IdExchange 1.9.1

Alerting CMS Users of Expiring Certificates

Setting Up Automated Certificate Renewal Alerts

Purpose: Configure IDMS to automatically detect expiring certificates via CMS and send email renewal alerts to affected users.

Prerequisites

  • Administrative access to the IDMS system

  • Access to the CMS source connected to IDMS

  • Knowledge of the current CMS policy assignments (if policy changes may be required)

  • At least one test user with an expiring certificate available for validation


Steps to Take for Alerting CMS Users of Expiring Certificates

Item

Procedure

Reference

Step 1

Obtain the Latest CMS Data

In IDMS, generate the Total Active Credential Report to generate a fresh report of all users and their certificate statuses.

Expected result: IDMS produces a complete report listing all users and their associated certificates.

CMS Total Active Credentials (TAC) Report

Step 2

Configure Renewal Settings and Review Certificates Approaching Expiration

  1. From the report, identify the certificates that are approaching their expiration dates.

  2. Review the summary of users who will receive renewal notification alerts.

Expected result: You have a clear list of users who will be notified.

Certificate Expiration Alerts

Step 3

Update the CMS Policy (if required)
Note: This step is only required if a device holder needs to be assigned a different policy during the renewal process. If no policy changes are needed, skip to Step 4.

  1. Navigate to the policy mapping configuration.

  2. Update the mapping so the new policy is specified in the application update request for the affected user(s).

Expected result: The updated policy is saved and will be applied during the renewal process.


Specifying a Different CMS Policy for the Credential Renewal

Step 4

Run a Single-User Test

  1. Select one user from the expiration list and trigger a test notification to that user.

  2. Verify that the user receives the renewal alert email and that the email content and certificate details are correct.

Expected result: The test user receives a properly formatted renewal alert with accurate certificate information.

Performing a Test of the Renewal Automation Alert

Step 5

Configure and Start the Renewal Job

In IDMS, configure a scheduled job that will query the CMS report for expiring certificates and send email alerts to all affected users.

Expected result: The job is created and scheduled to run.

Certificate Expiration Alerts

Step 6

Monitor the Job

While the job is running, navigate to Scheduling, then Job Information to check the real-time status of the job.

Expected result: The job status shows as running or completed without errors.


Step 7

Review the Results

  1. After the job completes, navigate to Jobs, then Batch Processing.

  2. Locate the completed job and review its details, paying attention to any errors or failed notifications.

Expected result: All targeted users have been successfully notified, and no errors are listed.




Completion Checklist

  • CMS data is current and the expiration report has been generated

  • Affected users have been identified

  • CMS policy mappings are correct (if changes were needed)

  • Single-user test completed successfully

  • Scheduled job ran and completed without errors

  • Batch processing results reviewed and confirmed


2022-07-29_09-22-55.png