Loading
Salesforce Enforces New Security Requirements in Summer 2026Read More

Looks like you haven't replaced the certificate or used the wrong certificate. Replace the certificate with the correct certificate for the substrate and try again.

Publish Date: Jul 22, 2026
Description

In Consumer Goods Cloud, the CG Pairing Services certificate renewal process fails and the tenant throws an error. This typically occurs when the user performing the certificate replacement is missing the Processing Services permission set and license, which prevents the renewal from completing successfully.

Resolution
Follow these steps to successfully replace the CG Pairing Services certificate:

  1. Assign the Processing Services permission set and license to the user performing the certificate replacement.
  2. In Setup, go to Certificate and Key Management and create a new certificate named CGCloud_Services.
  3. Download the newly created certificate.
  4. Navigate to the External Client AppEdit Settings → replace the old certificate with the new one → Save.
  5. In Setup, search for Processing Services and click Register.
  6. Once the above steps are completed then follow the below document from the Step "Replace the Self Signed Certificate for Your Connected App" : https://help.salesforce.com/s/articleView?id=ind.tpm_admin_task_tenant_pairing.htm&type=5

Once complete, the tenant should be restored.
Knowledge Article Number

005389646

 
Loading
Salesforce Help | Article