- DigiCert product docs
- Trust Lifecycle Manager
- Integration guides
- ServiceNow
- Configuration management database (CMDB) integration
Configuration management database (CMDB) integration
You can optionally enable ServiceNow CMDB integration to copy certificates to the cmdb_ci_certificate table in ServiceNow, using one or both of these methods:
ServiceNow app option: Use this option if you only want to copy the certificates you request through the ServiceNow app to the CMDB table. When you request a certificate with the ServiceNow app, it saves a local copy to the CMDB table. If you later update the issued certificate in DigiCert® ONE, the changes don’t get synced back to the CMDB table unless you also have a connector in place for the certificate's business unit.
DigiCert ONE connector: Add a connector in DigiCert ONE to copy selected certificates from business unit to the ServiceNow CMDB. You can select certificate profiles and exclude imported, discovered, expired, or revoked certificates. An initial migration job copies existing certificates that match the connector settings, and ongoing jobs copy updated certificate data to ServiceNow. For details on certificate properties that are copied, see ServiceNow CMDB table.
참고
The ServiceNow CMDB table has view-only access. You can’t directly manage the certificates from the CMDB table, but the integration lets you use the CMDB functionality to query, filter, and monitor the certificates from the ServiceNow Workspaces > Certificate Management page.
Prerequisites
To use the CMDB integration features, you need minimum version 1.3.0 of the DigiCert Trust Lifecycle Manager app for ServiceNow.
Your ServiceNow instance must have the Certificate Inventory and Management (App id: sn_disco_certmgmt) v3.3.0 plugin installed, which requires a paid subscription. To learn more and install this plugin:
From the ServiceNow store: Check the Certificate Inventory and Management app listing.
From the Application Manager for your ServiceNow instance: Search for the Certificate Inventory and Management plugin.
Use this integration method if you want to copy certificates you request through the ServiceNow app to the CMDB table.
To enable this option:
Select the CMDB integration item for the DigiCert Trust Lifecycle Manager app in ServiceNow.
Toggle on the option to copy certificates to CMDB.
When toggled on, the DigiCert Trust Lifecycle Manager app will start saving a copy of any certificate you request to the CMDB table.
Use this integration method if you want to copy selected certificates from a business unit to the ServiceNow CMDB table. You can select certificate profiles and exclude certificates based on their source or status.
Each connector is associated with a specific business unit and copies certificates from that business unit to the ServiceNow instance. To copy certificates from multiple business units, add multiple connectors in DigiCert ONE.
DigiCert ONE prerequisites
Your DigiCert account must have the Connectors and ServiceNow CMDB integration features enabled in DigiCert® Account Manager. Contact your DigiCert system administrator to verify or enable these features.
The user who will add the ServiceNow connector must have the CMDB Integration Config Manager user role assigned for Trust Lifecycle Manager.
Authentication methods
You can use either of the following methods to authenticate the DigiCert ONE connector to ServiceNow:
Account credentials: Enter the username and password for a ServiceNow account with the "user" role (x_dice_digicertone.user).
Certificate-based authentication: Upload a PKCS#12 certificate to authenticate via mutual TLS (mTLS).
Your ServiceNow instance must be enabled for certificate-based authentication using the same certificate that you add to the DigiCert ONE connector. For details, refer to the official ServiceNow documentation.
You can use any PKCS#12 certificate (with private key and associated password) to set up the connector. For details about how to generate the certificate in DigiCert ONE, see Generate authentication certificate for ServiceNow connector.
Add the connector in DigiCert ONE
You need a separate connector in DigiCert ONE for each business unit whose certificates you want to copy to the ServiceNow CMDB table.
To add the connector in DigiCert ONE:
From the Trust Lifecycle Manager main menu, select Integrations > Connectors.
Select the Add connector button.
In the IT service management section, select the tile for ServiceNow.
Fill out the form:
Name: Provide a friendly name for this connector.
Business unit: Select the business unit for the certificates to copy and synchronize to the ServiceNow CMDB table.
참고
Each ServiceNow connector is associated with a single business unit in Trust Lifecycle Manager. To copy certificates from multiple business units to ServiceNow, add multiple connectors.
Profiles: Select one or more certificate profiles to copy certificates enrolled using those profiles to ServiceNow. If you do not select a profile, certificates associated with all profiles in the selected business unit are included.
Exclude imported certificates: Select to prevent imported certificates from being copied to ServiceNow.
Exclude discovered certificates: Select to prevent discovered certificates from being copied to ServiceNow.
