You are here:
Manage Contact Center Certificates
Salesforce uses certificates to help ensure the security of your Service Cloud Voice contact center. If your certificate is about to expire, we let you know by email so you can replace it with a new certificate. Service Cloud Voice supports certificates with up to 4,096-bit keys.
Required Editions
This article applies to:
- Service Cloud Voice with Amazon Connect
- Service Cloud Voice with Partner Telephony from Amazon Connect
| View supported editions. |
| User Permissions Needed | |
|---|---|
| To create, edit, and manage certificates | Customize Application |
To see how to manage contact center certificates for Service Cloud Voice, watch the video.
When you create a Voice contact center with Amazon Connect, Salesforce creates a connected app that integrates Amazon Connect with Salesforce. Through SAML 2.0, the connected app and Salesforce (the identity provider) use a certificate to authenticate users. When you’re notified that a certificate is expiring soon, check whether it’s for your contact center. If it is, provide a replacement certificate.
- The update process includes a brief period when single sign-on (SSO) is unavailable, so complete the update during a low-traffic time.
- While using an expired certificate with your contact center doesn’t break anything, it’s not a good security practice. Updating the certificate takes just a few minutes.
-
Check whether the expiring certificate is used by your Voice contact center.
- From Setup, in the Quick Find box, enter Connected Apps, then select Manage Connected Apps.
- Click the app named (Your contact center name) Connected App.
- In the section named SAML Service Provider Settings, click the certificate listed in the Idp Certificate field to open the certificate settings.
- Check the certificate’s expiration date. If it expires soon, it’s time to replace it.
-
Create a replacement certificate.
- From Setup, in the Quick Find box, enter Certificate, then select Certificate and Key Management.
- To create a certificate, click Create Self-Signed Certificate. For help, see Generate a Self-Signed Certificate.
-
Replace the certificate used by your identity provider.
- From Setup, in the Quick Find box, enter Identity, then select Identity Provider.
- Click Edit.
- In the dropdown, select the certificate that you just created and save your changes.
- On the Identity Provider page, click Download Metadata to download the metadata XML file.
-
Replace the certificate used by your contact center’s connected app.
- From Setup, in the Quick Find box, enter Connected Apps, then select Manage Connected Apps.
- Click Edit next to the app named (Your contact center name) Connected App.
- In the Idp Certificate field, select the certificate that you just created and save your changes.
-
Update the certificate metadata in your AWS settings.
- Log in to the AWS Management Console.
- Click IAM, then select Identity providers.
- From the list of identity providers, select SalesforceServiceVoiceIdp.
- Click Replace Metadata and upload the XML file that you downloaded previously.
-
Verify that your contact center is using the new certificate.
- In Salesforce Setup, in the Quick Find box, enter Contact Centers, and select Amazon Contact Centers.
- Click Telephony Provider Settings.
- If your Amazon Connect Dashboard opens, you’re all set. If you see an error, something’s not right. Try walking through the steps again or contact Salesforce Customer Support for help.
If you have multiple Voice contact centers with telephony provided by Amazon Connect, complete these steps for each contact center.

