Loading
Prepare for Email to Become the Default Login ExperienceRead More
Multiple Salesforce Services Impacted - Support Case Creation Also AffectedRead More
Intermittent freezing when using using certain browser versionsRead More
Secure Your Salesforce Org
Best Practices for Managing Root Certificates

Best Practices for Managing Root Certificates

Root certificates are the essential trust anchors for your org’s encrypted integrations. Before configuring your Certificate Trust Store, learn how to maintain the integrity of your connections.

Required Editions

Available in:
Note
Note The Certificate Trust Store supports Named Credentials integrations only. All other external connections rely on root certificates included in the global, Salesforce-managed trust store.

Managing root certificates requires a proactive and cautious approach. A missing or expired root certificate can lead to widespread connection failures that are sometimes difficult to diagnose. To maintain secure and uninterrupted integrations, follow these best practices for monitoring and updating your Certificate Trust Store.

  • Before deleting a root certificate from your trust store, perform a full audit of your active integrations. Deleting a root certificate that’s currently in use immediately breaks all associated integrations.
  • Ensure that the right users in your org receive alerts about upcoming certificate expirations. Salesforce sends email alerts 60, 30, and 10 days before a root certificate in your trust store expires. To manage who gets notified, see Set Expired Certificate Notification Permission.
  • To prevent service disruptions, update root certificates before they expire. When you receive an expiring cert notification via email, plan on uploading a new certificate. Once you’ve uploaded a new certificate and tested it with the integration services, it is safe to delete the old certificate.
  • Review your Trust Store periodically, and remove root certificates for services or partners you no longer use. Your org can store up to 50 non-expired certificates.
 
Loading
Salesforce Help | Article