Salesforce certificate expiration notifications

Last updated: October 8, 2025

Salesforce periodically requires certificate updates to maintain secure, encrypted connections. When you receive a notification about an expiring Salesforce certificate, it’s important to understand what it means for your amplo environment and what steps to take.

Overview

In most cases, standard configurations are not affected by certificate expirations. However, if your organization uses custom integrations (such as API connections or third-party services), those may require updates to maintain connectivity once a new certificate is generated.

Process

If you receive a certificate expiration notice from Salesforce, follow these steps to renew and update your certificate:

  1. Navigate to Setup.

  2. Go to Certificate and Key Management.

  3. Download the expiring certificate and save it for your records.

  4. Generate a new certificate, choosing one of the following options:

    1. Self-signed certificate: Recommended for most use cases.

    2. CA-signed certificate: Required if a certificate authority signature is needed for your integration.

  5. Update any external integrations or connected services to use the new certificate.

  6. Test all connections to confirm they're working properly.

  7. Once confirmed, delete the old certificate.

Considerations

Before updating your certificates, keep the following in mind:

  • Update certificates before the expiration date to avoid service interruptions.

  • Allow adequate time for testing after generating the new certificate.

  • Keep a backup of the old certificate until all systems are verified to be working correctly with the new one.