Certificate timelines are shrinking – from 365 days to 47 by 2029. This demo shows an extensible FlowAgents framework that automates discovery and renewal across multi-vendor environments, with the audit trail to prove compliance.
Certificate renewal gets complicated quickly because there is rarely one standard process across an infrastructure environment. One system may expose an API. Another may require a Python script. Windows might be better handled through an Ansible playbook. Different teams may also rely on different internal and public certificate authorities.
That fragmentation is manageable when certificates are renewed infrequently. It gets much harder as public TLS certificate lifetimes continue shrinking toward 47 days and rotation becomes a recurring operational process rather than an annual maintenance task.
In this demo, Joksan Flores and Dan Sullivan show how to build certificate lifecycle management as an extensible framework on the Itential Platform.
FlowAgents handle the parts of the process that benefit from reasoning, such as identifying the type of system and selecting the appropriate discovery or renewal tool. Deterministic workflows handle predictable work such as evaluating expiration dates and building the renewal queue. Lifecycle Manager maintains certificate state and history across the process, while Itential Gateway executes scripts, playbooks, workflows, and API-based automation against the underlying infrastructure.
The result is a common operating model for certificate rotation without requiring every system to use the same automation method.
If your team is tracking expiration dates manually, managing different renewal processes across systems, or relying on separate scripts and tools that are difficult to coordinate, this demo shows a different operating model.
You’ll see how to turn those individual automation assets into one governed certificate lifecycle process that can continuously discover, classify, renew, and track certificates while still letting teams use the right tool for each environment.
Itential brings the pieces of certificate lifecycle automation together in one governed platform. FlowAgents can reason across approved tools, deterministic workflows handle repeatable tasks, Lifecycle Manager tracks state, and Itential Gateway executes scripts, playbooks, and API calls against the infrastructure.
That means teams can add new systems, CAs, or renewal methods without rebuilding the entire process.
As certificate lifetimes shrink, renewal becomes continuous operational work instead of an occasional maintenance task. Automating discovery, evaluation, renewal, and lifecycle tracking makes it easier to keep pace without adding more manual effort.
And because each change is tracked over time, the same process that keeps certificates current also creates the audit history needed to show what changed, when, and why.
Joksan Flores • 00:04
Hi, everybody. My name is Joksan Flores. I’m a principal solutions engineer here at Atential, and I am joined by a friend, mentor, and colleague Dan Sullivan. Dan, do you want to introduce yourself?
Dan Sullivan • 00:17
Sure. Hey, everyone. My name is Dan Sullivan. I work as part of the solutions engineering team and actually lead the team here at Itential. And I think I’ve been at this for about five years here at Itential. So really excited to be here today.
Joksan Flores • 00:33
Yeah, awesome. Thanks, Dan, for joining me on this. And today we’re going to be talking about one of these very important topics and ever, every day, more important and is to be ready for audits, right? Always be audit ready. And specifically today, as everybody knows, we have multiple capabilities that allow us to be compliant and ready and perform audits on environments. But today we’re very, very, very focused and specifically on certificate rotation. And we’re going to be using a lot of components from the Atential platform, but we’re definitely leveraging the capability of the new Flow AI portfolio and Flow agents to make this process a lot more extensible and a lot more flexible and handling certificates in a multi-vendor environment.
Joksan Flores • 01:18
I think one of the things, and Dan, can help me chime in on this. We’ve been talking, we talk to a lot of customers. From a variety of verticals, finance, energy, government, service providers. And one thing is very, very, very clear. The timeline for certificate renewal, and in general, right, everything, password rotation, certificates, threat assessment, software upgrades, the timelines have been shrinking. It used to be, and I think modern days still, a lot of people hold to this, is 365 days standard rotation for SSL search for mutual TLS and web certificates and load balances and so forth. Effective 2026, there’s been research that’s saying we have to start pushing the timeline down to 200 days.
Joksan Flores • 02:03
Now, 2027, the recommendation is to go to 100 days. And in 2029, the idea is to go to 47 days. And I have customers that are even pushing the timeline down to 30 days. Dan, I’m sure that you’ve heard plenty of around this topic.
