IT Project: SSL-PKI Certificate Renewal Automation Process Implementation
Project Status
June 2025: In preparation for the first phase of delivering comprehensive certificate management using AppViewX, the project team is collaborating with cross-functional internal teams and has completed a CyberArk security posture review as well as the initial configuration of AppViewX to accept data imports. It continues work to create user groups and associated roles and resources, as well as setting up and configuring role-based Access Control (RBAC). The project team anticipates launching the first phase of implementation in summer 2025 and is currently establishing a working group with university IT leaders to further develop future phases.
Background
IT staff across Northwestern manage over 1800 Secure Sockets Layer (SSL) and Transport Layer Security (TLS) certificates throughout the University, which are essential for protecting connections with end users accessing various hosted University sites. The current process is manual and involves multiple points of key-person risk. Many of these certificates are managed through Sectigo/InCommon, which plans to shorten the current renewal cycle significantly.
Over the next few years, certificate lifespans will gradually decrease from the current 398 days to a maximum of 47 days on March 15, 2029. This change will increase the manual management workload to potentially unmanageable levels and greatly elevate the risk of errors. Cyberinfrastructure (CI) has worked with IT departments across the University to select, evaluate, implement, and validate an automated solution that improves security and efficiency. AppViewX has been selected as the approved solution.
Benefits to the Northwestern Community
Ensuring the security of hosted and transferred data is a vital responsibility managed by Northwestern University's IT departments for students, faculty, researchers, and staff across various environments. Our current manual process for renewing over 1800 certificates is susceptible to errors due to its repetitive nature. As a result of this project, the certificate renewal process will be automated, which will increase efficiency, reduce the risk of errors caused by improper certificate replacement, and enable engineers and system administrators across the University’s IT departments to reassign time and resources to other priorities.
Goals and Objectives
This project will mitigate the manual work required to renew over 1800 secure certificates throughout the University annually, thereby optimizing service delivery, enhancing security, and increasing efficiency through automated workflows. The project will accomplish the following outcomes:- Introduction of automated scan and renewal of SSL certificates within the Northwestern IT community
- Improved ability to maintain inventory of all active SSL certificates and associated owners
- Improved ability to maintain inventory of all active SSL certificates and associated owners
- Provide High Availability (HA) configured environment for Business Continuity
- Enhanced reporting capabilities
-
Single Singn-On (SSO) Multi-factor authentication (MFA)
-
Enhanced Role-Based Access Control (RBAC)
-
Enhanced reporting capabilities
Approach
The project will be delivered over an eight month period. During the initial phase to launch this new service to the University IT community, the project team will:
- Provision Hardware
- Install and Configure the ADC - Cert+ environment
- Establish RBAC
- Onboard pilot group
- Conduct testing
- Onboard additional IT departments and schools
Project Timeline
| Date | Description | Status |
|---|---|---|
|
Summer 2025
|
|
In-progress |
|
Fall 2025 |
|
Not started
|
| Winter 2025 |
|
Not started |