---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Visibility to TLS certificates

# Visibility to TLS certificates {#ariaid-title1}

* Release version: Yokohama
* 
* Updated August 25, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Certificate Inventory and Management application allows Discovery to automatically scan for certificates on specific ports through
your existing CI-based Discovery schedules. In addition, you can create Discovery schedules to
scan for specific URLs.

The ServiceNow Store regularly releases new applications and updates to applications that are created by ServiceNow. If you already have the application, you can download the latest version to enhance your existing experience with our products. Since different features are available or enhanced each time an application is released in the Store, the content and features available in a particular release are indicated by version number in this document.

In Certificate Inventory and Management, you can add a list of
imported certificates to [Run Certificate Discovery via certificate file import](https://servicenow-prod.fluidtopics.net/efKCiaEDQiIz_DNL_1eTGQ "In Certificate Inventory and Management, you can discover certificates by importing certificate files into the system using pattern-based Discovery."), and scan for
certificates from your Certificate Authority (CA) such as GoDaddy and DigiCert. You can
also scan Sectigo and Entrust CAs.  
The existing certificate authority patterns for DigiCert to collect the following fields as part of the CA Trust Certificate discovery. These fields are required to create an automated flow (request, renew, or revoke) for certificates discovered by Digicert CA Discovery and are stored in the Certificate Extensions \[sn_disco_certmgmt_certificate_extension\] table.

* Certificate Id
* Order id
* Thumbprint
* Serial Number
* Certificate Status
{#run-cert-discovery__ul_mhh_spv_mqb}

Using the Certificate Inventory and Management, you can [Run Certificate Discovery via port scans](https://servicenow-prod.fluidtopics.net/F45oZmiPEW28Gq0x1L4utw "When the TLS port probe [tls_ssl_certs] is enabled, Discovery automatically scans 14 pre-authorized ports as part of your existing CI Discovery schedules."). You can also [Run Certificate Discovery via individual URL scans](https://servicenow-prod.fluidtopics.net/H3lnbAZB50Y2nYvCUjE_ag "To initiate certificate discovery through URL scans, you must manually include individual URLs and configure a new certificate Discovery schedule.").

To Import Certificates or Discovery CA Trust with more than 1500 certificates, create the
discovery schedule with more than one serverless patterns configured. Each pattern execution
supports a maximum of 1500 certificates discovery.

To discover all the certificates, the limit (defaults to 1500) and start_offset (defaults
to 0), must be configured accordingly. For example, to fetch up to 6,000 certificates, add
four serverless patterns with start_offset 0, 1500, 3000, and 4500. Start_offset and limit
parameters are configured as shown.