참고
You can select both exclusion options. When you do, imported and discovered certificates are excluded.
Exclude certificates by status: Select one or both statuses (Expired, Revoked) to exclude certificates from synchronization.
Link account: Add the URL and authentication details for your ServiceNow instance.
Instance URL: Enter the ServiceNow instance URL, for example,
https://my-instance-123.service-now.com.Authentication method: Select an authentication method to connect the ServiceNow instance to Trust Lifecycle Manager.
Account credentials: Enter the credentials for a valid ServiceNow user. At minimum, the ServiceNow user specified in the connector must have the "user" role (x_dice_digicertone.user).
Certificate-based authentication: Upload a PKCS#12 certificate to authenticate via mutual TLS (mTLS). Enter the password for the PKCS#12 certificate file.
Select Add to create the ServiceNow connector with the configured settings.
중요
After you create the connector, you cannot change its business unit, profiles, or certificate exclusion settings. Locking these settings helps keep the initial migration and subsequent updates synchronized with ServiceNow. To change these locked settings, you must delete the connector and create a new one.
Verify or edit the connector
To verify or edit the connector in DigiCert ONE:
Select Integrations > Connectors from the Trust Lifecycle Managermenu.
Select the ServiceNow connector by name to view the details for it.
If you need to make changes, select the pencil icon to edit the connector name or ServiceNow account settings. Select Update when done.
중요
After you create the connector, you cannot change its business unit, profiles, or certificate exclusion settings. To change these settings, you must delete the connector and create a new one.
Troubleshoot an existing connector
If the connector status changes to Action needed, correct the ServiceNow account settings and select Test connection from the connector’s actions menu on the Integrations > Connectors page. Trust Lifecycle Manager also tests the connection every 10 minutes. When the connection is restored, the connector returns to Active and resumes copying certificate data.
Delete and recreate the connector if the certificate counts do not match or if you want to edit profile and certificate exclusion settings.
Migration jobs
When the connection from DigiCert ONE to ServiceNow is established:
Approximately 30 minutes after you add the connector, a one-time migration job copies certificates that match the configured business unit, profile, and exclusion settings to the ServiceNow CMDB table.
참고
Trust Lifecycle Manager-specific certificate metadata such as certificate tags, custom attributes (service departments, cost centers, business unit name, etc.), and certificate owners don’t get copied to the CMDB table.
For details on what certificate properties are copied to the CMDB table, see ServiceNow CMDB table.
To monitor the migration, go to Integrations > Connectors, select the connector, and check the Migration status field on the connector details page. You can also track the status of the migration from the CMDB integration page in the DigiCert Trust Lifecycle Manager app in ServiceNow.
After the initial migration is complete, an incremental job runs every 10 minutes to synchronize any updated certificate data in the Trust Lifecycle Manager business unit to the ServiceNow CMDB table. The incremental job does not run until the initial migration completes successfully.
ServiceNow CMDB table
You can view the following certificate properties in the CMDB table after the initial migration job is completed. These fields represent the actual data copied to the CMDB for each certificate. They are updated during every sync with Trust Lifecycle Manager, including any new certificates issued or added to the business unit after the initial migration.
Field | Type | Required | Description |
|---|---|---|---|
| string | No | Name of the profile's base template. |
| string | Yes | Content of the certificate in PEM or Base64 formats. |
| string | Yes | Unique cryptographic hash used to identify and verify certificate authenticity. |
| string | Yes | Common name of the certificate to be issued. |
| string | No | Common name of the issuer. |
| string | Yes | Key length or curve size (2028, 4096, etc). |
| string | No | Serial number (hexadecimal characters) |
| string | No | Signature algorithm (for example, sha256RSA). |
| enum | Yes | Current status of the certificate, which can be |
| string | No | Common name in the Subject DN of the end-entity certificate. |
| string | No | Two letter ISO country code. |
| string | No | Full Distinguished Name (DN) string if aggregated. |
| string | No | Email address from the |
| string | No | Locality (L) |
| string | No | Organization (O) |
| string | No | Organizational Unit (OU) |
| string | No | State or Province (ST) |
| string | Yes | Certificate's hash value (SHA-256/SHA-1). |
| date | Yes | Indicates the timestamp from which the certificate is valid. |
| date | Yes | Indicates the timestamp after which the certificate is no longer valid. |
| string | No | IP address associated with the certificate or the endpoint where it was discovered. |
| string | No | Domain name associated with the certificate (for example, example.com). |
| string | Yes | Source of the certificate discovery, hardcoded as |