Skip to main content

Configuration management database (CMDB) integration

You can optionally enable ServiceNow CMDB integration to copy certificates to the cmdb_ci_certificate table in ServiceNow, using one or both of these methods:

  • ServiceNow app option: Use this option if you only want to copy the certificates you request through the ServiceNow app to the CMDB table. When you request a certificate with the ServiceNow app, it saves a local copy to the CMDB table. If you later update the issued certificate in DigiCert® ONE, the changes don’t get synced back to the CMDB table unless you also have a connector in place for the certificate's business unit.

  • DigiCert ONE connector: Add a connector in DigiCert ONE to copy selected certificates from business unit to the ServiceNow CMDB. You can select certificate profiles and exclude imported, discovered, expired, or revoked certificates. An initial migration job copies existing certificates that match the connector settings, and ongoing jobs copy updated certificate data to ServiceNow. For details on certificate properties that are copied, see ServiceNow CMDB table.

Anmerkung

The ServiceNow CMDB table has view-only access. You can’t directly manage the certificates from the CMDB table, but the integration lets you use the CMDB functionality to query, filter, and monitor the certificates from the ServiceNow Workspaces > Certificate Management page.

Prerequisites

To use the CMDB integration features, you need minimum version 1.3.0 of the DigiCert Trust Lifecycle Manager app for ServiceNow.

Your ServiceNow instance must have the Certificate Inventory and Management (App id: sn_disco_certmgmt) v3.3.0 plugin installed, which requires a paid subscription. To learn more and install this plugin:

Use this integration method if you want to copy certificates you request through the ServiceNow app to the CMDB table.

To enable this option:

  1. Select the CMDB integration item for the DigiCert Trust Lifecycle Manager app in ServiceNow.

  2. Toggle on the option to copy certificates to CMDB.

  3. When toggled on, the DigiCert Trust Lifecycle Manager app will start saving a copy of any certificate you request to the CMDB table.

Use this integration method if you want to copy selected certificates from a business unit to the ServiceNow CMDB table. You can select certificate profiles and exclude certificates based on their source or status.

Each connector is associated with a specific business unit and copies certificates from that business unit to the ServiceNow instance. To copy certificates from multiple business units, add multiple connectors in DigiCert ONE.

DigiCert ONE prerequisites

  • Your DigiCert account must have the Connectors and ServiceNow CMDB integration features enabled in DigiCert® Account Manager. Contact your DigiCert system administrator to verify or enable these features.

  • The user who will add the ServiceNow connector must have the CMDB Integration Config Manager user role assigned for Trust Lifecycle Manager.

Authentication methods

You can use either of the following methods to authenticate the DigiCert ONE connector to ServiceNow:

  • Account credentials: Enter the username and password for a ServiceNow account with the "user" role (x_dice_digicertone.user).

  • Certificate-based authentication: Upload a PKCS#12 certificate to authenticate via mutual TLS (mTLS).

    Your ServiceNow instance must be enabled for certificate-based authentication using the same certificate that you add to the DigiCert ONE connector. For details, refer to the official ServiceNow documentation.

    You can use any PKCS#12 certificate (with private key and associated password) to set up the connector. For details about how to generate the certificate in DigiCert ONE, see Generate authentication certificate for ServiceNow connector.

Add the connector in DigiCert ONE

You need a separate connector in DigiCert ONE for each business unit whose certificates you want to copy to the ServiceNow CMDB table.

To add the connector in DigiCert ONE:

Verify or edit the connector

To verify or edit the connector in DigiCert ONE:

  1. Select Integrations > Connectors from the Trust Lifecycle Managermenu.

  2. Select the ServiceNow connector by name to view the details for it.

  3. If you need to make changes, select the pencil icon to edit the connector name or ServiceNow account settings. Select Update when done.

    Wichtig

    After you create the connector, you cannot change its business unit, profiles, or certificate exclusion settings. To change these settings, you must delete the connector and create a new one.

Troubleshoot an existing connector

  • If the connector status changes to Action needed, correct the ServiceNow account settings and select Test connection from the connector’s actions menu on the Integrations > Connectors page. Trust Lifecycle Manager also tests the connection every 10 minutes. When the connection is restored, the connector returns to Active and resumes copying certificate data.

  • Delete and recreate the connector if the certificate counts do not match or if you want to edit profile and certificate exclusion settings.

Migration jobs

When the connection from DigiCert ONE to ServiceNow is established:

  • Approximately 30 minutes after you add the connector, a one-time migration job copies certificates that match the configured business unit, profile, and exclusion settings to the ServiceNow CMDB table.

    Anmerkung

    Trust Lifecycle Manager-specific certificate metadata such as certificate tags, custom attributes (service departments, cost centers, business unit name, etc.), and certificate owners don’t get copied to the CMDB table.

    For details on what certificate properties are copied to the CMDB table, see ServiceNow CMDB table.

  • To monitor the migration, go to Integrations > Connectors, select the connector, and check the Migration status field on the connector details page. You can also track the status of the migration from the CMDB integration page in the DigiCert Trust Lifecycle Manager app in ServiceNow.

  • After the initial migration is complete, an incremental job runs every 10 minutes to synchronize any updated certificate data in the Trust Lifecycle Manager business unit to the ServiceNow CMDB table. The incremental job does not run until the initial migration completes successfully.

ServiceNow CMDB table

You can view the following certificate properties in the CMDB table after the initial migration job is completed. These fields represent the actual data copied to the CMDB for each certificate. They are updated during every sync with Trust Lifecycle Manager, including any new certificates issued or added to the business unit after the initial migration.