What is a one sentence summary of your feature request?
Add Cert Publisher/Subject variable for custom message
Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.
Include the Cert Publisher/Subject in the variable for the custom SecureRun message. This information is available in both the Event Viewer and the Operational.log. But I’ve been unable to find a variable that matches for the custom SecureRun message. This adds considerable time to resolving simple problems for executables that have already been cleared but have had a cert change in the interim. It would also speed up new clearance requests since nearly all of our LPM clearances are based on Cert Subject.
How do you currently solve the challenges you have by not having this feature?
One of the following:
I download the file and check the cert
Help Desk gets the file from the user so I can check the cert
I wait until the Event from the user gets forwarded to our Event Viewer collector
All of these are either intrusive or time-wasters. Adding a variable in the SecureRun message would streamline our operations, reduce user frustration, and add value to PolicyPak.
Upload any supporting images that you think should be considered in this idea.
Holly — thanks for pointing this out. It looks like you’re right. The variable displayed in DN format is not currently included in the list (which we should address and fix). However, it is supported by the CSE and can be added manually.
If DN is what you’re looking for, you can manually use %PROCESS_EXECUTABLE_CERTIFICATE_SUBJECT%. It should behave as expected. See the example below: