---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Run IP-Based Certificate Discovery

# Run IP-Based Certificate Discovery {#ariaid-title1}

* Release version: Yokohama
* 
* Updated December 11, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Enable the Transfer Layer Security (TLS) port probe \[tls_ssl_certs\] and scan for
certificates on an IP address or multiple IP addresses.

## Before you begin

Know the IP address, range of IP addresses, or list of IP addresses you want to perform
Certificate Discovery on.

Role required: Certificate administrator, discovery_admin, or admin

## Procedure

1. Activate the TLS port probe \[tls_ssl_certs\].
   1. Navigate to AllDiscovery DefinitionPort Probes.
   2. Open tls_ssl_certs.
   3. To enable the probe, select the Active check box.  
      By default, the check box for any new installation is cleared.
   4. Confirm the Triggered by services has the services you need.  
      By default, the following services trigger the tls_ssl_certs probe: HTTPS,
      tomcat-ssl, IBM Websphere SSL, Idaps, IMAPS, pop3s, ftps-data, ftps, smtp,
      pop3, imap, Idap, ftp, submission.
   5. Select Update.
2. Create an IP-Based Certificate Discovery Schedule.
   1. Navigate to AllDiscoveryDiscovery Schedules.
   2. Select New.
   3. Fill out each text field with its corresponding value.  
      For more information on the fields and values, see [IP-Based Discovery Schedule Form Table](https://servicenow-prod.fluidtopics.net/qEKiqOdCT~UAHjz4qZOa1g "A table of the fields and values to set up an IP-based Certificate Discovery schedule.").
   4. Select and hold (or right-click) above Discovery Schedule and select Save.  
      By selecting Save, additional configuration options are available.
   5. Select the Use SNMP text field.
   6. In the new tabs that appear, select Discovery IP Ranges.
   7. Select New.
   8. Fill each field with its corresponding value.  
      For more information on the fields and values, see [Setting Your IP Addresses Form and Fields Table](https://servicenow-prod.fluidtopics.net/U6eldEKz5AIGLf4T11vJIg "A table of the fields and values to establish the IP address, range of IP addresses, or list of IP addresses for Certificate Discovery.").
   9. Select Submit.  
      The port tls_ssl_certs will look for Certificates available inside your selected IPs at the next time interval (daily, weekly, monthly, etc.).
   {#run-ip-based-certificate-discovery__substeps_zjf_mpt_kjb}
3. Create an IP-Based Certificate Quick Discovery for immediate discovery (optional).
   1. Navigate to AllDiscoveryDiscovery Schedules.
   2. Select Quick Discovery.
   3. Enter your Target IP into the Target IP field.  
      Warning:  
      Make sure that your IP address is accessible to the MID Server you're using. If it doesn't, you have to set [Credential aliases for Discovery](https://www.servicenow.com/docs/access?context=discovery-credential-alias&version=yokohama&pubname=yokohama-platform-security&ft:locale=en-US).
   4. Select OK.
   {#run-ip-based-certificate-discovery__substeps_u54_xpt_kjb}

## Result

The probe tls_ssl_certs searches for Certificates inside your selected IP immediately, and reports the certificates it finds.

*[\>]: and then


