Skip to main content

From the Q8 it said the cert in the current instance will remain the same for the new instance.

https://help.salesforce.com/s/articleView?id=000387056&type=1

 

We are migrating from AP4 to AP48...

In my understanding, the cert common name currently is ap4.salesforce.com, and in the future if will it be ap4.salesforce.com or ap48.salesforce.com

If the fingerprint or anything will be the same? As we have some applications to put the exact cert for cert pinning...

 

Thank you

 

#MyRefresh

1 respuesta
  1. 24 may 2023, 14:53

    Thanks for asking. That knowledge article needs to get updated as the answer to question 8 has changed recently. The certificate will change from ap4.salesforce.com to ap48.salesforce.com.

     

    That being said, Salesforce generally recommends not pinning its server certificates and, if a system needs to pin a certificate, pinning either the root or the intermediate certificate is expected to have a more seamless certificate-update experience. Hyperforce and the Salesforce Edge Network don't announce certificate updates in advance, and moving away from pinning the individual server certificates can help achieve better compatibility with Hyperforce and the Salesforce Edge Network.

     

    Additionally, as @Mark Gamache pointed out in https://trailhead.salesforce.com/trailblazer-community/feed/0D54S00000PjRyISAV, the security industry as a whole sees pinning as creating more risk than reward. The CA industry, with the leadership of the CABF, has made ill-gotten certs a thing of the past. Upcoming changes in their rules are likely to make pinning even more risky to service availability.

0/9000