You are using an unsupported browser. Please update your browser to the latest version on or before July 31, 2020.
close
You are viewing the article in preview mode. It is not live at the moment.

Salesforce is implementing security changes that are going to impact Salesforce orgs including Elements clients starting this month.
This article includes the impact and what steps to taketo prepare before they're enforced.

Clients will need to implement and use Microsoft Graph to connect between Salesforce and Exchange Online. To learn more about this and what is required, click here.
Clients will need to implement domain verification. To learn more about this and what is required, click here.

Home > CRM Platform - Salesforce > Prepare for Certificate Changes in 2026 and 2027
Prepare for Certificate Changes in 2026 and 2027
print icon

You or your Admin may have received a notice from Salesforce announcing three changes to their certificate policy to comply with upcoming industry-wide certificate changes. We will review each of them below.

 

Platform Update: Root Certificate Transition (Effective: February 5, 2026)

Due to changes enforced by the Root Certificate Authority, Salesforce will be transitioning from chaining Digicert Root G1 certificates to Digicert Root G2 certificates. This will mean that clients will need to update their trust stores to include Digicert Root G2 certificates. 

 

This will impact you, if you:

  1. Connect to Salesforce endpoints via browser or API
  2. Have certificates hosted on Salesforce using inbound one-way TLS 
  3. Use custom trust stores
  4. Practice certificate pinning

 

This will not impact the use of the following certificates:

  1. Self-signed certificates that are generated in Salesforce for SSO
  2. CA signed certificates uploaded to the Certificate and Key Management page in Slaesforce
  3. Use your own private PKI (Public Key Infrastructure)

 

While this will not impact most Elements clients, we recommend consulting with your IT and technology team to ensure that there are no actions for you to take.

 

Dual-Use Certification Deprecation (Effective: March 15, 2027)

For security and business continuity purposes, dual-use certificates will no longer be supported throughout various tech platforms, including Salesforce. 

 

Dual-use certificates are certificates that are used for both inbound and outbound authentication. An example of this would be if you use a custom API integration through Microsoft Azure, or another server provider, to sync data between it and Salesforce. A certificate has to be stored in both the external system and Salesforce so that the two systems can successfully authenticate with each other. If a dual-use certificate were used in this example, the same certificate would be used by both the API integration and Salesforce to authenticate that connection. With the move away from dual-use certificates, a different certificate would need to be used by both the server and Salesforce to make that connection.

 

If you have a custom integration that you use with Salesforce, we recommend reviewing your certificate usage to ensure that you are not using the same certificate for both systems. 

 

This will not impact you, if you:

  1. Generate certificates in Salesforce for SSO into Salesforce
  2. Use native bulk data tools with Salesforce (namely Dataloader.io and Data Loader Desktop Application)
  3. Generated a CA (Certificate Authority) certificate for use with the Fidelity for Salesforce app

 

Mandatory Reduction of Certificate Lifespans (Effective: March 15, 2026)

In accordance with industry-wide changes, Salesforce is using a phased approach to shorten the lifespan for new TLS certificates. Most clients wouldn't be using TLS certificates unless they have a custom integration or HTML service that is using a certificate to connect to Salesforce. 

 

Timeline

March 15, 2026: Certificate lifespan decreased from 398 to 200 days

March 15, 2027: Certificate lifespan decreases from 200 to 100 days

March 15, 2029: Certificate lifespan decreases from 100 to 47 days

 

Impact

 

If you are using a certificate that you generated through a Certificate Authority, this may impact you and we recommend consulting with your technology providers to determine best next steps.

 

This should not impact you if, if you:

  1. Have generated a self-sign signed certificate in Salesforce for SSO 
  2. Generated a CA (Certificate Authority) certificate for use with the Fidelity for Salesforce app

 

Elements can be customized by your System Administrator, so your views & access may differ from this documentation. Please contact your System Administrator with specific questions.

Feedback
0 out of 0 found this helpful

scroll to top icon