Pending Certificate Request Alerts

Pending certificate request alerts send email notifications to certificate approvers when a certificate request requiring approval (based on CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. policy) is received. Notifications can also be sent to the original requester to indicate that their request is pending approval. Alerts can be customized to include detailed information about the certificate request.

Tip:  Where to find this in the Management Portal:
Alerts → Pending Request
Important:  These alerts are not used to provide email alerts or run event handlers for certificate requests that require approval based on policies configured in Keyfactor Command workflows. Pending request notification for requests handled by Keyfactor Command workflowClosed A workflow is a series of steps necessary to complete a process. In Keyfactor Command, it refers to the workflow builder, which allows you to automate event-driven tasks such as when a certificate is requested, revoked or found in a certificate store. are configured within the workflow (see Add, Copy, or Modify a Workflow Definition).

Pending requests are typically generated from certificate templates configured to require manager approval at the CA level.

The functionality of pending request alerts for certificates requested within Keyfactor Command has largely been replaced by Keyfactor Command workflow (see Workflow), which manages approval processes internally. When using workflow, templates generally should not be configured to require manager approval, as this can result in duplicate approval requirements at both the CA and Keyfactor Command levels.

Pending request alerts are retained for use in the following scenarios:

  • Environments not using Keyfactor Command workflow

  • Environments transitioning from CA-based approval to Keyfactor Command workflow

  • Certificates requested outside of Keyfactor Command using templates that require manager approval

Note:  Pending request alerts are supported only for Microsoft CAs and select CA gateways. This feature is not supported for EJBCA CAs.

Refer to the following table for a complete list of the substitutable special text that can be used to customize alert messages.

Table 19: Substitutable Special Text for Pending Request Alerts

Variable

Name

Description

{apprlink}

Approval Link

Link pointing to the certificate-specific approval page in the Management Portal where the person responsible for approving the request can go to approve or deny the request.

{reqid}

CMS Request Id

The request ID for the certificate as stored in the Keyfactor Command database. This is not the same as the request ID issued by the CA.

{rcn}

Requested Common Name

Common name contained in the certificate request.

{rdn}

Requested Distinguished Name

Distinguished name contained in the certificate request.

{requester}

Requester

The user account that requested the certificate from the CA, in the form DOMAIN\username for Active Directory users.

{requester:mail}

Requester’s Email

Email address retrieved from Active Directory of the user account that requested the certificate from the CA, if present.

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{requester:givenname}

Requester’s First Name

First name retrieved from Active Directory of the user account that requested the certificate from the CA, if present.

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{requester:sn}

Requester’s Last Name

Last name retrieved from Active Directory of the user account that requested the certificate from the CA, if present.

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{requester:displayname}

Requester's Display Name

Display name retrieved from Active Directory of the user account that requested the certificate from the CA, if present.

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{careqid}

Issuing CA / Request ID

A string containing the Issuing CA name and the certificate’s Request ID from the CA.

{san}

Subject Alternative Name

Subject alternative names contained in the certificate request. There are four possible sources for the SANs that appear here:

  • For CSR enrollment, the original SANs included in the CSR.
  • Any SANs added through the Keyfactor Command Management Portal. For CSR enrollment, these take the place of the SANs in the CSR if the ATTRIBUTESUBJECTALTNAME2 option is turned on for the CA. See CSR Enrollment.
  • A SAN matching the CN added automatically during enrollment per the RFC 2818 compliance flag in the enrollment policy or CA configuration. See System-Wide: Policies Tab, Add or Modify an Enrollment Pattern, and Standalone Tab. This value is read only.
  • A SAN matching the CN added automatically by the Keyfactor Command policy module on the CA if the Keyfactor Command RFC 2818 Policy Handler is turned on, if one was not included in the CSR or added manually.

{subdate}

Submission Date

Date the certificate request was submitted.

{template}

Template Name

Name of the certificate template used to create the certificate request.

{templateshortname}

Template Short Name

Short name (often the name with no spaces) of the certificate template used to create the certificate request.

{metadata: Email-Contact}

Email-Contact

Example of a custom metadata field.