Skip to main content
IT Service Status
IT Service Status

IT Project: SSL-PKI Certificate Renewal Automation Process Implementation

Project Status

June 2025: In preparation for the first phase of delivering comprehensive certificate management using AppViewX, the project team is collaborating with cross-functional internal teams and has completed a CyberArk security posture review as well as the initial configuration of AppViewX to accept data imports. It continues work to create user groups and associated roles and resources, as well as setting up and configuring role-based Access Control (RBAC). The project team anticipates launching the first phase of implementation in summer 2025 and is currently establishing a working group with university IT leaders to further develop future phases.

Background

IT staff across Northwestern manage over 1800 Secure Sockets Layer (SSL) and Transport Layer Security (TLS) certificates throughout the University, which are essential for protecting connections with end users accessing various hosted University sites. The current process is manual and involves multiple points of key-person risk. Many of these certificates are managed through Sectigo/InCommon, which plans to shorten the current renewal cycle significantly.

Over the next few years, certificate lifespans will gradually decrease from the current 398 days to a maximum of 47 days on March 15, 2029. This change will increase the manual management workload to potentially unmanageable levels and greatly elevate the risk of errors. Cyberinfrastructure (CI) has worked with IT departments across the University to select, evaluate, implement, and validate an automated solution that improves security and efficiency. AppViewX has been selected as the approved solution.

Benefits to the Northwestern Community

Ensuring the security of hosted and transferred data is a vital responsibility managed by Northwestern University's IT departments for students, faculty, researchers, and staff across various environments. Our current manual process for renewing over 1800 certificates is susceptible to errors due to its repetitive nature. As a result of this project, the certificate renewal process will be automated, which will increase efficiency, reduce the risk of errors caused by improper certificate replacement, and enable engineers and system administrators across the University’s IT departments to reassign time and resources to other priorities.

Goals and Objectives

This project will mitigate the manual work required to renew over 1800 secure certificates throughout the University annually, thereby optimizing service delivery, enhancing security, and increasing efficiency through automated workflows. The project will accomplish the following outcomes:
  • Introduction of automated scan and renewal of SSL certificates within the Northwestern IT community
  • Improved ability to maintain inventory of all active SSL certificates and associated owners
  • Improved ability to maintain inventory of all active SSL certificates and associated owners
  • Provide High Availability (HA) configured environment for Business Continuity
  • Enhanced reporting capabilities
  • Single Singn-On (SSO) Multi-factor authentication (MFA)
  • Enhanced Role-Based Access Control (RBAC)
  • Enhanced reporting capabilities

Approach

The project will be delivered over an eight month period. During the initial phase to launch this new service to the University IT community, the project team will:

  • Provision Hardware
  • Install and Configure the ADC - Cert+ environment
  •  Establish RBAC
  • Onboard pilot group
  • Conduct testing
  • Onboard additional IT departments  and schools

Project Timeline

Project Timeline
Date Description Status
Summer 2025

  • Provision Environment
  • Install and Configure ADC- Cert+ Modules
  • Establish RBAC
  • Establish working group of University-wide technology leaders
  • Go live with the following groups:
    • Cyberinfrastructure, Telecommunications and Network Services
    • Cyberinfrastructure, Platform Services
    • Office of Global Marketing and Communications
In-progress

Fall  2025

  • Identify and onboard Phase II schools and units

Not started

 

Winter 2025
  • Identify and onboard Phase III schools and units
Not started