---
sourceDocument: Yokohama ServiceNow AI Platform Capabilities
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/servicenow-platform

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama ServiceNow AI Platform Capabilities

ft:clusterId :

    - platcap

bundleId :

    - platcap

workflow :

    - Platform


---

# Add SSL certificates for the MID Server

# Add SSL certificates for the MID Server {#ariaid-title1}

* Release version: Yokohama
* 
* Updated January 30, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read

Configure the MID Server to connect to a source over SSL.

## Before you begin

Role required: admin

|-|
|   |
[ ]

{#add-ssl-certificates__table_kvf_3v4_nhb}

## About this task

You can add certificates to the MID Server to communicate over SSL/TLS in one of two ways:

* Add certificates directly to the bundled JRE TrustStore file, using the following procedure.
* Specify a different TrustStore file for the MID Server to use. For more information, see [Specify an external TrustStore for the MID Server](https://www.servicenow.com/docs/L40L3~9gm~8pfHl7bZ1sbw "The MID Server JVM can utilize a TrustStore external to the MID installation directory so any certificates added to the TrustStore are not overwritten during an upgrade. It is important that this TrustStore file reside outside of the MID installation directory, and the Truststore location can be specified by adding additional parameters to the MID Server's wrapper-override.conf file.").
{#add-ssl-certificates__ul_typ_fbz_2qb}Review both methods to evaluate which best meets your needs.  
During MID upgrade the bundled TrustStore is overwritten. The MID Server attempts to migrate certificates from the existing TrustStore to the incoming one. To be migrated, certificates must meet the following criteria:

Quebec (backported to Orlando Patch 10 and Paris Patch 4)
:
    * X.509 v3 certificates
    * Basic Constraints Extension evaluates to false (or is not present)
    {#add-ssl-certificates__ul_vrh_lbz_2qb}

Rome (backported to Paris Patch 7 and Quebec Patch 2)
:
    * X.509 certificates
    * Any certificate present in the source, but not the destination TrustStore
    {#add-ssl-certificates__ul_r14_nbz_2qb}

Certificates that do not meet the criteria are overwritten. Alternatively, you can
specify an external TrustStore file which is unaffected by MID Server upgrades. For
more information, see [Specify an external TrustStore for the MID Server](https://www.servicenow.com/docs/L40L3~9gm~8pfHl7bZ1sbw "The MID Server JVM can utilize a TrustStore external to the MID installation directory so any certificates added to the TrustStore are not overwritten during an upgrade. It is important that this TrustStore file reside outside of the MID installation directory, and the Truststore location can be specified by adding additional parameters to the MID Server's wrapper-override.conf file.")  
In Rome and later families, the migration strategy utilized during upgrade is configurable via the MID Server configuration parameter mid.truststore.migration.strategy. It can take the following values:

* migrate_delta: the default strategy (outlined above for Rome)
* migrate_non_ca: a strategy matching the one outlined above for the Quebec family
* do_not_migrate: disables the TrustStore migration during upgrade, though a backup of the original TrustStore is made in the event of overwrite
{#add-ssl-certificates__ul_ur1_pbz_2qb}

During this migration process, a backup of the original and upgrade TrustStores are
made and stored in the agent's work directory:
...\\agent\\work\\truststore_migration\\\<time epoch seconds\>\\.
The original TrustStore is renamed to cacerts_before and the
upgrade TrustStore is renamed to cacerts_from_upgrade.

When switching to an external TrustStore, import all certificates from the bundled TrustStore into it. The MID Server might fail to start if a required certificate is missing from the new TrustStore.

## Procedure

1. Open a command prompt and navigate to the folder containing the JRE [keytool](https://docs.oracle.com/javase/6/docs/technotes/tools/solaris/keytool.html).  
   This is the location of the JRE bundled with the MID Server. An example path might be: C:\\Mid Server\\agent\\jre\\bin
2. Import a certificate into the MID Server's cacerts keystore, using this command:  
   `keytool -import -alias <certificate alias> -file "<path to certificate>" -keystore "<`path to the MID Server bundled JRE`>\lib\security\cacerts"`

   For example, you might enter: `keytool -import -alias MyCA -file "C:\myca.cer" -keystore "C:\Mid Server\agent\jre\lib\security\cacerts"`  
   Note:  
   The keytool utility prompts you for the TrustStore password. The default password for the MID Server bundled JRE TrustStore cacerts is <kbd class="ph userinput">changeit</kbd>. If the default password has
   been changed, enter the current password. Don't change the TrustStore password unless your security policy requires it.

