Skip to main content

#Security88 debatiendo

Our Tableau server's SSL certificate (from GoDaddy) expired today so we installed a new one. Users who browse to our Tableau site with Chrome or with Edge have no problems and the browsers indicate that the cert is trusted and good until March. However, three of our users are using Tableau Desktop 26.2.2783. One of them tried to use 'activate by logging into a server' and chose our Tableau server, but received the error 'cannot connect to Tableau Server, server's certificate is not trusted'. 

 

I have confirmed that this user has no problems accessing our Tableau site via browser. it's just the app that gets the certificate error. 

 

#Tableau Desktop & Web Authoring  #Security

2 respuestas
  1. Ayer, 16:24

    Thank you for the suggestion. I followed the steps in the link about clearing them manually, but for some reason, the error persisted. In the end what solved the problem was this: the certificate files we were using were IIS files, and came in the form of a .crt file, a PEM file, and an IIS intermediates .p7b file. I installed the CRT file to the user's certificate stores without a problem, but when I attempted to install the p7b file, Windows said it could not verify that the file was actually from GoDaddy (despite my having downloaded the file directly from the site). I had the machine install the file to the certificate store anyway, and afterwards Tableau Desktop was willing to start and activate properly. 

     

0/9000

Hi everyone, 

I'm experiencing an issue in a Salesforce Sandbox when trying to access: 

Setup → App Manager → View App → Manage Consumer Details 

 

When I click Manage Consumer Details, Salesforce opens the Verify Your Identity dialog, but the authentication immediately fails with the following error: 

There are no built-in authenticators available to this browser. 

Verify Your Identity fails with 'There are no built-in authenticators available to this browser' when opening Manage Consumer Details

 

Environment:

  • Salesforce Sandbox
  • Google Chrome

 

What I've already verified:

  • Touch ID is correctly registered as my authentication method.
  • Touch ID works correctly for other authentication requests.

 

From what I've investigated, it appears that the Verify Your Identity dialog may be rendered inside an internal iframe, and the browser is therefore unable to access the registered authenticator. 

 

Has anyone encountered this issue before? Is this a known Salesforce or Chrome limitation, or is there a configuration or workaround that resolves it? 

 

Any help or suggestions would be greatly appreciated. 

 

Thank you! 

 

 

 

#Security

14 respuestas
  1. Ayer, 13:39

    A work colleague has shared another alternative solution with me. 

     

    In Setup → Session Settings → Session Security Levels, move Passwordless Login via Passkeys to the High Assurance category. 

     

    Why does this work? 

     

    Salesforce allows us to define which authentication methods establish a High Assurance session. By classifying Passwordless Login via Passkeys as High Assurance, users who log in with a passkey start their session at that security level. 

     

    As a result, when they perform sensitive operations that require High Assurance, Salesforce doesn’t prompt them to verify their identity again during the same session: 

     

    If you require high assurance for sensitive operations and users have a high-assurance session after logging in, they aren’t prompted to verify their identity in the same session.

     

    The list of affected operations and the corresponding configuration can be found here: Require High-Assurance Session Security for Sensitive Operations

0/9000
4 respuestas
  1. 24 sept, 7:37

     Run your test class from Developer Console --> Test --> Run All first. Make sure the Parklocater class reaches 100% coverage and there are no test failures. After that, return to Trailhead and click Check Challenge again. Also verify that your test method covers all executable lines in the Parklocater class.

0/9000
4 respuestas
0/9000

Hi everyone, 

 

I’m working on a simple Lightning Web Component that contains a list of external reading resources. The links work normally when I copy them into Chrome, but I’m having trouble when I try to open them directly from the LWC. 

 

For example, I added a reference link for the Surah Baqarah Last 2 Ayat resource

. When I click the link from the component, the behavior is inconsistent depending on how the link is opened. 

 

I’m currently using a standard anchor element and have also tried NavigationMixin with standard__webPage. 

 

Is there a recommended Salesforce approach for opening an external HTTPS website from an LWC? Do I need to add the domain under Trusted URLs/CSP settings, or should an external website simply be opened in a new browser tab without any CSP configuration? 

 

Any example of the recommended implementation would be appreciated. 

 

#Security

2 respuestas
  1. Divs Chauhan (kcloud) Forum Ambassador
    23 sept, 6:35

     Hi Kevin, 

     for opening an external website from an LWC, you don't need any CSP/Trusted URL configuration that's only required when the LWC needs to call an external endpoint or load a remote resource . Simply navigating the user's browser to an external URL in a new tab is just standard browser navigation and Salesforce doesn't mediate it. you can use a plain anchor tag with rel="noopener noreferrer". 

      

     I hope this help!!

0/9000

Can anyone provide more details on exactly how and where the new Certificate Trust Store is used? 

 

The release notes suggest the Trust Store is intended to support adding additional root certificates to allow Named Credential callouts to endpoints signed by a private or internal CA not already in the global Salesforce-managed trust store. 

 

However, the help documentation indicates that the Trust Store is used for "for validating inbound TLS connections" (???), and also states "The Certificate Trust Store supports Named Credentials integrations only." 

