---
sourceDocument: Zurich IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-operations-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Run Certificate Discovery via ACC-VC

# Run Certificate Discovery via Agent Client Collector for Visibility Content {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Discover TLS/SSL certificates used by ports running on the agent's server. The Certificate Inventory and Management application uses this information to manage TLS/SSL certificates.

## Before you begin

Verify that the latest version of Agent Client Collector for Visibility Content (ACC-VC) is installed.

Verify that the latest version of Certificate Inventory and Management is installed.

Role required: agent_client_collector_admin

## Procedure

1. Navigate to AllAgent Client CollectorPolicies.
2. Enable the TLS SSL Certificate Capture policy.
3. Navigate to AllSystem propertiesAll properties.
4. To discover certificates on specific ports:
   1. Locate and select the sn_acc_vis_content.tls_ssl_scanner_ports property.
   2. Enter a comma-separated list of port numbers on which to scan for certificates in the Choices field.  
      By default, the values are identical to those values configured for the tls_ssl_certs property.
   {#run-cert-discovery-accvc__substeps_my1_q5t_ghc}
5. To discover certificates on all available open ports:
   1. Locate and select the sn_acc_vis_content.tls_ssl_scan_all_open_ports property.
   2. Assign the value true.
   {#run-cert-discovery-accvc__substeps_m4t_v5t_ghc}
6. **Optional:** To store the original certificate in the instance, set the sn_acc_vis_content.tls_ssl_keep_original property to true.

## Result

The Agent Client Collector collects the data and discovers the TLS/SSL certificates. This data is the same as what is gathered by the IP-based tls_ssl_probe property.  
The TLS/SSL certificates are populated in the following tables:

* Discovered Certificates \[sn_disco_certmgmt_certificate_history\]
* Unique Certificates \[cmdb_ci_certificate\]
* Installed Certificates \[sn_disco_certmgmt_cmdb_installed_certificate\]
{#run-cert-discovery-accvc__ul_ajr_s2s_rfc}

A CI relationship is created between the discovered certificates and the corresponding Host CI (in this case, the agent's server).
**Related tasks**   

* [Run certificate discovery via port scans](https://www.servicenow.com/docs/Jgjy1nhDm46eTBnpM5ovZg "When the TLS port probe [tls_ssl_certs] is enabled, Discovery automatically scans 14 pre-authorized ports as part of your existing CI Discovery schedules.")  
**Related reference**   

* [Certificate Inventory and Management](https://www.servicenow.com/docs/1hIMGcpjS1JouMKjapv7Kw "With Certificate Inventory and Management, you can discover, conduct an inventory, and proactively manage all TLS certificates. Certificate Inventory and Management supports IPv6, providing comprehensive coverage for your certificate management needs.")

*[\>]: and then


