---
title: Optional SSL Configuration
slug: neurons-for-itsm/on-premises-help/enu/2025/optional-ssl-configuration
docTags: 
createdAt: 2026-07-29T16:36:06.730Z
---

:::hint{type="info"}
The Metrics Server is not compatible with SSL if your Neurons for ITSM system has Windows authentication set up.
:::

You can configure Neurons for ITSM for SSL. This configuration is optional. There are three scenarios:

- The Neurons for ITSM application database and the configuration database both use SSL. See [Configuring SSL for the Configuration and Application Databases](docId\:veEanrDKk9vZWs5IM_CEC).
- The Neurons for ITSM application database uses SSL but the configuration database does not use SSL. See [Configuring SSL for the Application Database Only](docId\:veEanrDKk9vZWs5IM_CEC).
- Neither the Neurons for ITSM application database nor the configuration database uses SSL. In this scenario, do not check SSL on any of the pages of the System Configuration Wizard.

:::hint{type="info"}
For all fields in the System Configuration Wizard that ask for a server location, when using SSL, you must enter a fully-qualified domain name (FQDN). This is because SSL needs a certificate and the certificate authority requires an FQDN.
:::

## Configuring SSL for the Configuration and Application Databases

To configure both your Neurons for ITSM application database and the configuration database to use SSL, follow all of the steps in all of these sections:

- [Before You Begin](docId\:veEanrDKk9vZWs5IM_CEC)
- [Configuring SSL in Microsoft IIS Manager](docId\:veEanrDKk9vZWs5IM_CEC)
- [Configuring SSL in the System Configuration Wizard](docId\:veEanrDKk9vZWs5IM_CEC)

### Before You Begin

- Ensure that https:\\\localhost:443 displays the Microsoft IIS Manager welcome page.
- Ensure that your system has a valid certificate.

### Configuring SSL in Microsoft IIS Manager

1. In Microsoft IIS Manager, navigate to Sites > Default Web Site and select SSL Settings.
2. On the **SSL Settings** page, check Require SSL and under client certificates, select Ignore.
3. Navigate to Sites > HEAT and select SSL Settings.
4. On the **SSL Settings** page, check Require SSL and under client certificates, select Ignore.
5. Navigate to Sites > CentralConfig and select SSL Settings.
6. On the **SSL Settings** page, check Require SSL and under client certificates, select Ignore.
7. Navigate to Sites > FRSSurveyProxy and select SSL Settings.  
8. On the **SSL Settings** page, check Require SSL and under client certificates, select Ignore.
9. Add an SSL port by doing the following:

:::Paragraph{indent="1"}
a. Navigate to **Sites > Default Web Site**, right click, and select Edit Bindings....
:::

:::Paragraph{indent="1"}
b. Click Add....
:::

:::Paragraph{indent="1"}
c. In the **Add Site Binding** dialog box, for the **Type** field, select HTTPS and in the **SSL certificate** field, select the certificate that you received from the certificate authority. The system automatically enters 443 for the port.
:::

:::Paragraph{indent="1"}
d. In the **IP Address** field, enter a fully-qualified domain name.
:::

:::Paragraph{indent="1"}
e. Click OK.
:::

10. Verify that you can access https\://*fully\_qualified\_domain\_name*.

### Configuring SSL in the System Configuration Wizard

1. In the System Configuration Wizard, on th&#x65;**&#x20;Configuration Application** page, ensure that the value in the **Configuration Server Domain Name** field uses a fully-qualified domain name. Do not use a machine name.

:::Paragraph{indent="1"}
*Configuration Application Page*
:::

::Image[]{src="https://api.archbee.com/api/optimize/parib0MC3hVoUNdfQdnac/kKuTJG3F2DMrpg0-UK-LI_configserverssl.png" position="flex-start" size="80" indent="1" width="865" height="640" initialPath="../Resources/Images/ConfigServerSSL.png" githubPath="ITSM-On-Prem-Help/Content/Resources/Images/ConfigServerSSL.png" showCaption="false"}

2. On the bottom of the Neurons for ITS&#x4D;**&#x20;Application** page, ensure that you check Use domain name to access Application and enter a fully-qualified domain name for the Neurons for ITSM application server.  Do not use a machine name.

