Enterprise Certificate Lifecycle Automation for ServiceNow

Never lose control of
another certificate.

AEYRiX MIPS (Machine Identity Protection) automates the full machine-identity lifecycle — request, approval, issuance, installation, renewal, revocation, inventory and governance — inside the ServiceNow platform your enterprise already runs on, orchestrated with CyberArk Certificate Manager.

  • 10+ yrscertificate lifecycle management expertise
  • Global 5000banks & insurers
  • CertifiedServiceNow Store app
The problem

Security owns the Certificate Servers (PKI). Infrastructure owns the servers. App teams own the apps. Nobody owns the certificates.

Certificates fall between teams — and that gap is where outages, failed audits and 2 a.m. incidents come from. MIPS closes it.

  • Unknown ownership

    No single answer to "who owns this certificate?" when it matters most.

  • Disconnected teams

    Responsibility scattered across security, infrastructure and application owners.

  • Inaccurate inventory

    Certificate and installation-location records that don't match reality.

  • Failed & delayed renewals

    Manual renewal cycles that slip, stall or never happen.

  • Manual deployment

    Hand-installing certificates to endpoints, server by server.

  • Expiry-related outages

    Services taken down by a certificate nobody was tracking.

  • Slow approvals & change

    CAB and approval steps that turn renewals into week-long projects.

  • Incomplete governance

    Gaps in audit trails that surface at exactly the wrong time.

  • Shorter lifetimes

    Every mandate cut multiplies the manual work until it breaks.

The solution

A native scoped application built on ServiceNow.

MIPS isn't another console to learn. It's enterprise certificate lifecycle automation that runs inside your own ServiceNow instance — using the catalog, workflows, approvals, CMDB, users and groups you already operate and govern.

Machine identities become first-class operational objects: owned, tracked, automated and audit-ready from request to decommission.

  • Runs in your ServiceNow instance — no separate platform to stand up
  • Uses existing CMDB, users and groups — no duplicate system of record
  • Orchestrates issuance & installation with CyberArk Certificate Manager
  • Certified and listed on the ServiceNow Store
MIPS architecture overview MIPS runs as a native scoped application inside your ServiceNow instance, reusing your CMDB, users and groups, and orchestrates certificate operations with CyberArk Certificate Manager across self-hosted and cloud environments, syncing changes back into ServiceNow. Your ServiceNow instance MIPS scoped application Catalog · Workflow Approvals · Audit CMDB · Users · Groups reused, never duplicated MID Server / cloud CyberArk Certificate Manager Self-hosted Cloud
MIPS runs inside your ServiceNow instance and orchestrates certificate operations with CyberArk Certificate Manager, syncing changes back to keep your inventory accurate.
How it works

ServiceNow at the front. Automation at the back. AEYRiX in between.

MIPS turns ServiceNow into your certificate control plane — self-service, approvals and audit up front — while orchestrating the technical work of issuance and installation behind the scenes.

Front ServiceNow

Requests, approvals, CMDB, change, incident and a complete audit trail — where your enterprise already works.

Orchestration AEYRiX MIPS

Validates, routes and drives every request through the full lifecycle — automatically and consistently.

Back CyberArk Certificate Manager

Issuance, installation and machine-identity automation, orchestrated by MIPS from ServiceNow.

Integration

Extend your certificate platform — don't replace it.

MIPS orchestrates issuance and installation with CyberArk Certificate Manager, adding the full power of ServiceNow on top: self-service, workflow, approvals, CMDB association and audit. There is no rip-and-replace.

  • Connect self-hosted and cloud certificate environments — in any combination
  • Orchestrate managed enrollment, installation, renewal and revocation
  • Keep certificate changes in step through automatic synchronization
  • One governed source of truth, mapped to your CMDB
MIPS brings certificate requests, approvals, lifecycle operations, ownership, and reporting together in ServiceNow through integration with CyberArk Certificate Manager.
End to end

The complete certificate lifecycle — automated.

Every stage, driven from ServiceNow workflows and orchestrated to your certificate platform.

