At ZangaBee, we continuously monitor updates from the platforms we support, including Salesforce and Celigo. By staying current with upcoming changes, we help our customers keep their integrations secure, reliable, and compliant.

Salesforce has announced several important certificate-related changes that will affect integrations over the coming years. These changes are driven by evolving industry security standards and are designed to improve the security of TLS and mTLS connections.

If your organization integrates with Salesforce, particularly through Celigo, now is a good time to review these updates and determine whether any action is required.

1. Dual-Use Certificate Deprecation (Effective March 15, 2027)

This is the most urgent upcoming change.

The industry is moving away from dual-use certificates, meaning the same certificate can no longer be used for both client authentication and server authentication. Organizations using mutual TLS (mTLS) must ensure they use separate client certificates to remain compliant.

Failure to prepare could result in integration failures and service disruptions.

Although browser vendors have made minor adjustments to their timelines, Salesforce recommends acting now to maintain secure and compliant integrations.

2. TLS Certificate Lifespan Reduction (Effective March 15, 2026)

Industry security standards are also reducing the maximum validity period of TLS certificates.

Salesforce will progressively shorten TLS server certificate lifespans.

  • Current maximum: approximately 200 days
  • Target by March 2029: 47 days

This means organizations will need to renew and rotate certificates much more frequently. Planning for automated certificate management where possible is strongly recommended.

3. Root Certificate Transition (Completed February 5, 2026)

Salesforce has completed its transition to certificates chained to the DigiCert Global Root G2.

If your systems establish one-way inbound TLS connections to Salesforce, your trust stores should include the current Mozilla Root Store, ensuring that the required root certificate authorities are trusted.

What Does This Mean for Celigo Integrations?

For most organizations using Celigo to integrate with Salesforce, no action is expected to be required. Celigo-supported integrations generally handle these certificate updates without customer intervention.

However, every integration landscape is different. If your environment contains custom components or additional connections, it is worth verifying that everything is ready.

At ZangaBee, we actively monitor changes like these so our customers do not have to. We review vendor announcements, assess their impact on integrations, and help customers prepare well before deadlines arrive.

How ZangaBee Can Help

Our records indicate that your organization uses Salesforce, possibly in combination with Celigo.

If you already have a support contract with ZangaBee, there is nothing you need to do. We will include these checks as part of your support services.

If you do not have a support contract, we recommend reviewing your environment to determine whether any changes are required. If you would like assistance, we can assess your Salesforce integrations and include your environment in our planning before the relevant deadlines.

Questions?

If you would like us to review your Salesforce integrations or discuss whether these certificate changes affect your environment, feel free to contact us:

We are happy to help ensure your integrations remain secure, compliant, and uninterrupted.

🍪 Wij gebruiken cookies om je de beste gebruikservaring te kunnen bieden.