---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/it-operations-management

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# ACC certificates

# Agent Client Collector certificates {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Agent Client Collector certificates verify the authenticity of your agents, servers, and users. Using Agent Client Collector certificates ensures the safety of your environment.

## Discovering certificates {#acc-certificates__section_k5r_gfl_k3c}

To discover certificates on all of your host's applications with open ports, navigate to AllSystem PropertiesAll Properties and set the sn_acc_vis_content.tls_ssl_scan_all_open_ports property to true.

If you want to maintain certificates only for applications running on specific ports, set this property to false. The property's default value is true.
* **[Manually refresh Agent Client Collector certificates](https://servicenow-prod.fluidtopics.net/8El2lBB8F9HpbUoNA7Nk9w)**   
  Refresh Agent Client Collector self-signed certificates manually to validate Agent Client Collector plugins, instead of waiting for the scheduled synchronization. For example, you can use this feature when the agent can't validate a plugin and you don't want to wait for the scheduled synchronization.
* **[Enable OpenSSL secure signing for plugins](https://servicenow-prod.fluidtopics.net/UD40gFeQTkY6Vsh4zJzUbg)**   
  Create a self-signed certificate for an Agent Client Collector plugin. The following procedure gives an example of how to create an x509 certificate using OpenSSL. For other certificate types, consult OpenSSL documentation.
* **[Add a self-signed certificate to your operating system's truststore](https://servicenow-prod.fluidtopics.net/52mev4Kedx4DjxCF4DPcdQ)**   
  Add a self-signed certificate to the truststore of your operating system (OS). By adding a certificate to the truststore, you can verify that the certificate is authentic and that your connections are secure.
* **[Import a self-signed certificate](https://servicenow-prod.fluidtopics.net/m6fw6CuxQrwxkxv87iRqwg)**   
  Import a self-signed certificate in a Windows system by using the Certificate Import Wizard. The Certificate Import Wizard is required to complete the self-signed certificate import process on a Windows Operating System (OS).
* **[Revoke Agent Client Collector certificates](https://servicenow-prod.fluidtopics.net/KLtm_u53fqfnHAdmbXRkSQ)**   
  Stop communication between the agent and ITOM cloud services by removing an Agent Client Collector certificate. For example, there might be a security breach due to which you want to stop communication by revoking the agent's certificate.
* **[Agent certificate rotation](https://servicenow-prod.fluidtopics.net/FsX5QUrB0nGmR8HZ2iWGEw)**   
  The Agent Client Collector certificate is valid for two years and must be rotated before it expires to avoid issues with agent connectivity. When expiration is approaching, the agent initiates a certificate rotation request.
* **[Run Certificate Discovery via Agent Client Collector for Visibility - Content](https://servicenow-prod.fluidtopics.net/D9HYSfYgXWXQ2FGZzlLiVw)**   
  Discover TLS/SSL certificates used by ports running on the agent's server. The Certificate Inventory and Management application uses this information to manage TLS/SSL certificates.

