Salesforce uses SSL certificates to secure data communications, authenticate users via Single Sign-On (SSO), and establish trusted connections with external systems. When these certificates approach their expiration date, Salesforce sends automatic email notifications to relevant administrators to prevent service disruptions.
Salesforce sends certificate expiration notifications to prevent service disruptions, such as inability to access custom domains or SSO (Single Sign-On) authentication failures. SSO is an authentication method that allows users to access Salesforce using credentials from an external identity provider. These notifications help administrators maintain uninterrupted service by replacing certificates before they expire.
A Certificate Authority (CA) is a trusted entity that issues digital certificates to verify the authenticity of secure communications. In Salesforce, CAs play a key role in ensuring secure, encrypted connections between clients, integrations, and Salesforce services
Certificate expiration notifications are sent at the following intervals:
Notifications are sent to users with the following Salesforce permissions:
Note: Restricting certificate expiration notification emails to specific users is currently an Idea on the Salesforce IdeaExchange. See "Limit Who Receives Notifications About Certificate Expiration for the latest update"
Self-signed certificates are commonly used for Single Sign-On (SSO) settings in the 'Request Signing Certificate' or 'Assertion Decryption Certificate' field, or for callouts to external sites for client authentication. A CA-signed (Certificate Authority-signed) certificate is used to prove that your org's data communications are genuine.
If you receive this notification, open the Salesforce org mentioned and navigate to Setup | Security | Certificate and Key Management. The certificate name in this list matches the name provided in the notification.
Before replacing the certificate, identify where it is currently being used in your Salesforce org:
Depending on how the expiring certificate is used in your Salesforce org, follow the appropriate steps below:
The certificate may be used as the "Request Signing Certificate" for an SSO setting. Follow these steps to resolve:
The certificate may be used in a Connected App configuration, such as for OAuth SSO setup. Update the Connected App to use a new, valid certificate. See the Trailhead example for guidance .
The Identity Provider feature was enabled by default in many Salesforce orgs, which automatically creates a self-signed certificate. If you are not actively using the Identity Provider feature:
If the certificate is used for callouts to external sites via custom Apex code:
Once the expiring certificate has been replaced in all locations, the old certificate should show a Del link next to its name in Certificate and Key Management. Click this link to delete the expired certificate.
Salesforce Identity Provider Feature
Generate a Self-Signed Certificate
Generate a Certificate Signed by a Certificate Authority
Limit Who Receives Notifications About Certificate Expiration
How to Remove Expired Self-Signed Certificate
Limit Who Receives Notifications About Certificate Expiration
000385781

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.