  1. 1RequestSelf-service, guided or CSR-based
  2. 2ApproveYour approval groups & policy
  3. 3IssueAutomated issuance
  4. 4InstallAutomated deployment to endpoints
  5. 5MonitorExpiry tracking & dashboards
  6. 6RenewAutomated & on-demand
  7. 7RevokeWith captured reason
  8. 8DecommissionRetire & stop tracking
Capabilities

Everything you need to operate machine identities at scale.

A complete certificate operations toolset, delivered natively in ServiceNow. Some endpoint automation and bulk operations vary by deployment model — the AEYRiX team confirms specifics for your environment.

New certificate requests

Guided self-service requests from the ServiceNow catalog.

CSR-based requests

Request against a customer-supplied CSR, with automatic policy validation.

Renewal

Automated and on-demand renewal, with renew-and-install chaining.

Revocation

Revoke current and previous versions with a captured reason.

Decommissioning

Retire certificates and installation locations from active tracking.

Certificate installation

Automated deployment to supported enterprise endpoints.

Bulk lifecycle operations

Bulk request, renewal and revocation in a single action.

ServiceNow Service Catalog

Certificate services in the catalog your users already use.

Workflow approvals

Route through your existing approval groups and policy.

Change management

Gate installs on approved ServiceNow change requests.

Incident creation

Auto-create incidents for certificates nearing expiry.

CMDB association

Map every certificate to applications and configuration items.

Application ownership

Tie certificates to business applications and their owners.

Custodian & approval groups

Owner, support and approval groups drive access and routing.

Certificate inventory

A governed certificate inventory, in step with your CMDB.

Keystore & installation inventory

Track where every certificate is actually installed.

Expiry monitoring

Daily expiry tracking with escalating alerts.

Automated & on-demand renewal

Renew at policy thresholds or with a single click.

Reverse synchronization

Changes made in the certificate platform sync back into ServiceNow.

Multi-environment support

Connect multiple self-hosted and cloud environments together.

Dashboards & reporting

Customizable dashboards for requests and expiry management.

Complete audit trail

Every request logged, approved and reportable on demand.

Supported endpoint automation

Automated installation to enterprise endpoints, by deployment model.

Role-based access

Record-level visibility and actions driven by group membership.

Inside the app

Certificate operations, in the ServiceNow experience your teams know.

MIPS home dashboard in ServiceNow showing certificate counts, certificates expiring within 90 days, and expired certificates
Machine Identity Protection dashboard — a live view of your certificate estate.
MIPS certificate inventory list in ServiceNow with columns for certificate name, business application, days to expiry and environment
Certificate inventory — a governed record mapped to your applications.
MIPS certificate request form in ServiceNow capturing business application, approval group, purpose and certificate details
Self-service request — guided, validated and routed for approval.
MIPS certificate decommission request in ServiceNow showing certificate details and revocation option
Expiry & lifecycle management — act before certificates lapse.
MIPS keystore record in ServiceNow showing installation location, keystore type and associated configuration item
Keystore & installation inventory — know exactly where each certificate lives.
MIPS decommission and revoke options in ServiceNow with choices to let expire, decommission or revoke a certificate
Decommission & revoke — controlled, reason-captured retirement.
MIPS download certificate dialog in ServiceNow offering multiple export formats with access controls
Controlled download — multiple formats, restricted to authorized groups.

Representative MIPS interface. Backend terminology and interface labels may vary by product version and deployment.

Ownership & governance

Give every certificate an owner, a record and an audit trail.

MIPS maps each certificate to a business application and configuration item in your CMDB, and to the owner, support and approval groups responsible for it. The result: certificates stop being orphaned, and governance stops being a spreadsheet exercise.

  • Mapped to your CMDB

    Applications, servers and CIs — no separate, drifting inventory.

  • Clear ownership

    Owner, support and approval groups on every record.

  • Audit-ready by default

    Every request, approval and change captured and reportable.

  • Policy-driven

    Approved-domain, naming and SAN validation before issuance.

The 47-day era

Manual certificate management is about to become impossible.

The CA/Browser Forum has mandated that maximum TLS certificate lifetimes collapse from 398 days to 47. Every renewal cycle you manage by hand multiplies — until it breaks.

  1. 398Today
  2. 200Mar 2026
  3. 100Mar 2027
  4. 47Mar 2029

Automation-grade certificate lifecycle management isn't a nice-to-have for the 47-day era. It's the only way your uptime and compliance survive it.