The help text within a Winter 27 sandbox states it is used for "API calls and SSO": 

New Certificate Trust Store usage unclear

 

1) Where exactly is the new "Certificate Trust Store" used?  Is it Named Credentials only?  Is it with outbound TLS connections or inbound, too? 

 

2) It is also unclear if the new "Certificate Trust Store" replaces the global Salesforce-managed trust store, or if the Trust Store provides a means to add additional certificates.  In other words, customers should never need to upload public root certificates that are already present in the global Salesforce-managed trust store, customers only need to upload root certificates from a private or internal CA, right? 

 

Thanks! 

#Security

3 respuestas
0/9000

Today I have facing an issue, In my project we have some developer sandboxes. After sandbox refresh action completed, Currently we are unable to verify the email for the non admin users (users whom are not mentioned in the public group which can mentioned during sandbox refresh process). Means, Once sandbox refresh done, We unfreeze the active user and update his original email and that user have received the verification email with verification link. But during clicking the verification link, it's required login to confirm the email address. 

 

But you know, That user doesn't able to login into salesforce because the sandbox just refreshed and user doesn't have the access for the org, We actually ask the user to confirm the email for perform the "password reset" action for that user to enable the access for the org. 

 

So how to by pass this "Login required" behaviour and verify the email link as like previous from the email directly? 

 

Even I have disabled the Permission "

Require identity verification for email address changes" from Identity Verification settings as per Salesforce docs.

 

But still the behaviour is same, So anyone know how to fix/bypass this? 

 

Any help appriciated. 

 

#Salesforce Admin #Sandboxes #Security #Identity and Access Management #Salesforce

 

Thanks, 

Mohanraj S 

 

 

1 respuesta
  1. 22 sept, 16:06

    We have had luck in resolving this a few ways. 

    • Selecting the 'Generate new password and notify user immediately' checkbox. 
    • Generating a temporary verification code and sending to them. 

    Otherwise you may need to reach out to Salesforce support to get help. There was a bug that says it has been fixed. Users are not able to change and verify their emails in all Orgs after Summer 26 release | Issue Details | Salesforce Help

     

     

    Either way, it also explains other options that may help unstuck your non admins in a Sandbox. 

0/9000

Hello All, 

We are currently facing an issue with the Salesforce Connector for Google Sheets. We have been unable to export Salesforce reports to Google Sheets using the connector. 

We are receiving the following error message: 

"In order to get all of the report data, disconnect and re-authorize the Add-on from Salesforce using Help > Connection Information > Disconnect Add-on. Once disconnected, log in to Salesforce again using the Add-on." 

Based on our initial findings, we suspect that this issue may have been caused by the recent MFA enforcement in the Production environment.  

Each time a user tries to export a report, a new verification window opens and asks for an MFA verification code.

We are using the Salesforce Connector and have followed the instructions provided in the error message. After reconnecting, the export works only up to 2,000 records, and then the connection fails again.

Is there any workaround or recommended solution to prevent repeated MFA prompts and allow users to export reports successfully?

 

 

 

#Salesforce Admin  #Security  #MFA  #Salesforce_connector

7 comentarios
  1. 21 sept, 9:55

    We are migrating to SOQL, meaning we will use the same Google Connector to query the data directly instead of exporting reports. Because this SOQL export operates via the API rather than the UI, it successfully bypasses the mentioned limitation.

    However, please keep the following SOQL specifics in mind:

    • Row Limits: Extracts are capped at 10,000 rows.
    • Headers: Google Sheets will display field API names instead of standard field labels.
    • Formatting: The column order in the sheet may not match the order of fields in your query.

    Despite these quirks, this remains a highly effective workaround.

0/9000

Hey Community. 

 

I have what I thought was quite a simple requirement for a user permission.    

 

I have user a who is assigned a profile which provides read and view all for opportunities.  I have then assigned them to a permission set which provides all those profile users the ability to edit only 5 fields but on all record types.   

 

I then have a second permission set assigned only to this specific user which allows them to create and edit funding and legacy record type opportunities with full edit permission on all fields on those records types.   

 

However, they are still able to create opportunities of any record type and have full edit which we do not want.   

 

I have been researching this and the conclusion is that SF combines those permissions, taking the 'create and full edit' from one and 'all record types' from the other.  This does not make sense to me and I cannot believe that this is not achievable through permission sets. I feel as though I am missing something obvious. 

 

Does anyone have any suggestions on how to achieve this OOB.  

 

Many thanks 

Natalie Gorman 

 

#Security  #Permissionset

3 respuestas
  1. 21 sept, 9:03

    @Rahul Chauhan

    , thank you.  I've used validation rules and custom permissions to achieve other rules but I don't think this is a practical solution for this one as we are effectively saying if they try to edit and save any of the fields bar 5 on the opportunity then prevent that.  I don't believe there is a way in a validation to say allow only these 5 fields,  and thererore I would have to list all the fields that they cannot edit - is that correct?  In which case there are too many fields and the managing of this if new fields were added to the opportunity doesn't make it a sensible option.   

     

    I think the only other alternative out of the box would be to have a seperate profile which we were trying to avoid. Do you agree that is the only other option without resorting to apex or such like?

0/9000

I need help to test the roll out of Salefsorce MFA Passkey set up. Please suggest all personas and all test scenarios for testing  

 

#Security

2 respuestas
0/9000