Dan Sullivan • 02:19
Yeah, quite a bit. And I think it’s top of mind with a lot of organizations. As you know, the certificate renewal process is not always a simple one. And there are a lot of different processes that organizations are trying to go through and looking. And they’re all looking at how do we centralize this? How do we get our arms around this so that we can do it really quickly and effectively?
Joksan Flores • 02:50
Yep, 100%, Dan. I agree. I think there’s a lot of people that we talk to that they do it in disparate ways, different teams. Nobody has a common CA and so forth. And we’ll talk about the challenges actually here. So this is the reason why what Dan was kind of pointing and talking towards, right? This is a distributive problem.
Joksan Flores • 03:09
Shorter cycles of certificate means larger scale, right? We know plenty of people that come to us and say we’re doing renewals manually today. And that’s great, right? Sometimes people have, you know, I’ve talked to organizations that have 50 certs to manage, maybe 100 public certs. And if it’s on a yearly rotation basis, then that’s totally fine, right? You can probably get away with doing it manually. But driving the timeline down towards 47 or even 30 days means that now, how do you scale?
Joksan Flores • 03:34
Right? Are you going to have people that are their full-time job is going to be certificate rotation? Dan talked about this, right? The rotation technology or the methodology of doing this is different on every system. Some systems have APIs for uploading certs, for issuing the certificate sign-in requests, for uploading and activating the cert. Some systems require a script. Some systems, you know, use Ansible is better for them.
Joksan Flores • 04:01
And there’s no commonality, right? There doesn’t seem to be any commonality across this. And we have to have an extensible way of solving this problem, but also have a framework around it. We talked about a no-common CA across teams. So having the capability of integrating with multiple CAs is pay a month. I think every company that I talk to has at least two plus CAs, at least, right? The majority of them have an internal CA for anything that’s internal domain, and they may have one or two public CAs, right?
Joksan Flores • 04:30
Venify, GoDaddy, or any of those systems. And we need to be able to integrate with them if we want to do certificate renewal and certificate signing in an automated way. And we talked about a framework, right? We need to have a way of plugging in those scripts and Ansible things that we come up with or any workflows or anything like that. We need to be able to put them in a common place so that we can. execute these renewals in a timely fashion that we can be ready for audits and so forth rather than let every team be up to their own devices. Right.
Joksan Flores • 05:05
Dan, any comments on that?
Dan Sullivan • 05:07
Yeah, I mean, I was talking to a customer recently who basically said that sometimes what’s happening to them is they figure out a certificate needs to be renewed once it expires. And, you know, so they were taking outages basically once their certs expired. Right. And so they were trying to figure out how can they do this at scale? How can they be a little bit more proactive when it comes to this sort of thing?
Joksan Flores • 05:33
Yeah, that actually brings an interesting point, Dan, I think, right? Like sometimes people use internal CAs to sign the certificate between the compute host and the load balancer, but then all the compute hosts happen to be on the same certificate lifecycle, right? Timeline. So if all, you know, if you have six members in a pool and they all expire at once, then you host. Or if you have an internal tool, like I heard a customer the other day, right? I can’t obviously reveal the name, but they had an InfoBlock certificate issue. So they lost access to their InfoBlocks.
Joksan Flores • 06:01
And guess what? Their DNS is broken and a lot of stuff is broken. So yeah, it’s not great when you find out that your certificate was expired by the NOC, right? Instead of knowing about it. Okay, so this is the certificate renewal process as it’s been designed for this webinar, right? There’s been a little bit of work on designing the pieces so that they all plug into each other. And like I said earlier, we’re using a lot of the components of the platform, but the use of Atential Flow Agents and Flow AI is key.
Joksan Flores • 06:35
And then we’re also introducing the use of lifecycle manager to keep state of the life cycle of the life cycle of the certs along the life of the search, right? Obviously, today we don’t have 30 days between the process of renewal and discovery, but we’re going to kind of simulate some of those pieces. But the idea here is that we can show that we can keep the certs model that’s a resource in the Attention platform over the 30, 47, 90-day life cycle of the cert and come back and renew them once they’re closer to expiration. Dan, do you want to talk a little bit about this design?
