---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Verify certificate chain and hostname

# Verify certificate chain and hostname {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
Configure the com.glide.communications.httpclient.verify_hostname property to prevent man-in-the-middle-attacks by ensuring that the certification verification process is executed.
When the com.glide.communications.httpclient.verify_hostname property is not set to the secure value of true, the hostname and certificate chain presented by remote hosts during a TLS connection initiated from the ServiceNow instance are not validated.

This vulnerability compromises the security of the TLS connection and allows person-in-the-middle attacks, where communications between two parties are intercepted. This may lead to sensitive data disclosure.

Ensure that the com.glide.communications.httpclient.verify_hostname system property is set to the secure value of true.

## More information {#sc-verify-certificate-chain-and-hostname__section_qhx_1b1_xwb}

{#sc-verify-certificate-chain-and-hostname__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | com.glide.communications.httpclient.verify_hostname |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Default value | true |
| Fallback value | false |
| Category | [Communications](https://www.servicenow.com/docs/Ol4HTvWwwFO1g_KjaK_8RQ "This control ensures proper encryption using strong algorithms and ciphers. This includes ensuring the recommended version of TLS is used for client connectivity, use of strong cipher suites, use of trusted and signed certificates, ensuring connections are encrypted between components and logging of connection failures.") |
| Security risk | * Severity score: High * CVSS score: 7.4 * Security risk details: This vulnerability compromises the security of the TLS connection and allows person-in-the-middle attacks, where communications between two parties are intercepted. This may lead to sensitive data disclosure. {#sc-verify-certificate-chain-and-hostname__ul_ihv_dvg_1xb} |
| Dependencies and prerequisites | The com.glide.communications.httpclient.verify_hostname property governs hostname and certificate chain validation independently of the com.glide.communications.httpclient.verify_revoked_certificate property, the overall gate for certificate revocation checking. |
| Functional impact | When the com.glide.communications.httpclient.verify_hostname property is set to true, an outbound HTTPS connection is rejected if the remote host's certificate does not match the requested hostname or its certificate chain can't be validated. Outbound integrations to hosts with a mismatched or misconfigured certificate will fail to connect once this property is set to true. |
[ ]

{#sc-verify-certificate-chain-and-hostname__table_ajc_b43_3kb}

