Skip to main content

#MyRefresh0 discussing

Maybe someone here has experience of instance refresh by Salesforce (when Salesforce migrates sandboxes to other locations)

When a full copy sandbox is migrated during instance refresh, what happenes to data and metadata in the sandbox? Does everything stay the same, or it is refreshed with production data and metadata?

6 answers
0/9000

Next month, there is a scheduled instance refresh for our org. One impact of the instance refresh is that two URLs on the chat script will be updated. We have several external websites (vendors) where our chat buttons are hosted and the number of chat buttons is over 30. It is a difficult task to coordinate the change with all the vendors because they have their own restrictions and release timelines.

 

I wanted to know if there is any solution that we can implement that will prevent the need to update the chat script URLs whenever an instance refresh or org migration happens. #MyRefresh

3 answers
0/9000

From the Q8 it said the cert in the current instance will remain the same for the new instance.

https://help.salesforce.com/s/articleView?id=000387056&type=1

 

We are migrating from AP4 to AP48...

In my understanding, the cert common name currently is ap4.salesforce.com, and in the future if will it be ap4.salesforce.com or ap48.salesforce.com

If the fingerprint or anything will be the same? As we have some applications to put the exact cert for cert pinning...

 

Thank you

 

#MyRefresh

1 answer
  1. May 24, 2023, 2:53 PM

    Thanks for asking. That knowledge article needs to get updated as the answer to question 8 has changed recently. The certificate will change from ap4.salesforce.com to ap48.salesforce.com.

     

    That being said, Salesforce generally recommends not pinning its server certificates and, if a system needs to pin a certificate, pinning either the root or the intermediate certificate is expected to have a more seamless certificate-update experience. Hyperforce and the Salesforce Edge Network don't announce certificate updates in advance, and moving away from pinning the individual server certificates can help achieve better compatibility with Hyperforce and the Salesforce Edge Network.

     

    Additionally, as @Mark Gamache pointed out in https://trailhead.salesforce.com/trailblazer-community/feed/0D54S00000PjRyISAV, the security industry as a whole sees pinning as creating more risk than reward. The CA industry, with the leadership of the CABF, has made ill-gotten certs a thing of the past. Upcoming changes in their rules are likely to make pinning even more risky to service availability.

0/9000