Dan Sullivan • 07:09
Yeah, a little bit. I actually, and maybe I might push it back on you, but one aspect I think that’s kind of interesting about this particular use case is that we have multiple agents and we’re actually sharing data between them. And that’s kind of where Lifecycle Manager is coming in. It’s effectively a store of agent data. And we have kind of a mix, as you pointed out. We have some deterministic assets, some workflows and things. And we also have some agents.
Dan Sullivan • 07:41
And we’re actually able to share data between the agents, I think, which is pretty unique. Now, obviously, if you don’t have Lifecycle Manager, you might have another solution, whether it’s a database or maybe you can use Git repo or something like that. But since we had Lifecycle Manager as part of the attention platform, we’re leveraging that.
Joksan Flores • 07:59
Yep. And I think, Dan, that’s one of my favorite pieces of this framework, if you will, right? I wouldn’t call it just a demo. I think I would call it an idea of a framework. Obviously, this can be modified by anybody. Like you said, if they don’t want to use LifeCycle Manager, they could use something else. The fact that you can have, and you see the top, this is kind of a split up process where you have an user trigger a certificate discovery, point it to a few hosts.
Joksan Flores • 08:25
Hosts are in the inventory of the platform. We have an agent that discovers the certificate, puts him in LifeCyclone, right? If you look at there in the middle, the agents themselves give us the ability to do things like F5, Linux, and Windows. And we worked in separate pieces of this demo, right? Like you worked on the Linux piece, I worked on the Windows piece, and then we just plugged them in together. And having an agent let us be a lot more flexible with Dan and I don’t have to negotiate data models and schemas and things like that, right? The agents just give us the ability to be super flexible.
Joksan Flores • 08:56
But also, more importantly to me, is that now if somebody comes up with a new piece of this, right? They want to do A10 load bouncers or, you know, Amazon certificate manager, they can plug in their pieces here for discovery and for renewal. And it’s just, you know, it’s going to be all the same, right? All certificates have some common attributes, right? They have a fingerprint, they have an expiration, they have, you know, initiator, they have a domain associated, and you know, some SANS list and stuff like that, right? So model all the common attributes, and then we use independent tooling for doing some of these pieces. So that’s the top.
Dan Sullivan • 09:28
Exactly. Yep.
Joksan Flores • 09:29
So that’s the top piece for discovery. And then Dan, the bottom, There’s a couple of schedules, right? One of them, the dusted reclassification, which is a little tiny demo. You show that piece, right? Which is not depicted here, which essentially says, hey, let’s go and classify the certificates that are, you know, need renewal in less than 90 days, or that’s adjustable, right? And you actually had that where we can now, once we have this model and this whole process has been created, we can actually adjust the renewals cycle and to what we see fit, right?
Joksan Flores • 09:57
We can renew every 30 days. Obviously, you know, customers have to do this in a balanced way because obviously that increases in cost for them and more churn and things like that, more maintenance, but it’s completely automatable. So there’s a schedule that says, hey, go and pull all the certificates that need renewal within 90 days, add them to this group that is called renewals in lifecycle manager. And then in a maintenance way, which of course with a maintenance schedule, which of course we’re going to trigger manually here, the renewal happens in parallel for all those certs that are eligible for renewal, right? And we’re going to use a flow agent that goes and identifies the certificate, the system, and then it picks the tool, the appropriate tool. And that goes back to this extensibility that I was talking about earlier, right? We use scripts, we use workflows, we use Ansible playbooks on this, and people can come and pick their own tool, right?
Joksan Flores • 10:45
If it’s API-heavy, use a workflow. That’s the best tool. If it’s CLI-driven, but it’s not great for Ansible, use a script. If Ansible has all the tooling, like e.g. , for Windows, where Ansible has a lot of useful tools with PowerShell, then use Ansible. So very, very extensible framework. And we’ll show you that in a minute.
Dan Sullivan • 11:03
Yeah, I mean, I think, again, you point out the really important part, which is obviously everyone can do cert renewals. There’s nothing terribly unique about it. But having a sort of infrastructure where you can plug in the disparate types. So if you have some cert process or some cert renewal process based on a specific application you have and it’s different, then you can still plug it in, right?
