Skip to main content

Hello Salesforce Developer Community, 

 

We are building a custom Apex HTTP integration to sync patient appointment schedules from our clinic web portal into Salesforce Health Cloud, but we are encountering an SSL/CORS authentication error.

 

Technical Scenario & Error: When executing an Apex HttpRequest callout from a Salesforce Sandbox to our endpoint hosted on our domain (avangartclinic.com), the system throws a System.CalloutException: Unauthorized endpoint or TLS Mutual Authentication failure.

 

Environment Details:

  • Portal Domain: avangartclinic.com
  • Salesforce Service: Health Cloud / Apex REST Callout
  • Error: TLS Handshake / CORS Origin Header Discrepancy

Steps Taken:

  1. Verified that the primary SSL certificate on avangartclinic.com is valid and fully chain-verified.
  2. Added (avangartclinic.com) to Salesforce Remote Site Settings.
  3. Tested the REST API endpoint independently via Postman (returns HTTP 200 OK).

 

Are there specific Content Security Policy (CSP) Trusted Sites configurations or certificate trust chain requirements in Salesforce Health Cloud when connecting to custom HTTPS endpoints?

 

Any advice or Apex code snippets would be greatly appreciated.

Thanks! 

 

#Apex Code

1 件の回答
  1. 9月23日 16:46

    Hi @Avangart Clinic

     

    Since this is an Apex server-to-server callout, I would focus on the TLS/SSL handshake rather than CORS or CSP. CORS is primarily relevant to browser-based requests. 

    I would check the following: 

    •  Verify the endpoint in Remote Site Settings or, preferably, use a Named Credential. 
    •  Validate the complete SSL certificate chain, including all intermediate certificates. 
    •  Check that the endpoint supports the TLS version/cipher requirements expected by Salesforce. 
    •  Test the certificate chain using openssl s_client -connect avangartclinic.com:443 -showcerts. 
    •  If mutual TLS (mTLS) is being used, also verify the client certificate and its chain. 

     

    Since Postman works successfully, I would specifically compare the TLS handshake/certificate chain rather than focusing on the API response itself. 

      

    In short, I would investigate the SSL certificate chain and TLS configuration first; CSP Trusted Sites is unlikely to resolve an Apex callout TLS error. 

     

    https://help.salesforce.com/s/articleView?id=000386138&type=1&utm

     

    https://help.salesforce.com/s/articleView?id=000386840&type=1&utm_source

     

    https://help.salesforce.com/s/articleView?id=000385068&type=1&utm

     

    If you find this response helpful, please mark it as the Accepted Answer, as it may also help other Trailblazers.  

0/9000