---
sourceDocument: Zurich IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/it-operations-management

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Integration with KeyFactor EJBCA automated flows

# Integration with KeyFactor EJBCA automated flows {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Automate the flow of requesting, renewing, and revoking your certificates by integrating Keyfactor EJBCA with the Automated Certificate Management Environment (ACME).
Keyfactor EJBCA is a certificate authority that issues your certificates. ACME are a set of protocols and rules that give you a secure environment to use an automated flow of managing certificates.

By configuring your routing policy fields, you can ensure that the content in your Certificate Signing Request (CSR) aligns with the correct routing policy. This streamlines the process of requesting, renewing, and revoking your
certificates.

EJBCA has two types of Credentials. One includes External Account Binding (EAB), and the other doesn't.

In EJBCA, automated certificate workflows start when you create routing policies for EJBCA ACME Certificates. For every routing policy, there are required fields where you have to give information.

Your platform has routing policies where you fill in all the fields of the routing policy. Your platform aligns that information to each CSR you create to request, renew, and revoke certificates.

For more information, see [Create routing policies for EJBCA ACME certificates](https://www.servicenow.com/docs/ai9bslE476tZdSVaANwf4Q "Automate your EJBCA ACME workflows by creating a routing policy that aligns with your Certificate Signing Requests (CSRs) to request, renew, and revoke certificates.").

Perform the following task to use EJBCA ACME to automate your certificate life cycle:

1. [Create a Connection \& Credential alias](https://www.servicenow.com/docs/access?context=connection-alias&version=zurich&pubname=zurich-platform-security&ft:locale=en-US)
2. [Configure base API URL for EJBCA ACME](https://www.servicenow.com/docs/fNdiz~gm6XSCwpQIziM4Rw "Configure your base API URL for EJBCA ACME to your organization's root URL address.")
3. [Validate EJBCA ACME base API URL](https://www.servicenow.com/docs/aqOE7Lnk3XE0dqUa39q7QA "Validate that your base API URL for EJBCA ACME has been updated to your organization's root URL address.")
{#automate-certificates-ejbca-acme__ol_km5_h5d_1gc}

