Issued Certificate Request Alerts

Issued certificate request alerts send email notifications when a certificate request has been approved and the certificate has been issued. Notifications can be sent to the original requester and/or other relevant parties, and can be customized to include detailed certificate information.

Tip:  Where to find this in the Management Portal:
Alerts → Issued Request

The issued alert handler runs immediately when an enrollmentClosed Certificate enrollment refers to the process by which a user requests a digital certificate. The user must submit the request to a certificate authority (CA). is approved within the Keyfactor Command platform and also runs via a schedule to pick up any approvals done outside of Keyfactor Command. Issued alerts use the pending certificate request alerts schedule for any jobs that run on a schedule (see Configuring a Pending Request Alert Schedule). Certificate requests approved externally must first be synchronized into Keyfactor Command using a CAClosed A certificate authority (CA) is an entity that issues digital certificates. Within Keyfactor Command, a CA may be a Microsoft CA or a Keyfactor gateway to a cloud-based or remote CA. synchronization job before they will be picked up by a scheduled issued alert job.

Note:  Issued certificate request alerts are triggered both immediately and on a schedule. Alerts run immediately when a certificate is approved within Keyfactor Command and also run on a schedule to capture certificates approved outside of Keyfactor Command (for example, directly at the CA).

Because scheduled alerts process previously approved requests that have been synchronized into Keyfactor Commandv (specifically those that required CA manager approval), configuring issued alerts after initial CA synchronization is recommended. This helps prevent a large volume of alert emails from being generated for existing approved requests.

Refer to the following table for a complete list of the substitutable special text that can be used to customize alert messages.

Table 20: Substitutable Special Text for Issued Certificate Alerts

Variable

Name

Description

{dnldlink}

Download Link

Link pointing to the Certificate Requests page in the Keyfactor Command Management Portal where the certificate requester or the person responsible for installing the certificate can go to download the certificate. The certificate will be available only in a PEM format without the private key unless private key retention has been turned on for the template (see Certificate Templates).

{certemail}

Email Address in Certificate

Email address contained in the certificate, if present

{cn}

Common Name

Common name contained in the certificate

{dn}

Distinguished Name

Distinguished name contained in the certificate

{certnotbefore}

Issue Date

Validity date of the certificate

{certnotafter}

Expiration Date

Expiration date of the certificate

{issuerDN}

Issuer DN

Distinguished name of the certificate’s issuer

{principal:mail}

Principal’s Email

Email address retrieved from Active Directory of the user whose UPN is contained in the SAN field of the certificate, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{principal:givenname}

Principal’s First Name

First name retrieved from Active Directory of the user whose UPN is contained in the SAN field of the certificate, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{principal:sn}

Principal’s Last Name

Last name retrieved from Active Directory of the user whose UPN is contained in the SAN field of the certificate, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{principal:displayname}

Principal’s Display Name

Display name retrieved from Active Directory of the user whose UPN is contained in the SAN field of the certificate, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{requester}

Requester

The user account that requested the certificate from the CA, in the form DOMAIN\username for Active Directory users.

{requester:mail}

Requester’s Email

Email address retrieved from Active Directory of the user account that requested the certificate from the CA, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{requester:givenname}

Requester’s First Name

First name retrieved from Active Directory of the user account that requested the certificate from the CA, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{requester:sn}

Requester’s Last Name

Last name retrieved from Active Directory of the user account that requested the certificate from the CA, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{requester:displayname}

Requester’s Display Name

Display name retrieved from Active Directory of the user account that requested the certificate from the CA, if present

Note:  This substitutable special text token appears in the dropdown only in environments that use Active Directory as the identity provider.

{careqid}

Issuing CA / Request ID

A string containing the Issuing CA name and the certificate’s Request ID from the CA

{serial}

Serial Number

The serial number of the certificate

{san}

Subject Alternative Name

Subject alternative names contained in the certificate

{template}

Template Name

Name of the certificate template used to create the certificate

{templateshortname}

Template Short Name

Short name (often the name with no spaces) of the certificate template used to create the certificate request

{thumbprint}

Thumbprint

The thumbprint (hash) of the certificate

{metadata:Email-Contact}

Email-Contact

Example of a custom metadata field

Tip:  Click the help icon () next to the Issued Certificate Request Alerts page title to open the Keyfactor Software & Documentation Portal to this section. You will receive a prompt indicating:

You are being redirected to an external website ‘software.keyfactor.com'. Would you like to proceed?

You can also find Help in the NavigatorClosed The Navigator is the Keyfactor Command left-hand (newer versions) or top (older versions) navigation menu. Certificate collections and reports can be configured to be added to the menu using user-defined Show in Navigator settings.. From here you can choose to open either the Keyfactor Software & Documentation Portal at the home page or the Keyfactor API Endpoint Utility.

Keyfactor provides two sets of documentation: the On-Premises Documentation Suite and the Managed Services Documentation Suite. Which documentation set is accessed is determined by the Application Settings: On-Prem Documentation setting (see Application Settings: Console Tab).