---
sourceDocument: Brazil IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-operations-management

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Automated certificate management for TLS certificates

# Automated certificate management for TLS certificates {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
From Certificate Inventory and Management version 1.3.8, you can automate the request flow for new certificates, renewals, and revoking certificates.

Certificate Inventory and Management automatically fetches certificates from Certificate Authorities (CAs) without requiring manual intervention from the PKI team. Starting in Version 2.1.0, this feature supports DigiCert and
Entrust CA Gateway for seamless automatic fulfillment flows, with the limitation that only OV DigiCert certificates can be requested. Version 2.3.2 introduces support for the Microsoft CA. For automated flows with DigiCert or
Entrust CA Gateway in Certificate Inventory and Management, you must have permissions to request, renew, and revoke certificates.  
For provider-specific requirements, see the following documentation:

* Microsoft CA: For information about configuring and administering a Microsoft certification authority, go to [Microsoft Learn](https://learn.microsoft.com/en-us/) and search for the "Active Directory Certificate Services documentation" article.
* DigiCert: For information about API access and certificate order management, go to the [DigiCert developer portal](https://dev.digicert.com/) and search for the "CertCentral APIs" documentation.
* Entrust: Refer to your Entrust CA Gateway documentation.
{#automated-cert-requests__ul_dn5_3fh_lkc}

For automated flows with DigiCert or Entrust CA Gateway in Certificate Inventory and Management, you must have permissions to request, renew, and revoke certificates.  
The Microsoft CA user requires the following permissions:{#automated-cert-requests__table_xdl_5jz_31c__entry__2}

| Permission | Action |
|-|-|
| CredSSP on CA, intermediate server, and MID Server | Set up CredSSP on CA, intermediate server, and MID Server. For CredSSP configuration steps, see the Now Support Knowledge Base documented in the KB article [KB1632624](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1632624). |
| Membership in Enterprise Admins | Ensure the user holds membership in the Enterprise Admins group. |
| Security Group Inclusion for Template | Ensure the user is included in the Security Group of the template. |
| Specific Permissions in CA | Grant the user permissions: Read, Issue and Manage Certificates, Manage CA, and Request Certificates in the CA. |
[Table 1. Microsoft Gateway user permissions]

{#automated-cert-requests__table_xdl_5jz_31c}