Joksan Flores • 11:28
Yep. Even if that process might be put a human in, right, Dan, I think we know customers are like, oh, there’s this one tool that I saw worth automating. That’s fine, right? You can still model the human, do it. And then the human comes and approves it in the platform, you know, keeps the track, the state of the certificate. All right. So this is the demo architecture.
Joksan Flores • 11:45
And here’s the platform, right? So obviously, we’re using a lot of the components, Dan, right? I think we’re using Flow AI, right? So Flow Agent Builder. We’re using workflows. We’re using Less Actor Manager. We have the systems that we’re using.
Joksan Flores • 11:56
We’re very focused on compute today here, right? But this could be used for a lot of other systems, right? Management tools, F5, load balancers, CASB systems, we’re using inventory manager to keep track and make sure that, you know, obviously we don’t have to plug in passwords and things like that. It’s all kept within inventory and secret management in our platform. We’re using Gateway Manager for obviously the brokering of the scripts and playbooks and things like that. And then we have agent sessions that are calling things into the systems. We’re using our gateway for all the execution and talking to the end systems.
Joksan Flores • 12:27
Gateway is super important here. And one of the things to call out, right, is we’re using our platform in the cloud, but the gateway itself lives on-prem. So the execution of the renewal logic, whenever we’re doing things like executing scripts or playbooks or executing API calls to on-prem systems, is happening all within the premise, right? Within the customer’s network. And then we have, obviously, we have an LLM for our agents. Any other comments on this, Dan?
Dan Sullivan • 12:55
Yeah, so we’ve got some scripts and we’ve got even some Ansible playbooks. And I think neither one of us are necessarily experts in, you know, Cert rotation using Ansible or Python to begin with. So I think we vibe coded our scripts and our playbooks. So there’s nothing secret in there, I guess, is maybe one statement to make. And I think that’s sort of an interesting part of this whole thing is we didn’t necessarily have to be experts in those to get that stuff together. It wasn’t too complicated.
Joksan Flores • 13:33
That’s a good point, Dan, right? We talked a lot about high code a lot of times, right? Or DIY, right? Like the idea here was like, we’re doing plenty of DIY, right? We’re vibe coding scripts. We just have a place to put them and where to scale away, right? Like we were actually made scripts and playbooks AI tools, right?
Joksan Flores • 13:49
Just like you would plug in an MCP. So for those customers that are looking at AI, right, think about it that way. Like we have scripts as a tool, which I built MCPs manually. It’s quite a bit of work to do that stuff. So just having the ability to just onboard a script to the gateway and now it shows up as a tool in a workflow or in an agent, it’s pretty cool.
Dan Sullivan • 14:10
I was just going to say, we can also make the inventory actionable in those scripts as well, which I think is pretty important. So it makes it pretty easy to get inventory information into your Python, into your Python scripts as well. Ansible is already sort of well understood, but the way the gateway works, you actually can pass inventory directly into. Directly into the Python script to make it actionable. So that’s pretty interesting.
Joksan Flores • 14:37
That’s a good point, Dan. And also, like, the secrets management bits, right? So, obviously, we have this slide here that talks plenty about that, but I think this is important, right? What Dan just said, having the ability to plug in inventory. And this is, you know, again, right? We using the platform and the idea of bringing all these assets together, right? And the idea that I can bring more things as my process evolves, right?
Joksan Flores • 14:57
I can bring, you know, a 2nd version of a Windows renewal playbook, or maybe if I added fives and I was, I want to use the AS3A library, or I want to use something with Bodo3 for AWS or what have you. I can bring in new tooling. And the idea is that you can just plug all this in via the platform, right? So our platform has a lot of the components that you can’t necessarily vibe code, right? I think you can Vivecode your way through the logic of renewing search for Windows, which is what I did with Ansible. I think Vivecoding your way through something like this, where not only do we have the bits to add the playbooks and they show up on the platform automatically, but have the agent governance, right? Being able to evaluate all the sessions, being able to plug in an LLM model and that I can use at will, right?
