---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Request certificate using ACME automatic flow

# Request new certificate using ACME automated flow of DNS challenge {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Request a new certificate and automatically retrieve the certificates for an application using an Automated Certificate Management Environment (ACME) automated flow of DNS challenge.

## Before you begin

Ensure that a credential has been set up.  
Note:  
The GoDaddy credential is provided with the base system inside the credential page.

The Certificate Management catalog has been enabled.

A routing policy with a DNS challenge action exists.  
Role required: Certificate requester, PKI admin, PKI user, flow_designer, action_designer, or admin  
Note:  
A certificate requester is a user who doesn't have the PKI admin or PKI user role.

## Procedure

1. Access the automated flow.
   1. Navigate to AllService Catalog.
   2. Select Certificate Management.
   3. Select Automated Flow.
   {#request-new-certificate-using-acme-automated-flow-dns__substeps_my4_3zr_lbc}
2. Select Request New Certificate (Automated).
3. On the form, fill in the fields.  
   {#request-new-certificate-using-acme-automated-flow-dns__table_hx4_qxq_gbc__entry__2}

   | Field | Description |
   |-|-|
   | Certificate Purpose | Indicates whether the request is for an internal or external certificate. For CAs such as Let's Encrypt, select External. |
   | Certificate Signing Request (CSR) | CSR containing certificate information. |
   | Validity Period for Certificate (In Days) | Number of days the certificate is valid. For Let's Encrypt, the maximum validity period is 90 days. |
   | Certificate Owner Group | Group for which the certificate tasks are generated. |
   | Certificate Owner | Name or role of the person who will own the certificate. |
   [Table 1. New certificate form]

   {#request-new-certificate-using-acme-automated-flow-dns__table_hx4_qxq_gbc}  
   The following CSR attributes are matched and auto-populated based on the certificate information from CSR:
   * Subject Common Name
   * Subject Alternative Name
   * Organization
   * Organizational Unit
   * Locality/City
   * Province
   * Country
   * Email Address
   {#request-new-certificate-using-acme-automated-flow-dns__ul_tr3_fnc_nqb}
4. Select Submit.  
   Once the request is submitted, a task is created for completing the DNS challenge. The task is completed automatically.

## Result

* Once DNS record propagation has completed after two minutes, the DNS challenge is completed automatically and the automated flow sends a request to the CA to get the certificate.Admins can change
  this duration by modifying the sn_disco_certmgmt.wait_time_for_dns_record_propagation system property.

* The certificate is attached to the New certificate task.
* The request certificate task status changes to Completed.
{#request-new-certificate-using-acme-automated-flow-dns__ul_gnc_c2h_j1c}

*[\>]: and then


