---
sourceDocument: Yokohama IT Operations Management
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/it-operations-management

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama IT Operations Management

ft:clusterId :

    - itom

bundleId :

    - itom

workflow :

    - Technology


---

# Agent certificate rotation

# Agent certificate rotation {#ariaid-title1}

* Release version: Yokohama
* 
* Updated June 22, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The Agent Client Collector certificate is valid for two years and must be rotated before it expires to avoid issues with agent connectivity. When expiration is approaching, the agent initiates a certificate rotation
request.  
When an Agent Client Collector's certificate expiration is approaching, system properties verify that a valid certificate is in place when the existing certificate expires.

* certificate-rotation-days-out: Indicates the number of days before certificate expiration that an agent attempts to rotate its certificate. Configured in the acc.yml configuration file. Default = 28.
* sn_agent.certificate_rotation_days_out: Indicates the number of days before certificate expiration that the system accepts a certificate rotation request for a specific agent. Configured on the System Properties page (AllSystem PropertiesAll Properties). Default = 28.
{#agent-certificate-rotation__ul_mg4_wbb_tfc}
**Related tasks**   

* [View the Agent Client Collector configuration file for an agent](https://www.servicenow.com/docs/6UFdGLbuRUjsyAHTsCiWbg "View the acc.yml Agent Client Collector configuration file without having to access the host server by retrieving the file from an agent.")  
**Related reference**   

* [Configuration file options](https://www.servicenow.com/docs/zq_E2TBTbSIGbIQLrAYa_A "Options available in the acc.yml configuration file.")

*[\>]: and then