Joksan Flores • 15:47
We were experimenting as we built some of this, right, with Anthropic models, GPT models, open weight models like Gemma, et cetera. And also, the fact that in the platform itself, right, we’re all logged in using SSO. We have proper RBAC, right? We’re not letting anybody that’s not allowed to access some of these assets and perhaps modify them or run them, right? So we can have control over everything that has been done inside or for the certificate renewal process, right? So that only the admins that are chosen or the people that built or something like that. And then also, Dan, we talked about secrets, right?
Joksan Flores • 16:22
Secrets management is a super important piece of the gateway when it comes to talking to inventory, right? So having the ability to fetch secrets from a secret store during runtime without having to have them exposed in the platform is a big piece as well.
Dan Sullivan • 16:38
Absolutely.
Joksan Flores • 16:41
Okay, so let’s go to demo time. I’m going to stop sharing and Dan’s going to take it over and then let’s see what this looks like.
Dan Sullivan • 16:49
All right, let’s do it. All right. So kind of the split window thing going on here, but let’s get after this. So 1st on the platform side, as we mentioned, we’re using Lifecycle Manager. So we have a model defined. And if we go to see what instances we have plugged in, you’ll see here that there’s nothing here. So obviously we need to discover some certificates.
Dan Sullivan • 17:17
So that’s kind of the 1st part of the demo that Joxon was mentioning, that we’re going to discover some certificates. So over here on the right is operations manager, and that’s kind of the jumping off point where we’re launching all of our automation. So 1st off, what we’re going to do is launch the certificate discovery. So we’ll just run this manually. Now, you’ll notice here we have a schedule. So you can periodically kick this off and discover certs and add them and track them. In our case here, we’ll just run this manually.
Joksan Flores • 17:53
And then, question, quick highlight real quick, right? If I had a pipeline that’s deploying applications, I could also trigger this API, right?
Dan Sullivan • 18:00
Yeah, absolutely. So I’m just going to jump back over here to the dashboard. And you’ll see here that we’ve kicked off a discovery agent that’s running. So we can actually watch what’s happening. You’ll see that it’s fetching some Windows information. So based on the inventory, there’s a Windows host in there. And it’s actually going to go off and fetch that.
Dan Sullivan • 18:25
And it’s doing the certificate discovery now on the Linux hosts. And after this runs, what we should see is the collection of certificates onboarded into LCM that we can then track. And we’ll take some other actions on them in just a few minutes.
Joksan Flores • 18:42
I think it’s pretty cool, Dan, that we have actually so found. This is, again, a highlight again, the most fascinating piece for me is that we have, like it said, the agent right there says on the reasoning, found six hosts, four Linux and two Windows, right? So if we have fives, it’ll let’s say four Windows to Linux, you know, four fives or whatever, right? Like, and then it’s launching multiple tools depending on the OS that it’s using, right?
Dan Sullivan • 19:03
Yeah. So at this point, with any good demo, we have some UI so that people can see what’s going on. So we’re in our work center application. So if I jump to work center, basically what we can see here is that the agent wants to interact with the human. So that’s sort of the human on the loop here. So let’s see what the agent comes up with. So it looks like we’ve discovered a couple of certificates.
Dan Sullivan • 19:33
Some of these are in pretty rough shape. We’ve got a few expiring in a couple of days. So in this case, we’re going to continue and onboard them. So let’s just click on that. If we went back to the agent sessions, we’ll see that. The agent is still running here, and it took our input from the human in the loop task, and it’s continuing on. And so now it’s going to, there’s an onboarding agent that’s basically going to add the certificates into LCM.
Dan Sullivan • 20:06
So if we went back over here to our screen and go to lifecycle manager, we should actually see some of this happening real time. So see here. Okay, the certificate onboarding agent is running now, and it’s going to again add in the instances into lifecycle manager. So I’ll click over here. Let’s see what’s happening. And we’ll see those pop up in just a few minutes. Okay, so now we have their certificates onboarded here.
