---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/pt-BR/security-management

 Release :

    - australia

ft:locale :

    - pt-BR

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# SSL Certificate Lookup: Multiple/None found

# RISKIQ SSL certificate lookups that
return multiple certificates or no certificates {#ariaid-title1}

* Versão de lançamento: Australia
* 
* Atualizado 12 de mar. de 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 min. de leitura

A security incident analyst can use multiple SSL certificate results to determine
whether a site is part of a common, recognizable entity. No SSL certificate results may
indicate sites with obscure or suspicious names have no trusted certificates. Lookup results
for observables that do not return SSL certificates, or that return multiple SSL
certificates, are displayed on the Observable Enrichment Results tab on the
security incident record.  

## No SSL certificate results or multiple SSL certificate results

Follow the steps to view the results for observables that do not return SSL
certificates, or that return multiple certificates.

1. In the security incident record, click the Observable Enrichment Results tab.Figura 1. Observable Enrichment Results tab

   The observable enrichment results for the RISKIQ and WHOISIQ lookup are
   displayed.

   In the Observable column,
   servicenow.com corresponds to the
   Search returned 138 certificates message in
   the Summary column. Similarly,
   invalidsubdomain.servicenow.com corresponds
   to No certificates were found in the
   Summarycolumn. These summaries indicate that
   multiple SSL certificates were found, and that no exact matches for SSL
   certificates were found, respectively.
2. In the Observable column, click servicenow.com.Figura 2. Multiple SSL certificates

   The summary message that is displayed on the record indicates that
   multiple results for SSL Certificates were returned for
   <kbd class="ph userinput">servicenow.com</kbd>, and a primary SSL Certificate
   could not be matched. This message is often returned on lookups that include
   common domain names, such as <kbd class="ph userinput">servicenow.com</kbd>.
   If you require more information on a common domain, you can perform the search directly with the RISKIQ API.
3. Navigate back to the Observable Enrichment Results tab, and in the Observable column, click invalidsubdomain.servicenow.com.Figura 3. No SSL Certificates  
   Nota:  
   * If no SSL certificates are found for the current observable, then the Summary field displays the message, No certificates were found.
   * If no active SSL certificates are found for the current observable, then the Summary field displays the message, No active certificates were found.
   {#riskiq_ssl_no_match__ul_kd5_45l_xsb}
{#riskiq_ssl_no_match__ol_f4h_rqr_tdb}