   If the certificate is for a CA, the keytool also asks whether to trust the certificate authority. To add a certificate to an instance, see [Upload a certificate to an instance](https://www.servicenow.com/docs/access?context=t_UploadACertificateToAnInstance&version=yokohama&pubname=yokohama-platform-security&ft:locale=en-US).
3. **Optional:** Display a list of the current certificates by running the command: `keytool.exe -list -keystore "C:\Mid
   Server\agent\jre\lib\security\cacerts"`
**Related concepts**   

* [MID Server certificate check policies](https://www.servicenow.com/docs/tOKLEFH3vUlhK8cK6T9Qbg "MID Server uses three kinds of security checks to secure external traffic. The security checks use TLS/SSL certificate validation, hostname validation, and OCSP validation to improve security. Control these security checks with the MID Server certificate check policies table.")
* [MID Server authentication credentials and SOAP requests](https://www.servicenow.com/docs/BPXeR~A4Pja0FFKo5zJnNQ#mid-authentication-soap-requests "Set basic authentication credentials to update the web service invocation data. For added security, you can enforce basic authentication on each incoming SOAP request to the MID Server.")
* [MID Server unified key store](https://www.servicenow.com/docs/PC4ku1Ji6e1D~jCtGlLMdQ#mid-unified-keystore "The MID Server unified key store allows all products on the MID Server to use common certificates and key pairs. This feature allows applications to use the same secure communication channel to the MID Server that the MID Server uses to connect to the instance.")
* [MID Server command audit log](https://www.servicenow.com/docs/TKg5HoGYD3aeMymIaXTgtg "The command audit log records the commands run by the MID Server for the Discovery application. Review the commands to check for anomalies or errors.")
* [MID Server FIPS Enforced Mode](https://www.servicenow.com/docs/yxoIYPMPcSO~EwcvjLToVA#mid-fips-enforced "The MID Server supports the National Security Cloud (NSC) IL-5 environment, which requires all utilized cryptography to be FIPS validated. The MID server can be run in FIPS Enforced Mode, where only cryptographic algorithms which are FIPS validated are utilized.")
* [MID Server Governance](https://www.servicenow.com/docs/q3~hPnrT2lKXM8RCmlRC_A "Improve MID Server security by setting an automatic timeout to invalidate and shut down inactive MID Servers. You can enable this feature and set the inactivity timeout period globally and for each MID Server.")  
**Related tasks**   

* [Encrypt or decrypt MID Server configuration file values](https://www.servicenow.com/docs/se2YdJ_e18Y8Bn~j31Zp_w "The value of any MID Server parameter in the config.xml file can be encrypted. The attributes for all encrypted values are managed from within the configuration file, including the security attribute of the login password.")
* [Enable MID Server mutual authentication](https://www.servicenow.com/docs/82SMuK_ICPRrJdpDGUyjnw "Configure the MID Server to use a client certificate for authenticating to the instance. This avoids the need to create a basic authentication credentials in the Key Store for the MID Server's configuration.")
* [MID Server Azure Key Vault integration](https://www.servicenow.com/docs/8gVpuy6YYoY3ZnqDnFpTfw#mid_azure_key_vault_integration "The MID Server integration with the Azure Key vault enables Orchestration, Discovery, and Service Mapping to run without storing any credentials on the instance.")
* [Rekey a MID Server](https://www.servicenow.com/docs/bAXGhBncVeafIyy2~xKKEA "Rekey a MID Server to generate a new private key. Private keys are used to decrypt automation credentials, so that MID Servers can transmit information securely. Key pairs are initially generated when a MID Server is validated, and MID Servers should be rekeyed periodically to meet security requirements.")
* [Specify an external TrustStore for the MID Server](https://www.servicenow.com/docs/L40L3~9gm~8pfHl7bZ1sbw "The MID Server JVM can utilize a TrustStore external to the MID installation directory so any certificates added to the TrustStore are not overwritten during an upgrade. It is important that this TrustStore file reside outside of the MID installation directory, and the Truststore location can be specified by adding additional parameters to the MID Server's wrapper-override.conf file.")
* [Attach a script file to a file synchronized MID Server](https://www.servicenow.com/docs/1mKnTHT3aJ0ikYKoz3j0xg#mid-server-script-attach "You can attach a script file to synchronize to a connected MID Server.")  
**Related reference**   

* [MID Server configuration file security](https://www.servicenow.com/docs/ZnQrxSVhYYvmmwNxcSR~Cw "Sensitive MID Server configuration data can be protected using several different schemes, including internal and external data encryption and external data storage.")
* [MID Server SSH cryptographic algorithms](https://www.servicenow.com/docs/m0Y7qqMJwFfwS6Fe5rcLbg "The MID Server utilizes SSH clients to perform many discovery actions. During the SSH handshake, both the client and server first determine which algorithms both parties support, then client picks the highest priority algorithm. For the Host Key Algorithm, the client picks highest priority algorithm which both parties support that matches the key type.")