Dan Sullivan • 20:40
So we’ve got four different certs that we’re tracking and we’ve got those onboarded. And the next thing we want to do is figure out, we want to create sort of a renewal path. So basically, now that we have a lease inside of LCM, we actually have another process in which we will sort of gather which certificates we want to renew. So we can, again, schedule that or we can run it manually. So for the purposes of this, I think we put it up high. Like we’ve got some certs that we want to renew that window serve. It doesn’t expire for a while, but just as part of the demo, we’ll add it and make it look 90 days ahead.
Dan Sullivan • 21:24
So it should gather all the certs and try to renew them.
Joksan Flores • 21:27
And then this is the bid where we say this is our expiry window, right? Like what we were talking about, timeline, right? 365, 200. That’s the number right here. So I was before, right? You can this number, once it’s automated, you can adjust it to whatever you want, right?
Dan Sullivan • 21:43
So, e.g. , these 1st three certs expire in under 10 days. So, if we just put 10 in there, it’d grab three. But since we want to actually exercise the Windows part, we’ll just make it a little bit wider because that’s a valid cert right now. But we’ll just renew it as part of the demo. So now, the other interesting thing is because this This, uh, the gathering of the certificate renewal data, it has to chunk through all the instances in LCM. This is actually a workflow, so we’ve done we did this deterministically because you’re going to run it really often.
Dan Sullivan • 22:13
It’s going to be scheduled. You don’t want to pay tokens for this part. It’s fairly, there’s no real reasoning benefit to letting an agent do it. So, we’ve actually going to just do this manually with a workflow at this point. So, let’s just run this.
Joksan Flores • 22:25
And this is why, Dan, this is why to have the platform that’s like we have the ability to pick and choose which things reason through which things we don’t, right? This is like a fair straightforward process. It’s come out, it’s the same all the time, right?
Dan Sullivan • 22:39
So, yeah. And so, this workflow is run to completion already. So, if I went back to lifecycle manager, we have these instance groups, and anything that we’re going to renew immediately is in this renewal group. So, if I click on the instances here, you’ll see that we have three, we’ve got four certs in here. If I went back to the model itself and the instances, what you’ll notice here is if I click on one of these, I actually have some properties. And so, I’ve got the fingerprint, some of the information regarding the cert. You’ll also see that there’s even, I can add more intermediate, you know, I can add root certificates and anything else that’s needed to actually renew the cert.
Dan Sullivan • 23:25
Some of these are self-signed, so they don’t really need it. We just need the fingerprint, they’re just done on the device. And more importantly, I have kind of this history tab. So, I can actually click on this and you can see, okay, the initial state was empty, and then this is the new state. This is the cert data that we’ve added, and we’re going to track now. And this will become interesting after we do a renewal. We’ll actually can go in and see what’s changed.
Dan Sullivan • 23:49
So I think we’re in good shape.
Joksan Flores • 23:51
I can use this for compliance purposes too, right? Like I should be able to come in here and show my history, access it VI API, or export it into the board, right?
Dan Sullivan • 23:59
Yeah. Yeah, you’ll notice here we’ve just got the discovery scan captured as a as a historical result, but over time, it’ll so once we do the renewal, we’ll see that in the history as well. So that’s pretty useful. So you can see over time what’s happening, what’s not, what. And you can record all that and pretty easy to generate reports based on it.
Joksan Flores • 24:23
You can also prove to everybody that you’ve, you know, you renewed your search every day, right? You’re subject to some compliance like that, right? Some FedRAMP requirements or whatever.
Dan Sullivan • 24:32
Yeah, it’ll be pretty easy to generate a report off of some of this as well if you need to. So let’s get to it here. So if I go back here and now I can just, I’ve got a few other endpoints. One is this launch certificate renewal. And what this is going to do is this is actually going to kick off a process and kick off some agents to actually do the renewal. And we’ll also see those agents run in parallel. But the input to this is basically just whatever is in the instance group.
