About mTLS
What is mTLS?
Mutual TLS or mTLS for short is a secure way for two services to communicate across the internet. This method of authentication verifies that both parties have the appropriate private keys as well as certificates in place before establishing a trusted connection. Test Generator and Cloud Runner use mTLS to certify that a secure connection is formed between the ServiceNow infrastructure and the instance.
Why do I need mTLS?
To provide a high level of security and to prevent any malicious activity, Test Generator and Cloud Runner both require mTLS enablement.
What happens when I enable mTLS?
Enabling mTLS on an instance restarts the nodes of each of the instances. The instance won’t experience any downtime during this event. Upon enablement, ServiceNow automatically creates a support ticket which can be tracked in your support portal.
How do I check to see if mTLS is enabled?
To check if mTLS is enabled for your instance(s) access https:///adcv2/supports_tls. A return value of "true" means the instance is configured for mTLS. If it returns false, check with your support engineer to request that ADC-to-APP mTLS is enabled for your instance(s).
How do I enable mTLS?
Upon installation of the ATF Test Generator and Cloud Runner store application, we will attempt to automatically enable mTLS for your instance. If mTLS is not enabled within 24 hours, please create a support ticket.
Potential risks with enabling MTLS
Enabling mTLS can sometimes break integrations. If an integration were to break, the following mitigation plans can be implemented :
- Mitigation 1: Get the CA (certificate authority) root certificate for the broken service and upload it to the sys_ca_certificate table. Ex. Slack
- Mitigation 2: Go to sys_ca_certificate and delete the one record that ATF Cloud Runner inserts (ServiceNow Root CA Certificate). This will turn off mTLS to the load balancer within 15-20 minutes. This will disable/render the ATF Cloud Runner unusable.
Installation Exits
Customizations to the sys_installation_exit table (specifically the record with name Login, or records that extend Login) can prevent the ATF Cloud Runner from logging in to the instance. If you have modified your installation exits, verify that your installation exit still has the following code:
else if (SNC.AuthenticationHelper.isMutualAuth()) { var userLoginName = user.authenticateMutualAuthToken(); if (userLoginName != null) { return user.getUser(userLoginName); } }