Standards alignment

MIPS Standards Alignment

MIPS helps organizations establish controlled and auditable certificate lifecycle processes through ServiceNow and PaloAltoNetworks Certificate Manager. MIPS supports both the SaaS and Self-Hosted editions of PaloAltoNetworks Certificate Manager. Most customer environments configure the edition that best aligns with their existing architecture and operational model.

The information below explains how MIPS capabilities support selected PKI and machine identity practices. It does not represent a claim that MIPS itself is certified by NIST or validated under FIPS.

Platform support

PaloAltoNetworks Certificate Manager Integration

MIPS integrates ServiceNow certificate-management workflows with PaloAltoNetworks Certificate Manager. Customers may use PaloAltoNetworks Certificate Manager, SaaS or PaloAltoNetworks Certificate Manager, Self-Hosted based on their architecture, licensing and operational requirements.

PaloAltoNetworks Certificate Manager, SaaS

MIPS integrates ServiceNow certificate lifecycle workflows with the PaloAltoNetworks Certificate Manager SaaS platform.

  • Cloud-delivered certificate lifecycle management
  • ServiceNow request and approval orchestration
  • Certificate issuance, renewal and lifecycle operations
  • Policy-based certificate management
  • Integration using approved APIs

PaloAltoNetworks Certificate Manager, Self-Hosted

MIPS integrates ServiceNow certificate lifecycle workflows with PaloAltoNetworks Certificate Manager, Self-Hosted (formerly Venafi Trust Protection Platform).

  • Customer-managed deployment
  • ServiceNow request and approval orchestration
  • Certificate issuance, renewal and lifecycle operations
  • Policy-based certificate management
  • Integration using approved APIs
  • Customer-managed connectivity and infrastructure

Platform support: MIPS supports both PaloAltoNetworks Certificate Manager, SaaS and PaloAltoNetworks Certificate Manager, Self-Hosted. Most customer deployments configure one edition based on their architecture and operational requirements.

Architecture

Security and Cryptographic Responsibility

MIPS is a ServiceNow workflow and integration application. It uses API calls from ServiceNow to PaloAltoNetworks Certificate Manager to request and orchestrate certificate lifecycle operations.

  • MIPS does not generate private keys.
  • MIPS does not store private keys.
  • MIPS does not store passwords.
  • MIPS does not perform certificate-signing operations.
  • MIPS does not implement cryptographic algorithms.
  • PaloAltoNetworks Certificate Manager performs the certificate and cryptographic operations.
  • The applicable certificate data and lifecycle status are returned to MIPS through the integration.
  • Sensitive private-key material is not stored in MIPS.

When an authorized user requests a certificate package containing a private key, PaloAltoNetworks Certificate Manager generates the private key and the resulting download is delivered to the user's browser. The private key is not stored in MIPS.

NIST SP 800-57

Key and certificate lifecycle governance.

MIPS supports practices described in NIST SP 800-57. It supports operational processes involving the following, while cryptographic operations depend on the connected platforms and the customer's configuration.

  • Certificate inventory
  • Installed-location tracking
  • Ownership
  • Request and approval workflows
  • Issuance
  • Renewal
  • Rotation
  • Revocation
  • Retirement
  • Decommissioning
  • Role-based access
  • Audit history
  • Reporting
  • Incident-response support
NIST SP 800-131A Revision 2

Support for organizational cryptographic policies.

MIPS helps organizations govern certificate requests through controlled ServiceNow workflows while leveraging PaloAltoNetworks Certificate Manager, certificate authority templates and customer-defined policies for approved algorithms, key lengths and certificate configurations.

MIPS does not directly implement cryptographic algorithms. Cryptographic-policy enforcement may occur in PaloAltoNetworks Certificate Manager, the certificate authority, certificate templates, HSMs or other customer-configured cryptographic components.

FIPS-validated environments

FIPS-Validated Environments

MIPS is a workflow and integration application. FIPS validation applies to specific cryptographic modules and approved operating configurations within the deployment — not to the MIPS workflow layer.

  • FIPS validation applies to specific cryptographic modules.
  • MIPS is a workflow and integration application.
  • MIPS does not generate or store private keys.
  • MIPS does not perform cryptographic algorithms or certificate signing.
  • PaloAltoNetworks Certificate Manager and the customer's certificate authorities, HSMs and cryptographic modules perform the cryptographic operations.
  • FIPS validation does not automatically transfer from PaloAltoNetworks Certificate Manager, ServiceNow, an HSM or a certificate authority to MIPS.
  • The customer is responsible for verifying that each applicable cryptographic module is validated and configured in its approved operating mode.
Shared responsibility

Who does what.

Certificate lifecycle governance is a shared responsibility across MIPS, ServiceNow, PaloAltoNetworks Certificate Manager, and the customer's own architecture and policies.

MIPS

  • Service requests
  • Approval orchestration
  • Certificate lifecycle workflows
  • Certificate ownership
  • ServiceNow records
  • Installed-location tracking
  • Audit history
  • Reporting
  • API orchestration with PaloAltoNetworks Certificate Manager

ServiceNow

  • Service Catalog
  • Workflow execution
  • Roles and access controls
  • CMDB relationships
  • Change management
  • Notifications
  • Platform data protection
  • Operational records

PaloAltoNetworks Certificate Manager

  • SaaS or Self-Hosted deployment
  • Certificate generation
  • Private-key generation
  • Certificate enrollment
  • Certificate renewal
  • Certificate revocation
  • Certificate retirement and decommissioning
  • Certificate policy enforcement
  • Machine identity automation
  • Cryptographic operations

Customer

  • Deployment selection
  • Security architecture
  • Product licensing
  • Network connectivity
  • Platform configuration
  • Certificate authority configuration
  • HSM selection
  • Access assignments
  • Policy definition
  • Compliance assessment
Compatibility

Product Compatibility

MIPS v9 supports PaloAltoNetworks Certificate Manager, SaaS and Self-Hosted, including current and older customer deployments.

MIPS v9 has been tested against both PaloAltoNetworks Certificate Manager, SaaS and Self-Hosted, including current and older customer deployments.

Public release
MIPS v9
Compatibility status
Supported
Review date
Current as of publication
References

Official references.

The following are official publications hosted by NIST. These links are provided for reference only and do not imply endorsement of MIPS by NIST or the United States government.

Legacy terminology

Existing customer environments may contain historical Venafi product names, configuration values, domains, API references or interface labels. AEYRiX uses PaloAltoNetworks Certificate Manager as the current product name throughout this website. Legacy Venafi terminology is retained only where necessary to describe existing customer environments, technical configuration or compatibility.

Legacy operational identifiers such as venafi.cloud may still appear in existing customer environments, configuration values, URLs, APIs, or interface labels. These historical identifiers do not change the current product naming used by AEYRiX.

Important disclaimer

Read this before relying on the above.

Standards note: MIPS supports workflows and controls that can help organizations align with established PKI and machine identity practices. Compliance and cryptographic validation depend on the customer's architecture, policies, configurations, certificate authorities, underlying platforms and validated cryptographic modules.

The information provided on this page is intended to explain how MIPS may support an organization's security and certificate-management practices. It is not legal, regulatory, audit, or compliance advice. Use of MIPS does not by itself guarantee compliance with any standard, regulation, or organizational policy.