---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# F5 certificate

# F5 certificate discovery {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read

The ServiceNow®
Discovery application uses The F5-SSH-SSL Certification pattern extension to find all associated certificates on F5 load balancers that use IPv4 addresses, IPv6 addresses, or both.
The The F5-SSH-SSL Certification pattern extension is part of the F5 load balancer and F5 load balancer SSH patterns that discover [F5 BIG-IP load balancer](https://servicenow-prod.fluidtopics.net/CdSmjjxJaPKXByxudAfv0w "Discovery and Service Mapping can find F5 BIG-IP load balancers via SNMP, SSH, and through the REST API."). The The F5-SSH-SSL Certification pattern extension discovers F5 load balancer instances running on the hosts via SNMP/SSH, and then discovers certifications used by the running node of the load balancer.  
Note:  
For load balancers running IPv6, only SSH is supported.

## Request apps on the Store {#f5-certificate-discovery__section_ltl_dsh_2nb}

Visit the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website to view all the available apps and for information about submitting requests to the store. For cumulative release notes information for all released apps, see the [ServiceNow Store version history release notes](https://www.servicenow.com/docs/r/store-release-notes/sn-store-release-notes.html).{#f5-certificate-discovery__inline-send-to-store}
For details on system requirements and family compatibility, view the application listing on the [ServiceNow Store](https://store.servicenow.com/sn_appstore_store.do#!/store/home) website.

## IPv6 support limitations {#f5-certificate-discovery__section_aky_4zg_q5b}

* F5 SNMP is not supported.
* MID Server cannot run REST APIs with IPv6.

  To run discovery with F5 REST, see [KB0864769](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB0864769).
{#f5-certificate-discovery__ul_zj2_rzg_q5b}

## Prerequisites {#f5-certificate-discovery__section_szy_hsh_2nb}

Verify the applications are up to date
:
    * Discovery and Service Mapping Patterns
    * CMDB CI Class Models
    {#f5-certificate-discovery__ul_mmm_gq3_rbc}

Verify the configuration of F5 load balancer
:
    * Ensure that F5 load balancer instances are up and running.
    * Make sure the host (that has the F5 instance running on it) can discover successfully with the Discovery user credentials.
    {#f5-certificate-discovery__ul_osf_wl3_2nb}

Verify the configuration of Discovery
:   Ensure that the Discovery user added in the ServiceNow AI Platform instance can run the following commands: {#f5-certificate-discovery__table_h4p_1p3_2nb__entry__2}

    | Command | Description |
    |-|-|
    | modify | Modifies the TMSH components. You can modify one or more property settings in multiple components. The modify command uses the following option: display-threshold pager |
    | display_threshold | Allows you to re-enable a display-threshold in your script. |
    | list | Displays components that you have permission to view or are passed as arguments. The list command looks for the following arguments: * ssl-cert * certificate-key-size * checksum * create-time * expiration-string * issuer * subject * version * fingerprint * serial-number * subject-alternative-name * size {#f5-certificate-discovery__ul_ibv_lkk_hnb} |
    [ ]

    {#f5-certificate-discovery__table_h4p_1p3_2nb}

Verify the configuration of the patterns

:   Make sure that the F5-SSH-SSL Certification shared library is added to the extension section of the F5 Load Balancer and F5 Load Balancer SSH
    patterns, in order to collect the certification attributes.

## F5 certificate discovery class model {#f5-certificate-discovery__section_ihy_ms3_2nb}

<br />

<br />

## Data collected by Discovery during horizontal discovery {#f5-certificate-discovery__section_vdv_f53_2nb}

The discovered data includes the following tables and fields.
{#f5-certificate-discovery__table_w2j_l53_2nb__entry__2}

| Table and field | Description |
|-|-|
| Base Configuration Item Cluster \[cmdb\] ||
| Serial number | Serial Number associated with the CI. |
| Configuration Item \[cmdb_ci\] ||
| operational_status | Operational status of the cluster node. |
| Unique Certificate \[cmdb_ci_unique_certificate\] ||
| fingerprint | Hash value of the certificate. |
| fingerprint algorithm | Algorithm used to hash the certificate. |
| subject common name | Identifies the hostname/domain associated with the certificate. |
| subject distinguished name | Identifying information of the subject. |
| issuer distinguished name | Distinguished name of the issuer. |
| comments |   |
| renewal tracking | Indicates whether to create any priority 1 or priority 3 tasks for the expiring certificates. |
| issuer common name | Common name of the issuer. |
| valid From | Validity start period of the certificate. |
| serial Number | Serial Number associated with the CI. |
| subject country | The subject's two letter country code. |
| subject organization | Subject's organization. |
| Version | X.509 version of the certificate. |
| Issuer | Entity that signed and issued the certificate. |
| subject organizational unit | Subject's organizational unit. |
| subject alternative name | List of fully qualified domain names secured by the certificate. |
| valid to | Validity end period of the certificate. |
| name |   |
| State | Lifecycle states of the certificate. |
| root issuer | Root entity that signed and issued the immediate certificate. |
| key size | Size of the key used by the signing algorithm. |
| subject locality | Subject's locality. |
| subject state | Subject's state. |
[ ]

{#f5-certificate-discovery__table_w2j_l53_2nb}

## CI relationships {#f5-certificate-discovery__section_fy1_5x3_2nb}

The The F5-SSH-SSL Certification pattern extension does not create any CI relationships.

