Loading
Prepare for Email to Become the Default Login ExperienceRead More
Multiple Salesforce Services Impacted - Support Case Creation Also AffectedRead More
Intermittent freezing when using using certain browser versionsRead More
Secure Your Salesforce Org
Validate the Revocation Status of User Authentication Certificates

Validate the Revocation Status of User Authentication Certificates

Each time users log in with a certificate, you can validate its revocation status using the Online Certificate Status Protocol (OCSP) or Certificate Revocation Lists (CRL). With OCSP, Salesforce checks the revocation status of certificates in real time. If an OCSP status check fails, or a certificate isn’t configured for OCSP, Salesforce uses a CRL instead.

Required Editions

Available in: both Salesforce Classic and Lightning Experience in All editions
User Permissions Needed
To manage certificate-based-authentication: Manage Internal Users

Before you enable revocation status checks, make sure that your uploaded user certificates contain OCSP or CRL endpoints. This setting prevents logins with certificates that don’t have valid endpoints or have a revoked status.

  1. From Setup, use the Quick Find box to find and select Identity Verification.
  2. Select Check the revocation status of certificates.
  3. Save your changes.
 
Loading
Salesforce Help | Article