Contact Us 1-800-596-4880

Updating Expiring Certificates

Connected apps enable a two-way connection between Anypoint Platform and Salesforce organizations. The connected apps depend on digital certificates for proper functionality. These certificates are time-bound and subject to expiration.

How Certificates Are Generated

During the connection process, API Experience Hub generates self-signed certificates that expire in one year.

One of these self-signed certificates links the Anypoint Platform organization and the Salesforce organization. The certificate and the private key are stored in Secrets Manager in Anypoint Security. When this certificate expires, no notification is sent to the administrator of the Salesforce instance. However, the initial connection between Anypoint Platform and Salesforce remains operational. The next time the administrator logs in to API Experience Hub, an error message displays a connection error and enables the administrator to reconnect. When the administrator logs back in to API Experience Hub, a new certificate generates automatically with a one-year expiration time.

API Experience Hub uses the Salesforce Metadata API to generate an Anypoint certificate during the connection process. The connected app uses this certificate to access metadata content from Anypoint. This certificate is also valid for one year. The administrator of the Salesforce instance receives an email 30 days before the certificate expires. Because a named credential uses the Anypoint certificate, you can’t delete the certificate.

Before You Begin

Before getting started, ensure you have the API Experience Hub Administrator permissions.

Update the Salesforce Identity Data Certificate

To generate a new Anypoint certificate:

  1. Go to Salesforce and click Setup > Security > Certificate and Key Management.

  2. Locate Anypoint in the list and click Edit.

  3. Enter a new name, for example, Anypoint to expire.

    Example for renaming the certificate
  4. Click Save.

  5. Log in to API Experience Hub to trigger a diagnostic check to create a new certificate.

  6. Delete the renamed certificate, for example, Anypoint to expire:

    1. Go to Salesforce and click Setup > Security > Certificate and Key Management.

    2. Locate the renamed certificate in the list and click Delete.