What’s changing?
As of April 2022, Commerce Cloud will start blocking traffic that doesn’t originate from Commerce Cloud eCDN from accessing the hyphenated demandware.net hostname. This change rejects calls that use hyphenated hostnames production- or development- to access Open Commerce API (OCAPI) or Storefront.
Traffic through demandware.net doesn’t provide eCDN controls today. Take action to protect your data by ensuring that external traffic passes through the security layers of the eCDN before it accesses your environment.
How is my org affected?
This change affects Commerce Cloud customers who use production- or development- hostnames to access OCAPI or Storefront. Change these hyphenated hostnames to your vanity hostname to avoid any impact from the change.
Implementations that use the Commerce Cloud eCDN or a stacked CDN configuration in front of the Commerce Cloud eCDN, for example, using a vanity hostname such as brand.com, www.brand.com, aren’t affected. If you access Business Manager via production-realm-customer.demandware.net, you aren’t affected because Business Manager is considered internal to the Commerce Cloud ecosystem.
When is the change happening?
The change is enforced in phases from April through August 2022.
How can I prepare?
Please take the following actions:
What steps do I take to deprecate non-SNI traffic?
Update your supported web browsers.
Review stacked Akamai configurations for non-SNI traffic going to a SFCC/Cloudflare root domain.
Which specific services are still allowed to access the hyphenated demandware.net hostname?
Please note that not all Salesforce services will be included in these new firewall rules by Commerce Cloud.
Get Help
Direct questions about this change to the B2C Commerce Trailblazer Group. If you notice a critical impact to environments during enforcement, or if the new firewall rules are not working as expected, you can raise a case with Salesforce Support.
000391803

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.