import · Nov 03, 2022 · video

hello everyone my name is Steve Emerson and I'm the outbound product manager for itom visibility here at servicenow today I'm going to demonstrate how you can automate fulfillment for Microsoft certificate requests with servicenow as of November 2022 servicenow's certificate inventory and management provides a holistic solution for Discovery lifecycle management and fulfillment of digisert and trust and now Microsoft certificates before I show you the demo here's a quick overview of how it works first we provide you with a single pane of glass for you to visualize certificate workflow automation which enables you to track automation value over time automated workflows Begin by submitting requests in the service catalog for new renew and revoke then a routing policy processes the requests to Microsoft active directory certificate services with the option of having an approval before being processed after that workflow automation sends the request to Microsoft active directory certificate services for processing once the request is completed a change request is created to ensure governance of the process the requested certificate and corresponding certificates from the chain are attached to the task and are stored in the cmdb now on to the demo to get started with automating certificate fulfillment requests for Microsoft active directory certificate Services go to store.servicenow.com and search for certificate inventory and management you will want to install version 2.32 in your servicenow instance we will start our demo in the employee Center which is where people can go to to make requests to submit incidents to search and knowledge base and we're going to start by looking at our new taxonomy that we've introduced in the November release there is a privacy and security topic and underneath that we've created a certificate management topic underneath there we have manual and automated let's look at the automated service requests so here we have requests for new renew and revoke note that the revoke request is only available to users that have a pki admin role exposing this only to the pka admin role ensures that only the right people can make a request to revoke a certificate the last thing you want is somebody to mistakenly request this and cause an outage let's look at the request for a new certificate for Microsoft certificates the first thing we need to do is make sure that we choose internal for the certificate purpose now in this case it defaults to internal now prior to November we had external as an option that was to be used for digisour and entrust since those are external certificate authorities since Microsoft CA is an internal CA we have added a new purpose there the next thing we do is we paste in the certificate signing request or the CSR if we scroll back up on the right hand side we see there's immediate validation as soon as we click out of that box as to what we are requesting perhaps we have pasted in the wrong CSR and at this point we can go find the right one before we continue everything looks good we'll scroll down we have the ability here to select an application an application service or an application server that this certificate will support later on once you run a certificate discovery all of this information will be automatically discovered and related to the certificate anyway now here we have the option to choose a certificate owner group I'm going to go ahead and choose certificate owners this is the group that will own the certificate this is where the tasks will be sent to when there is a need to renew that certificate 60 days prior to expiration I'll choose an owner as myself this owner is who gets assigned as the assigned to on the cmdbci record we can select the environment that this certificate is going to support as well as what type of tasks do we want to create 60 days prior to expiration Priority One tasks are for your certificates that are most critical to your business priority three tasks are everything else essentially or you have the option to choose do not create renewal tasks perhaps this is a one-time use certificate for a project we're going to go ahead and change this to create priority threes and submit so as soon as we submit that we see that it has automatically triggered a new automated flow for Microsoft CA request we've got the serial number and we see that a change request was created at the same time we see that the certificate along with the certificate chain has been attached to the task so this request is now complete in just a matter of seconds let's go ahead and take a look now at the request for more information here's the request that we just submitted that request turned into this automated task as part of the automated task we see that it was related to a certificate this is essentially the cmdbci there is now a seem to be CI in the unique certificates table for this certificate and I'll show you that in a moment we see that the certificate along with the certificate chain have also been attached to this task this means that the person who requested this can now go ahead and deploy this certificate to the appropriate host or hosts we see all the information about the certificate that we requested you can verify one more time that it matches up and if it wasn't right you could go ahead and request a revoke at this point and then at the bottom here we see that a normal change request was created because this was a request for a new certificate let us take a look now at the certificate record in the cmdb once again we see the subject common name we see the valid from the valid two dates we see that this was automatically assigned to Steve Emerson because I chose that on the Certificate request form as well as the change group which was the certificate owners that I chose I also chose to create priority three tasks for the renewal so 60 days prior to an expiration of this certificate I will receive a priority three task to go ahead and action with the November release we've also added this new tab called certificate chain so for any cmdb certificate CI form you can click on that and see what is the chain information for that certificate now that we've seen the process for requesting a new certificate let's look behind the scenes to see how that request was processed we're going to go to our routing policy so we bring up the Microsoft CA routing policy that I've created this is the logic that processes the requests that are submitted it looks at the contents of the CSR along with some other variables like environment and of course purpose now this one here is for Microsoft you could have multiple routing policies per CA or you could have multiple routing policies for across different cas now in this case here the reason why I only have one routing policy for Microsoft is because I have a wild card policy where I can submit any domain I wanted to if you have specific domains that you want to process differently perhaps for certain domains you want to always require an approval you can do that finally in our November 22 release we've also introduced the ability to specify a specific mid server for a routing policy this is for reachability purposes or for sharing the load amongst mid servers now that we've seen the process to request a new certificate and how certificates are processed with the routing policy let's look at the process to request a certificate revoke we are back in our service catalog on the employee Center here we see the three requests once again I'll do the revoke request in just one second here but just wanted to note that the renewal request is very similar to what I showed you on the new request with the only difference being that you need to choose an existing certificate rather than starting from scratch now let's look at the certificate revoke and once again this is only available to those that have a pki admin rolling service now to prevent any kind of accidental certificate revocations the first thing we need to do is choose an existing certificate let's pick the one I just submitted and we need to put a reason in here so perhaps the project ended early and we want to just revoke it because we no longer need it project ended once we click submit we'll be prompted one more time if just to make sure that we want to go ahead and submit this request if we bring up the task that was created for this automated action we see that it was related to that certificate and we see that an automated change request was created we always create emergency changes by default out of the box with any revocations you can change the properties of this if you'd like but out of the box we create emergency change so that you can have your emergency cab go ahead and process that through their process let's take a look at the certificate details we can see that the state is now revoked and it is also revoked on the Microsoft CA now that you've seen the process to request a new and revoke let us take a look now at the dashboard so here we have a single pane of glass dashboard for you to visualize your automated flow tasks as well as how many tasks you've done over time here are the current open new renew and revoke tasks notice how they're all zero that's because we are using automation if you were doing the manual process you would see a lot of numbers here the only reason why these might be open still is if we're perhaps waiting on an approval here you can see the task automation Trends so you can start to show your your leadership how much time you're saving by automating more and more certificate requests over time and then down here on the right you can see that we have our tasks by CA so I showed you Microsoft I have separate videos for n trust and digisert here on YouTube so if you use those Technologies go check them out we just saw how you can automate fulfillment of new renew and revoke requests from Microsoft certificates using servicenow in doing so you will be able to prevent outages from expired certificates reduce time and effort with automated processes establish governance procedures and reduce risk and improve the customer experience now certificate inventory and management is included with itom visibility which is a suite of products that enable you to gain visibility of your entire estate and populate your cmdb which is that single source of record for configuration data of everything in your environment it helps you manage what you know to learn more about item visibility and how it can help your organization please reach out to your servicenow account team thank you for watching and have a great rest of your day

View original source

https://www.youtube.com/watch?v=NfGlhfhvdDY