Dan Sullivan • 25:09
So whatever is populated in the in the whatever certs are populated in the renewal group is the input to this process. So when we launch them, it’s only going to execute on what’s in the renewal group. So if you have 3,000 certs, but you’re only going to renew a few. it’s just going to focus on that so it doesn’t have to scan a ton of data so over time we’ll have that gather certificate renewal run periodically so that it can gather certs and then feed the work into the into the renewal process and so we’ve got so this will be kind of interesting so let’s kick this off and we’ll go in and run the renewal so i’ll jump back here looks like we’ve kicked off the workflow here and this workflow will actually start agents in parallel so if i go back into uh into the if i go back in back to the dashboard and then into the agent sessions um you’ll see here that we’ve got four actual agents running um at one time so they’re spawned off they’re actually running in parallel doing the renewal so if i click into one of those i can look at the session for it um And you can see here, here we have the prompt. It’s basically telling us what to do, telling it how to do it. We’ve got tools onboarded here specifically for the Linux thing that we’re doing and the Windows host.
Dan Sullivan • 26:34
And if you have more specific processes, so maybe you have multiple types of Linux with certain applications on each one and you want to renew a cert or restart an application, you can plug in specific functions that you need. And as long as the agent can delineate between them, and you can do that by marking the inventory or however else you want to do it. But now the agent can delineate and call the appropriate tool for the appropriate device.
Joksan Flores • 27:03
And then one thing that I found super fascinating is if you go back to the prompt up top, is that if you need to add a new system to this, you can just add the discovery bit, right? Which could be a workflow or a script. And then here you just adjust the prompt to say, hey, if you have any specific things for the renewal of, I don’t know, A10 certificates, then you just add a step 3C or what have you, right? It is pretty easy to modify.
Dan Sullivan • 27:28
Yeah, and I think, and the agent is actually restricted. It only has a couple of tools that it can call. So at build time, we actually, within the attention platform, when you build out an agent, you give it access to the tools you want it to have. So it can only call the tools that we give it access to. And it’s got a pretty good, pretty strict prompt here that it’s following. So we can sort of eliminate the worry about hallucination or anything like that. And it looks like in this case, the Windows renewal succeeded on this one.
Dan Sullivan • 28:01
So we’re in pretty good shape. The agent is doing a little bit more reasoning. And we can go and see the other. Oh, in that case, it didn’t renew it, but let’s see here. So we’ve got the other ones running and they should be completing fairly soon. So if we click into this one here, looks like the renewal succeeded. We’ve got a new fingerprint and we’re going to renew it for 40 days.
Dan Sullivan • 28:30
So it looks like we’re pretty good here. And we’ve got one more running. It should be just about done. Go ahead and start it. We’ll see. Okay. Yep.
Dan Sullivan • 28:51
And of course, this renewal is just calling, this is our, this tool is just calling a script for us. It looks like we renew this one as well. And now what we can do is go back to lifecycle manager here. We can take a look at some of these certs. So we have our SSL cert and we have the instances. So here are the Linux ones. If I just click on one of these and look at the properties, look at the history, we can take a look and see exactly what happened here.
Joksan Flores • 29:28
Very cool.
Dan Sullivan • 29:30
So now I can actually see that. See that I’ve actually updated the fingerprint. I changed the status to active. And you’ll see now that I’ve got my extended time stamp. So I know that this list needs to be rotated for a while. So I’m sort of good to go. And I’ve got a little bit of history that’ll also tell me when what, you know, from an audit perspective here, if I expand this here, you can see now that I’ve discovered it and then onboarded it.
Dan Sullivan • 30:14
And then renewed it again down here so that now on the audit trail, we have the renewal that we just did. So that’s pretty good. And I can track this over time.
Joksan Flores • 30:23
And so, Dan, this is like the easy reporting right here, right? So we saw that this guy changed. We can report on this. And then also, I’ve had people like with one webinar before, I think it could be a couple of weeks ago, where, you know, the question is like, can we put a CR creation, right? Can I create a CR? off of this thing at the end when it gets renewed or something for tracking purposes and we could right like could freak yeah absolutely yeah to do that so it’s just yeah the system of record is ServiceNow then that’s fine and it’s also the data is also here um but we’ll see like you know and then the ones that don’t happen for whatever reason right because of no expiration date or what have you you’ll see the audit trail won’t change right like that windows didn’t get renewed i just looked on the in the background it didn’t it didn’t change right the certificate actually the fingerprint didn’t change so it’s too soon to renew it essentially so you can see that if you you know if you look at the windows audit it doesn’t show like hey they just didn’t do it because it’s not it’s not time to renew it yet we’re a victim of testing we already renewed it yeah wait yeah no tested the thing tested the thing a bunch of times so we have to renew um them a bunch of times right but you know but it’s okay right because i think i’m fairly happy with that outcome because i’m just looking to the background it says hey It didn’t need to renew, so it didn’t renew.
