---
sourceDocument: Australia IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-operations-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Visibility to TLS certificates

# Visibility to TLS certificates {#ariaid-title1}

Release version: Australia  
Updated March 12, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
The Certificate Inventory and Management application allows Discovery to automatically scan for certificates on specific ports through
your existing CI-based Discovery schedules. In addition, you can create Discovery schedules to
scan for specific URLs.

The ServiceNow Store regularly releases new applications and updates to ServiceNow applications. If you already have an application, you can download the latest version to enhance your existing experience with ServiceNow products. Features vary by release. The version number indicates which content and features are available in each release.

In Certificate Inventory and Management, you can add a list of
imported certificates to [Run certificate discovery via certificate file import](https://www.servicenow.com/docs/xI_g1cfWB9wFpMllv9f8zw "In Certificate Inventory and Management, you can discover certificates by importing certificate files into the system using pattern-based Discovery."), and scan for
certificates from your Certificate Authority (CA) such as GoDaddy and DigiCert. You can
also scan Sectigo and Entrust CAs.  
The existing certificate authority patterns for DigiCert to collect the following fields as part of the CA Trust Certificate discovery. These fields are required to create an automated flow (request, renew, or revoke) for certificates discovered by Digicert CA Discovery and are stored in the Certificate Extensions \[sn_disco_certmgmt_certificate_extension\] table.

* Certificate Id
* Order id
* Thumbprint
* Serial Number
* Certificate Status
{#run-cert-discovery__ul_mhh_spv_mqb}

Using the Certificate Inventory and Management, you can [Run certificate discovery via port scans](https://www.servicenow.com/docs/oUQFXXOCFU0sigXev_tfxw "When the TLS port probe [tls_ssl_certs] is enabled, Discovery automatically scans 14 pre-authorized ports as part of your existing CI Discovery schedules."). You can also [Run certificate discovery via individual URL scans](https://www.servicenow.com/docs/~MKkFNZ621NRvG_EDH9Z3g "To initiate certificate discovery through URL scans, you must manually include individual URLs and configure a new certificate Discovery schedule.").

To Import Certificates or Discovery CA Trust with more than 1500 certificates, create the
discovery schedule with more than one serverless patterns configured. Each pattern execution
supports a maximum of 1500 certificates discovery.

To discover all the certificates, the limit (defaults to 1500) and start_offset (defaults to 0), must be configured accordingly. For example, to fetch up to 6,000 certificates, add four serverless patterns with start_offset 0,
1500, 3000, and 4500.