:::Paragraph{indent="1"}
Neurons for ITS&#x4D;*&#x20;Application Page*
:::

::Image[]{src="https://api.archbee.com/api/optimize/parib0MC3hVoUNdfQdnac/eE7qp6FZxsUdaWYyutkjU_configureapplicationsettings2.png" position="flex-start" size="80" indent="1" width="1371" height="949" initialPath="Install_Deploy_Images/configure_application_settings2.png" githubPath="ITSM-On-Prem-Help/Content/Install_Deploy_guide/Install_Deploy_Images/configure_application_settings2.png" showCaption="false"}

3. On the **Application Server Settings** page, do the following:
   - Ensure that you enter the fully-qualified domain name in the **Configuration Server Location** field.
   - Check Use SSL.
   - Enter the fully-qualified domain name in the **Host Name** field.

:::Paragraph{indent="1"}
*Application Server Settings Page.*
:::

::Image[]{src="https://api.archbee.com/api/optimize/parib0MC3hVoUNdfQdnac/XInv--7yApIHQpc5vEu4i_applicationserversettings2.png" position="flex-start" size="80" indent="1" width="1376" height="948" initialPath="Install_Deploy_Images/application_server_settings2.png" githubPath="ITSM-On-Prem-Help/Content/Install_Deploy_guide/Install_Deploy_Images/application_server_settings2.png" showCaption="false"}

4. On the **Other Feature Settings** page, for the Neurons for ITSM application server, check Use SSL.

:::Paragraph{indent="1"}
*Other Feature Settings Page*
:::

::Image[]{src="https://api.archbee.com/api/optimize/parib0MC3hVoUNdfQdnac/r9kQ3yzWW5jqTCxw7XQ6e_otherfeaturesettings2.png" position="flex-start" size="80" indent="1" width="1376" height="946" initialPath="Install_Deploy_Images/other_feature_settings2.png" githubPath="ITSM-On-Prem-Help/Content/Install_Deploy_guide/Install_Deploy_Images/other_feature_settings2.png" showCaption="false"}

5. On the **Metrics Server&#x20;**&#x70;age, check Use SSL.

:::Paragraph{indent="1"}
*Metrics Server Page*
:::

::Image[]{src="https://api.archbee.com/api/optimize/parib0MC3hVoUNdfQdnac/CdElNWK-qzDe7N_C85arm_metrics-ssl.png" position="flex-start" size="80" indent="1" width="865" height="640" initialPath="Install_Deploy_Images/Metrics-SSL.png" githubPath="ITSM-On-Prem-Help/Content/Install_Deploy_guide/Install_Deploy_Images/Metrics-SSL.png" showCaption="false"}

### Configuring SSL for the Application Database Only

To configure your Neurons for ITSM application database to use SSL but not the configuration database, follow all of the steps in all three sections:

- [Before You Begin](docId\:veEanrDKk9vZWs5IM_CEC)
- [Configuring SSL in Microsoft IIS Manager](docId\:veEanrDKk9vZWs5IM_CEC)
- [Configuring SSL in the System Configuration Wizard](docId\:veEanrDKk9vZWs5IM_CEC)

### Before You Begin

- Ensure that https:\\\localhost:443 displays the Microsoft IIS Manager welcome page.
- Ensure that your system has a valid certificate.

