You are here:
Manage Your Certificate Trust Store
Use the Certificate Trust Store to maintain a repository of root certificates for validating TLS connections. The Certificate Trust Store is tied to your individual Salesforce org and isn’t shared with others. By managing your own trust store, you can ensure that integrations align with your specific security and compliance requirements.
The Certificate Trust Store supports Named Credentials integrations only. All other external connections rely on root certificates included in the global, Salesforce-managed trust store.
- Best Practices for Managing Root Certificates
Root certificates are the essential trust anchors for your org’s encrypted integrations. Before configuring your Certificate Trust Store, learn how to maintain the integrity of your connections. - Upload a Root Certificate
Add a certificate to your trust store by uploading a root certificate in a supported format. - Download a Root Certificate
Download a certificate if you need to inspect, audit, backup, share with a partner or vendor, or import into another environment (e.g., prod → sandbox). - Delete a Root Certificate
When you’re notified that a certificate authority (CA) is expiring, or when your org no longer needs a certificate, manage certificate deletion appropriately.
