Skip to main content

I want to fix the SSL issue so that our customers don't have issues opening our emails. This help page explains the issue in more detail: https://help.salesforce.com/articleView?id=000355099&type=1&mode=1  I asked my MC Account Executive to give me a quote to fix this, even though normally when an issue like this affects existing customers the company responsible fixes the issue without charging their customers. But this is Salesforce... anyways this is her answer:  

Hi Alberto,

Our provisioning team configures the SSLs and upkeeps their security throughout your Contract. The list price for the 2 SSLs is $5,040.

Let me know if you'd like to proceed.

xxxxx xxxxx

Marketing Cloud Account Executive

 These are all the problems I have with this answer: 1. It's a Salesforce problem so you should fix it without us having to pay, as this is an issue that affects salesforce from fulfilling their contract 2. Why do we need 2 SSLs? 3. Normally 1 SSL certificate is free, even Mailchimp offers this. An SSL wouldn't cost more than $100. Salesforce wants $5,000 for 2 SSL certificates to fix their own issue  The solution I thought was to buy our own SSL certificates and then install them ourselves.   After trying to figure out how to setup these SSL certificates and getting nowhere my Account Executive created a ticket to help with this. This is the answer I received:  

Hi Alberto,

Thank you for your response.

What I want to know is:

Where can we upload our certificate in Marketing Cloud if this is something that we can do ourselves?

--Please note that even if you have SSL certificates to apply to a domain, it would require you to have a SSL SKU available on the account for it to be configured on the domain.

I did check further and could not see any spare SSL SKU available on this account. You will need to contact the AE of the account to confirm of there is a purchase available on the account and if not, then you will have to proceed with a purchase . The SAP domain to be completely secured with the SSL certificates will require 2 SSL SKU, one for (click, view and cloud links) and one for (images). You may mention in the form that you already have the certificates and would like to configure them to the domain in SFMC.

If we can’t do this ourselves, who do we need to contact to make this change?

Once the purchase is in place and the form is filled up, the SSL team would connect with you through their own case that is created. SSL team is the team who takes care of anything related to SSL. Unfortunately, a customer cannot configure them themselves in Marketing Cloud. Support does not involve in the process and thus can only provide any information that's required regarding this.

This case was created to know which domain would require SSL to be applied to , which was confirmed to be the SAP domain "mail.onlineautoparts.com.au".

For any further details related to the SKU and purchase, I request you to please connect with the AE and they would be able to assist you further.

Please feel free to let me know if you have any further questions. If not, please let me know if I can proceed to mark this as closed as the requested information was provided.

I await your response. If I do not hear from you today, I shall proceed to mark this as closed tomorrow by the end of the day.

Thank You

Regards,

xxxxxx xxxxxxx

Associate Support Engineer

  Help me understand why this problem that Salesforce overlooked, is mine to fix and why do I have to pay over $5,000 for MC to work correctly.  #AskAMCExpert

2 Antworten
  1. 21. Juni 2021, 22:46

    Hi Agni,

     

    Loading mixed content over HTTPS is a security vulnerability, so it makes sense that Chrome has made this change, and I presume that more browsers are going to enforce this. You can read more about the risk here: https://resources.infosecinstitute.com/topic/https-mixed-content-vulnerability/   Also, when a customer clicks on the link "View on browser" from a marketing email the page will highlight that the connection is not secure. This happens in Chrome, Firefox, and Edge on desktop and mobile.   How is this a Chrome issue? and not a Salesforce issue?  

    Hi Agni, Loading mixed content over HTTPS is a security vulnerability, so it makes sense that Chrome has made this change, and I presume that more browsers are going to enforce this.

     

    safari not secure.jpg

0/9000