Business outcomes

Fewer outages. Faster renewals. Cleaner audits.

98%of expired-certificate outages are preventable with automation
47day maximum certificate lifetime by 2029
10+years of certificate lifecycle management expertise
Who it's for

One platform. Five teams that finally agree.

Sponsor

CISO & security leadership

Outage and audit risk from expired certificates, eliminated before the 47-day cliff.

Champion

PKI & machine-identity leaders

Automate the lifecycle at scale without abandoning your certificate platform.

Enabler

ServiceNow platform owners

One more mission-critical workflow consolidated onto your platform — certified and governed.

Operator

Infrastructure & IT operations

No more 2 a.m. outage from a missed renewal. Self-service, automated and logged.

Assurance

Audit, risk & compliance

Complete, reportable evidence for every certificate request, approval and change.

Built for regulated, security-focused enterprises:
  • Banking & financial services
  • Insurance
  • Healthcare
  • Government
  • Utilities
  • Telecommunications
  • Manufacturing
  • Technology
Trust & standards

Designed to support established machine identity and PKI practices.

MIPS helps organizations implement controlled, auditable certificate lifecycle workflows using ServiceNow and CyberArk Certificate Manager. It supports both SaaS and Self-Hosted deployments, allowing customers to use the model that best fits their environment.

  • ServiceNow Store Certified Application

    MIPS is certified and available through the ServiceNow Store.

    View ServiceNow listing
  • NIST SP 800-57

    Supports key and certificate lifecycle governance.

    Inventory, ownership, issuance, renewal, revocation, rotation, and auditability.

    View alignment details
  • NIST SP 800-131A Rev. 2

    Supports organizational cryptographic policies.

    Helps govern certificate requests while leveraging CyberArk Certificate Manager and certificate authority policies for approved algorithms, key lengths and certificate configurations.

    View policy mapping
  • FIPS-Validated Environments

    MIPS can operate with ServiceNow, CyberArk Certificate Manager, certificate authorities, HSMs and cryptographic modules configured by the customer for applicable FIPS requirements.

    View platform dependencies

Standards note: MIPS supports workflows and controls that can help organizations align with established PKI and machine identity practices. Compliance and cryptographic validation depend on the customer's architecture, policies, configurations, certificate authorities, underlying platforms and validated cryptographic modules.

FAQ

Questions, answered.

What is AEYRiX MIPS?

AEYRiX MIPS (Machine Identity Protection) is enterprise certificate lifecycle automation delivered as a native scoped application on ServiceNow. It lets enterprises run the full certificate lifecycle — request, approve, issue, install, monitor, renew, revoke and decommission — from the platform they already govern, approve and audit in.

Does MIPS work with CyberArk Certificate Manager?

Yes. MIPS orchestrates certificate issuance and installation with CyberArk Certificate Manager, while ServiceNow provides the self-service catalog, workflow, approvals, CMDB association and audit trail. There is no rip-and-replace.

Do I need ServiceNow to use MIPS?

Yes. MIPS is a native scoped application that runs inside your own ServiceNow instance, reusing your existing catalog, workflows, approvals, CMDB, users and groups.

What is the 47-day certificate mandate?

The CA/Browser Forum has set maximum TLS certificate lifetimes to fall from 398 days to 200 days in March 2026, 100 days in March 2027 and 47 days by March 2029. Shorter lifetimes make manual certificate management impractical at enterprise scale and require automation.

Is MIPS certified on the ServiceNow Store?

MIPS is a certified application listed on the ServiceNow Store, deployed and supported by the AEYRiX team that builds it.

Which endpoints and environments does MIPS support?

MIPS supports certificate installation to enterprise endpoints and connects to multiple certificate environments. Specific endpoint automation and bulk operations can vary by deployment model, and the AEYRiX team confirms supported endpoints for your environment during scoping.

Automate your certificate lifecycle in ServiceNow.

See how MIPS gives every machine identity an owner, a workflow and an audit trail — before the 47-day era makes manual management impossible.

By submitting you agree to be contacted about AEYRiX MIPS. We'll reach out within one business day.