### Configuring SSL in Microsoft IIS Manager

1. In Microsoft IIS Manager, navigate to Sites > Default Web Site and select SSL Settings
2. On the **SSL Settings** page, ensure that Require SSL is not checked. Under client certificates, select Ignore.
3. Navigate to Sites > HEAT and select SSL Settings.
4. On the **SSL Settings** page, check Require SSL and under client certificates, select Ignore.
5. Navigate to Sites > CentralConfig and select SSL Settings.
6. On the **SSL Settings** page, ensure that Require SSL is not checked. Under client certificates, select Ignore.
7. Navigate to Sites > FRSSurveyProxy and select SSL Settings.
8. On the **SSL Settings** page, check Require SSL and under client certificates, select Ignore.
9. Add an **SSL** port by doing the following:

:::Paragraph{indent="1"}
a. Navigate to **Sites > Default Web Site**, right click, and select Edit Bindings....
:::

:::Paragraph{indent="1"}
b. Click Add....
:::

:::Paragraph{indent="1"}
c. In the **Add Site Binding** dialog box, for the **Type** field, select HTTPS and in the **SSL certificate** field, select the certificate that you received from the certificate authority. The system automatically enters 443 for the port.
:::

:::Paragraph{indent="1"}
d. In the SSL certificate field, enter a fully-qualified domain name.
:::

:::Paragraph{indent="1"}
e. Click OK.
:::

10. Double-click **Configuration Editor**.

:::Paragraph{indent="1"}
The **Configuration Editor** dialog box opens.
:::

::Image[]{src="https://api.archbee.com/api/optimize/parib0MC3hVoUNdfQdnac/6nh90TmoJjNiTBWH_1tjj_configuration-editor.png" position="flex-start" size="80" indent="1" width="972" height="628" initialPath="../ConfigDB_Guide/Config_Images/Configuration-Editor.png" githubPath="ITSM-On-Prem-Help/Content/ConfigDB_Guide/Config_Images/Configuration-Editor.png" showCaption="false"}

11. Select **System.webServer** and then select **serverRuntime**.
12. Modify the **uploadReadAheadSize** value to `2147483647`.
13. Click **Apply**.
14. Verify if you can access https\://*local\_host*.

### Configuring SSL in the System Configuration Wizard

1. In the System Configuration Wizard, on the Neurons for ITS&#x4D;**&#x20;Application** page, ensure that the Neurons for ITSM application database uses a fully-qualified domain name and not a machine name.

:::Paragraph{indent="1"}
Neurons for ITS&#x4D;*&#x20;Application Page*
:::

::Image[]{src="https://api.archbee.com/api/optimize/parib0MC3hVoUNdfQdnac/KEC_MZQkjyv3rQkrRzhQV_servicemanagerapplication.png" position="flex-start" size="80" indent="1" width="1371" height="949" initialPath="Install_Deploy_Images/service_manager_application.png" githubPath="ITSM-On-Prem-Help/Content/Install_Deploy_guide/Install_Deploy_Images/service_manager_application.png" showCaption="false"}

2. On the **Application Server Settings** page, do the following:
   - Ensure that Use SSL is not checked.
   - Ensure that you enter the fully-qualified domain name in the **Configuration Server Location** field.
   - Ensure that you enter the host name, and not the fully-qualified domain name, in the **Host Name** field.

:::Paragraph{indent="2"}
*Application Server Settings Page*
:::

::Image[]{src="https://api.archbee.com/api/optimize/parib0MC3hVoUNdfQdnac/XInv--7yApIHQpc5vEu4i_applicationserversettings2.png" position="flex-start" size="80" indent="2" width="1376" height="948" initialPath="Install_Deploy_Images/application_server_settings2.png" githubPath="ITSM-On-Prem-Help/Content/Install_Deploy_guide/Install_Deploy_Images/application_server_settings2.png" showCaption="false"}

3. On the **Other Feature Settings** page, check Use SSL.

:::hint{type="info" indent="1"}
This is the *only* place in the System Configuration Wizard where you check Use SSL. Do *not* check Use SSL on any other page.
:::

:::Paragraph{indent="1"}
*Other Feature Settings Page*
:::

