Denied Certificate Request Alerts

Denied certificate request alerts send email notifications when a certificate request that required approval is denied in Keyfactor Command. Notifications can be sent to the original requester and/or other relevant parties, and can include details about the request as well as comments from the administrator explaining why the request was denied.

Unlike pending certificate request alerts, which are sent on a configurable schedule, denied certificate request alerts are sent immediately when the request is denied.

Tip:  Where to find this in the Management Portal:
Alerts → Denied Request
Important:  These alerts are not used to provide email alerts or run event handlers for certificate requests that require approval based on policies configured in Keyfactor Command workflows. Denial notification for requests handled by Keyfactor Command workflowClosed A workflow is a series of steps necessary to complete a process. In Keyfactor Command, it refers to the workflow builder, which allows you to automate event-driven tasks such as when a certificate is requested, revoked or found in a certificate store. are configured within the workflow (see Add, Copy, or Modify a Workflow Definition).

Refer to the following table for a complete list of the substitutable special text that can be used to customize alert messages.

Table 21: Substitutable Special Text for Denied Certificate Request Alerts

Variable

Name

Description

{cmnt}

Denial Comments

Comments provided by the administrator responsible for approving or denying the certificate request at the time the request was denied

{rcn}

Requested Common Name

Common name contained in the certificate request

{rdn}

Requested Distinguished Name

Distinguished name contained in the certificate request

{requester:mail}

Requester’s Email

Email address retrieved from Active Directory of the user account that requested the certificate from the CA, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{requester:givenname}

Requester’s First Name

First name retrieved from Active Directory of the user account that requested the certificate from the CA, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{requester:sn}

Requester’s Last Name

Last name retrieved from Active Directory of the user account that requested the certificate from the CA, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{requester:displayname}

Requester's Display Name

Display name retrieved from Active Directory of the user account that requested the certificate from the CA, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{careqid}

Issuing CA / Request ID

A string containing the Issuing CA name and the certificate’s Request ID from the CA

{san}

Subject Alternative Name

Subject alternative names contained in the certificate request

{subdate}

Submission Date

Date the certificate request was submitted

{template}

Template Name

Name of the certificate template used to create the certificate request

{templateshortname}

Template Short Name

Short name (often the name with no spaces) of the certificate template used to create the certificate request

{metadata:Email-Contact}

Email-Contact

Example of a custom metadata field

Tip:  Click the help icon () next to the Denied Certificate Request Alerts page title to open the Keyfactor Software & Documentation Portal to this section. You will receive a prompt indicating:

You are being redirected to an external website ‘software.keyfactor.com'. Would you like to proceed?

You can also find Help in the NavigatorClosed The Navigator is the Keyfactor Command left-hand (newer versions) or top (older versions) navigation menu. Certificate collections and reports can be configured to be added to the menu using user-defined Show in Navigator settings.. From here you can choose to open either the Keyfactor Software & Documentation Portal at the home page or the Keyfactor API Endpoint Utility.

Keyfactor provides two sets of documentation: the On-Premises Documentation Suite and the Managed Services Documentation Suite. Which documentation set is accessed is determined by the Application Settings: On-Prem Documentation setting (see Application Settings: Console Tab).