---
sourceDocument: Australia Security Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/security-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Security Management

ft:clusterId :

    - security

bundleId :

    - security

workflow :

    - Technology


---

# Verify expected results for RISKIQ SSL certificate lookups

# Verify expected results for RISKIQ
SSL certificate lookups {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

When a security incident generates observables for URLs, domains, IP addresses,
certificate file hashes (SHA-1 fingerprint), and certificate serial numbers, security
incident analysts use the SSL certificate lookup results to verify sites have certificates
that have been issued by a trusted public Certificate Authority (CA).

## Before you begin

Role required: sn_si.analyst

## About this task

For supported observables, the ServiceNow AI Platform scans for the most
recent occurrence of URLs, domains, IP addresses, certificate file hashes (SHA-1
fingerprint), and certificate serial numbers. These are possible outcomes from the
scan:

An exact match is found
:   A valid issuer of an SSL certificate is listed on the Security Incident
    record.

No certificate results are found
:   No results are listed on the Security Incident record.

An exact match is found for a self-signed, or internally generated
certificate
:   Results for an internally generated SSL certificate are displayed on the
    Security Incident record.

An exact match is not found for a primary SSL certificate
:   A lookup value returns multiple entries and a primary certificate cannot be
    identified. A summary message is displayed on the Security Incident
    record.

## Procedure

1. To view the observables and verify lookup results, open the security incident record you are working with and locate the work notes.  
   To illustrate examples for the possible lookup results for this integration, suppose that a security incident was generated with the following observables:
   * community.servicenow.com
   * invalidsubdomain.servicenow.com
   * mail.dgnetworks.com
   * servicenow.com

   {#verify-expected-rslts-for-riskiq__ul_ozn_rlr_tdb} {#verify-expected-rslts-for-riskiq__table_onk_glr_tdb__entry__3}

   | Observable (example) | Scan results | Description and location |
   |-|-|-|
   | community.servicenow.com | Found certificate with a SHA1 hash. | An exact match is found, and a valid issuer of an SSL certificate is listed. Results for the exact match are displayed on the SSL Certificates tab on the security incident record. |
   | invalidsubdomain.servicenow.com | No certificates found. | A summary that indicates no certificate results were found is displayed on the Observable Enrichment Results tab on the security incident record. |
   | mail.dgnetworks.com | Found certificate with SHA1 hash. | An exact match is listed for a self-signed, or internally generated certificate. Results are displayed on the SSL Certificates tab on the security incident record. |
   | servicenow.com | Search returned 138 certificates, and a single primary certificate could not be identified. | An exact match is not found for a primary SSL certificate, because a lookup value returns multiple certificates. A summary that indicates no primary certificate was found is displayed on the Observable Enrichment Results tab on the security incident record. |
   [Table 1. Observables and location of lookup results]

   {#verify-expected-rslts-for-riskiq__table_onk_glr_tdb}  
   After the application is configured, the flow launches automatically. The lookup status and the observables are displayed in the work notes.
2. Verify that the lookup ran successfully.
If you cannot view expected results, verify that the observable is supported by the SSL certificate lookup for the integration.
* **[RISKIQ SSL certificate lookups that return an exact match](https://servicenow-prod.fluidtopics.net/VDw0RQPJVWXOMM9gjB4kAA)**   
  RISKIQ SSL certificate lookup results for an exact match are displayed on the SSL Certificates tab on the security incident record. An exact match provides a valid certificate authority name, which helps a security incident analyst determine the validity of a website.
* **[RISKIQ SSL certificate lookups that return multiple certificates or no certificates](https://servicenow-prod.fluidtopics.net/jy5OqQ3M3OfVMjoDYbTd3A)**   
  A security incident analyst can use multiple SSL certificate results to determine whether a site is part of a common, recognizable entity. No SSL certificate results may indicate sites with obscure or suspicious names have no trusted certificates. Lookup results for observables that don't return SSL certificates, or that return multiple SSL certificates, are displayed on the Observable Enrichment Results tab on the security incident record.

**Previous topic:** [Install and configure RISKIQ and WHOISIQ](https://servicenow-prod.fluidtopics.net/9und49zaUE3Cjrvo5xPDpg "Before you run the integration on your instance, complete the installation and configuration steps so the RISKIQ and WHOISIQ applications properly integrate with ServiceNow AI Platform Security Operations.")  
**Next topic:** [RISKIQ SSL certificate lookups that return an exact match](https://servicenow-prod.fluidtopics.net/VDw0RQPJVWXOMM9gjB4kAA "RISKIQ SSL certificate lookup results for an exact match are displayed on the SSL Certificates tab on the security incident record. An exact match provides a valid certificate authority name, which helps a security incident analyst determine the validity of a website.")  
**Related reference**   

* [Supported observables for RISKIQ and RISKIQ WHOISIQ](https://servicenow-prod.fluidtopics.net/er0CYm1rBPOEf_Aobh6OQA "The RISKIQ API supports automatic SSL certificate lookups on IP address, file hash, Certificate Serial Number, domain, and URL observables. URL and domain observables are enriched automatically with the WHOISIQ API. For observable enrichment on other types of observables with the WHOISIQ API, create observables and run lookups manually from the Observables table.")

