You are using an unsupported browser. Please update your browser to the latest version on or before July 31, 2020.
close
You are viewing the article in preview mode. It is not live at the moment.

We’re excited to share that Black Diamond has a new home on LinkedIn: SS&C Black Diamond Wealth Solutions 

Home > Elements Support & FAQs > Prepare for Certificate Changes in 2026 and 2027
Prepare for Certificate Changes in 2026 and 2027
print icon

You or your Admin may have received a notice from Salesforce announcing three changes to their certificate policy to comply with upcoming industry-wide certificate changes. We will review each of them below.

 

Platform Update: Root Certificate Transition (Effective: February 5, 2026)

Due to changes enforced by the Root Certificate Authority, Salesforce will be transitioning from chaining Digicert Root G1 certificates to Digicert Root G2 certificates. This will mean that clients will need to update their trust stores to include Digicert Root G2 certificates. 

 

This will impact you, if you:

  1. Connect to Salesforce endpoints via browser or API
  2. Have certificates hosted on Salesforce using inbound one-way TLS 
  3. Use custom trust stores
  4. Practice certificate pinning

 

This will not impact the use of the following certificates:

  1. Self-signed certificates that are generated in Salesforce for SSO
  2. CA signed certificates uploaded to the Certificate and Key Management page in Slaesforce
  3. Use your own private PKI (Public Key Infrastructure)

 

While this will not impact most Elements clients, we recommend consulting with your IT and technology team to ensure that there are no actions for you to take.

 

Dual-Use Certification Deprecation (Effective: March 15, 2027)

For security and business continuity purposes, dual-use certificates will no longer be supported throughout various tech platforms, including Salesforce. 

 

Dual-use certificates are certificates that are used for both inbound and outbound authentication. An example of this would be if you use a custom API integration through Microsoft Azure, or another server provider, to sync data between it and Salesforce. A certificate has to be stored in both the external system and Salesforce so that the two systems can successfully authenticate with each other. If a dual-use certificate were used in this example, the same certificate would be used by both the API integration and Salesforce to authenticate that connection. With the move away from dual-use certificates, a different certificate would need to be used by both the server and Salesforce to make that connection.

 

If you have a custom integration that you use with Salesforce, we recommend reviewing your certificate usage to ensure that you are not using the same certificate for both systems. 

 

This will not impact you, if you:

  1. Generate certificates in Salesforce for SSO into Salesforce
  2. Use native bulk data tools with Salesforce (namely Dataloader.io and Data Loader Desktop Application)
  3. Generated a CA (Certificate Authority) certificate for use with the Fidelity for Salesforce app

 

Mandatory Reduction of Certificate Lifespans (Effective: March 15, 2026)

In accordance with industry-wide changes, Salesforce is using a phased approach to shorten the lifespan for new TLS certificates. Most clients wouldn't be using TLS certificates unless they have a custom integration or HTML service that is using a certificate to connect to Salesforce. 

 

Timeline

March 15, 2026: Certificate lifespan decreased from 398 to 200 days

March 15, 2027: Certificate lifespan decreases from 200 to 100 days

March 15, 2029: Certificate lifespan decreases from 100 to 47 days

 

Impact

 

If you are using a certificate that you generated through a Certificate Authority, this may impact you and we recommend consulting with your technology providers to determine best next steps.

 

This should not impact you if, if you:

  1. Have generated a self-sign signed certificate in Salesforce for SSO 
  2. Generated a CA (Certificate Authority) certificate for use with the Fidelity for Salesforce app

 

Because all CRMs can be customized by the System Administrator, it is possible your views and access will differ. 
Please contact your System Administrator with questions on your firm's views and access.

Feedback
0 out of 0 found this helpful

scroll to top icon