Saturday 4 July 2015

HTTPS Security Certificate Change from SHA-1 to SHA-256 hash algorithms


Recently Salesforce upgraded security for HTTPS certificate by replacing SHA-1 signature hash algorithm with SHA-256 signed hash algorithm, and CA signed certificates to be only Symantec-issued certificates.

We were in middle of UAT, and Go-Live planned in couple of weeks ahead. Initially the self signed certificate SAP used was SHA-1 signed. There was one scenario where suddenly the connection between SAP and SFDC in all the sandboxes seemed broken resulting in communication error and failure. The most likely reason, which I later figured out in my opinion, was this HTTPS certificate security upgradation. SAP PI, the middleware, had to re-install this new SHA-256 certificate again and restart its XIAdapter to get the connection working.

The only potential change in our case was the middleware SAP PI to update the cached certificate with this new upgrade.

For more details, refer this SFDC knowledge article





No comments:

Post a Comment

Thank you for visiting. Your comments are highly appreciated.