---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# SSL Certificate Lookup: Multiple/None found

# RISKIQ SSL certificate lookups that
return multiple certificates or no certificates {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

A security incident analyst can use multiple SSL certificate results to determine whether a site is part of a common, recognizable entity. No SSL certificate results may indicate sites with obscure or suspicious names have no
trusted certificates. Lookup results for observables that don't return SSL certificates, or that return multiple SSL certificates, are displayed on the Observable Enrichment Results tab on the security incident
record.  

## No SSL certificate results or multiple SSL certificate results

Follow the steps to view the results for observables that do not return SSL
certificates, or that return multiple certificates.

1. In the security incident record, select the Observable Enrichment Results tab.

   The observable enrichment results for the RISKIQ and WHOISIQ lookup are displayed.

   In the Observable column, servicenow.com corresponds to the Search returned 138 certificates message in the Summary column. Similarly, invalidsubdomain.servicenow.com corresponds to No certificates were found in the Summarycolumn. These summaries indicate that multiple SSL certificates were found, and that no exact matches for SSL certificates were found,
   respectively.
2. In the Observable column, select servicenow.com.

   The summary message that is displayed on the record indicates that multiple results for SSL Certificates were returned for
   <kbd class="ph userinput">servicenow.com</kbd>, and a primary SSL Certificate could not be matched. This message is often returned on lookups that include common domain names, such as
   <kbd class="ph userinput">servicenow.com</kbd>.
   If you require more information on a common domain, you can perform the search directly with the RISKIQ API.
3. Navigate back to the Observable Enrichment Results tab, and in the Observable column, select invalidsubdomain.servicenow.com.  
   Note:  
   * If no SSL certificates are found for the current observable, then the Summary field displays the message, No certificates were found.
   * If no active SSL certificates are found for the current observable, then the Summary field displays the message, No active certificates were found.
   {#riskiq_ssl_no_match__ul_kd5_45l_xsb}
{#riskiq_ssl_no_match__ol_f4h_rqr_tdb}

