Validate the Revocation Status of User Authentication Certificates
Each time users log in with a certificate, you can validate its revocation status using
the Online Certificate Status Protocol (OCSP) or Certificate Revocation Lists (CRL). With OCSP,
Salesforce checks the revocation status of certificates in real time. If an OCSP status check
fails, or a certificate isn’t configured for OCSP, Salesforce uses a CRL instead.
Required Editions
Available in: both Salesforce Classic and
Lightning Experience in All editions
User Permissions Needed
To manage certificate-based-authentication:
Manage Internal Users
Before you enable revocation status checks, make sure that your uploaded user certificates
contain OCSP or CRL endpoints. This setting prevents logins with certificates that don’t have
valid endpoints or have a revoked status.
From Setup, in the Quick Find box, enter Identity Verification, and
then select Identity Verification.
Select Check the revocation status of certificates.
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.