Joksan Flores • 31:36
And if you look at an LCM back, the Windows instance has no changes, right? It just stayed the same. So that means that we’ll just try again next time, right? Whenever it’s possible.
Dan Sullivan • 31:45
Yeah, so you can see that historically, it didn’t update it. So it’s the same, right? We didn’t get the, we didn’t, the, it decided it shouldn’t update it, so it didn’t, so the state is the same. So over time, uh, when it’s time to renew it, it’ll actually happen and we’ll have the data to back it up.
Joksan Flores • 32:05
Awesome. This is really cool. I like the fact that it’s very extensible, that it looks like I can just add tools, change the prompt a little bit, and then that’s it. The model is still anchored around, or the modeling of the instances is still anchored LCM, but there’s no dependencies on changing the logic of lifecycle manager or anything like that just to make this happen. I can just plug in tools as I go.
Dan Sullivan • 32:29
Yeah, exactly. And later on, and like I said, the model is sufficient enough that we can onboard different types of CAs and everything should work just as it’s supposed to. So, yeah.
Joksan Flores • 32:43
Awesome. Pretty cool. Well, Dan, I think does that do it? I think.
Dan Sullivan • 32:47
Yeah, that’s it for me.
Joksan Flores • 32:49
Yeah. All right. I think that covers it. Hopefully, this is useful for everybody. The whole idea, again, is to remain audit ready. And for me, the big takeaway is the fact that you can build this in a way that is extensible. You can add new tools to it.
Joksan Flores • 33:02
And also the expiration date, right? The expiry notification or the rotation cycle rather becomes now just a variable in the process, right? I can adjust it from 90 to 20 to what have you. And at that point, I just have to make a decision and say, hey, do I want to pay for the 30-day renewal or do I want to just keep complying to my 90 days? But the whole process is commoditized by something like this. Now, this is a framework, Dan, right? It’s not a point solution.
Joksan Flores • 33:27
I don’t think anybody, you know, anybody that can tell you, hey, I can have a point solution to renew certs. I don’t know that that’s entirely like there’s one tool out there that will do it all, but this is a framework. And the idea is that you can put a bunch of customized solutions if that’s what you need to do to accomplish that.
Dan Sullivan • 33:43
Yeah, if you and I think a lot of the customers that we talk to have non-standard processes and things like that that are unique for some of the applications that they’re caring for. And they still need to renew the certs, but it’s not sort of a one-size-fits-all. And that’s where I think having a framework like this where you can plug in and have disparate solutions and still actually orchestrate the entire thing, have the data to back up from an auditing perspective. You know, we have some fairly limited integrations that we showed, but obviously, you know, if you want to add in capabilities to push data to ServiceNow, if you’re keeping updated stuff about certificates in your CMDB and you want to push it, that’s fine. We can add, you know, we’ve got integrations with ServiceNow. And I think the other interesting thing here is that we had kind of a mix of agentic and deterministic processes that we did, right? So things that are running all the time that don’t really benefit from the agentic solutions, we have those as workflows.
Dan Sullivan • 34:50
So you have the ability to sort of turn the knob. And maybe over time, some of what we’re doing with agents, you might decide, hey, this is pretty rudimentary. I think I can just use the workflow for this and I don’t need to spend the tokens. You have that ability as well.
Joksan Flores • 35:03
Yeah. And you can mix and match too, right? So this is, yeah, this is perfect. Thanks, Dan, for hosting this with me. I think this is pretty awesome. It’s very exciting. Complicated process, obviously, for everybody, but something that has to be done and is becoming more and more troublesome for people.
Joksan Flores • 35:21
Thanks everybody for tuning in, and we’ll see you on the next one.