::Image[]{src="https://api.archbee.com/api/optimize/parib0MC3hVoUNdfQdnac/r9kQ3yzWW5jqTCxw7XQ6e_otherfeaturesettings2.png" position="flex-start" size="80" indent="1" width="1376" height="946" initialPath="Install_Deploy_Images/other_feature_settings2.png" githubPath="ITSM-On-Prem-Help/Content/Install_Deploy_guide/Install_Deploy_Images/other_feature_settings2.png" showCaption="false"}

## Configuring SSL for Integration Service

:::Paragraph{indent="1"}
Ivanti Integration Service by default configured to work on non-SSL port irrespective of the “SSL” check box is selected in System Config Wizard (SCW).
:::

:::Paragraph{indent="1"}
\<That SCW checkbox tells other parts of the product that the integration service is SSL (or not), so it needs to be checked, and the manual edit of the JSON file is also needed.>
:::

:::Paragraph{listStyleType="decimal" indent="2"}
To make Integration Service work on SSL port, following steps to be performed on each server where Ivanti Integration Service is running.
:::

:::Paragraph{listStyleType="decimal" listStart="2" listRestartPolite="2" indent="2"}
Stop the Ivanti integration service.
:::

:::Paragraph{listStyleType="decimal" listStart="3" listRestartPolite="3" indent="2"}
Add the following entries at the end of appsettings.json of Integration Service.
:::

:::Paragraph{indent="2"}
The Default Path for Integration Service is “C:\Program Files\HEAT Software\HEAT\IntegrationServer\appsettings.json”
:::

:::CodeblockTabs{indent="2"}
```bash
"Kestrel": { 
   "Endpoints": {
    "HttpsInlineCertFile": {
       "Url": "https://<IntegrationURL>:1213",
             "Certificate": {
          "Subject": "<SystemCertificate>",
          "Location": "LocalMachine",
          "AllowInvalid": true
        } 
       } 
      } 
     }
```
:::

:::hint{type="info" indent="1"}
Th&#x65;**&#x20;IntegrationURL** should be replaced with the actual integration URL configured in SCW.
And a trusted certificate is available in your local Computer > Personal certificate store.\<Ensure the value in the **appsettingss.json** file is the "Issued To" string.>
:::

:::Paragraph{indent="1"}
Ivanti recommends that there is only one If there is more than one cert here with the same Name, the OS will choose one so it is best practice to ensure only one cert is present with the same name as configured in the json file
:::

:::hint{type="info" indent="1"}
**SystemCertificate&#x20;**&#x73;hould be replaced with the installed certificate name on server machine where the Integration Service is running.
:::

:::Paragraph{listStyleType="decimal" listStart="4" listRestartPolite="4" indent="2"}
Start the Integration Service.
:::

:::Paragraph{listStyleType="decimal" listStart="5" listRestartPolite="5" indent="2"}
Verify that https\://\<IntegrationURL>:1213/IntegrationService.svc is the correct URL.
:::

:::Paragraph{listStyleType="decimal" listStart="6" listRestartPolite="6" indent="2"}
Open the Web.Config of HEAT application located in “C:\Program Files\HEAT Software\HEAT\AppServer” and update the IntegrationURL with right value for the following binding.
:::

:::Paragraph{indent="2"}
\<endpoint address="https\://\< IntegrationURL >:1214/IntegrationService.svc"
:::

:::Paragraph{indent="2"}
binding="wsHttpBinding" bindingConfiguration="wsLargeDataBinding"
:::

:::Paragraph{indent="2"}
contract="IntegrationService.IIntegrationService" name="IntegrationServiceEndpoint">
:::

:::Paragraph{listStyleType="decimal" listStart="7" listRestartPolite="7" indent="2"}
Open the appsettings.json of HEAT application located in “C:\Program Files\HEAT Software\HEAT\AppServer” and update the IntegrationURL with the right value for the following binding:
:::

:::Paragraph{indent="2"}
"IntegrationServiceUri": https\://\< IntegrationURL >:1214
:::

8. Reset the IIS.
