function readOnly(count){ }
Starting November 20, the site will be set to read-only. On December 4, 2023,
forum discussions will move to the Trailblazer Community.
+ Start a Discussion
neha Gupta 139neha Gupta 139 

SFDC Expiring Certificate Notification Description

SFDC Expiring Certificate Notification
DescriptionWe received a mail from salesforce -
You have one or more certificates in your Salesforce org  that will expire soon. Review the list below and visit Certificate and Key Management from Setup to make an update.
I can see there is one valid certificate available can I replace the expiring certificate with this certificate  ?
Also when I am trying the replace this certificate , I am getting a warning message -
Warning: If you change this certificate, users can't connect to service providers until you reconfigure each service provider to work with the new certificate.
Let me know what actions I need to take .
NagendraNagendra (Salesforce Developers) 
Hi Neha,

Self-signed certificates are commonly used for Single Sign-On settings (in 'Request Signing Certificate' or 'Assertion Decryption Certificate' field) or callouts to external sites (for client authentication).
If you receive this notification and have already checked those items but are still unable to delete the certificate, please check the following,
The self-signed certificate was likely automatically created because the Salesforce as Identity Provider feature is enabled. This feature requires a certificate to be connected for the feature to be enabled. If you have no records under the "Service Provider" section, you are not using the feature.

Depending on your situation, one of the following two options may help you resolve the issue,
 
Option 1: Update the Identity Provider settings to use the new certificate.
Option 2: You can choose to disable the option of using Salesforce as an

Identity Provider entirely. This will remove the need for the certificate and prevent future expiration messages.

The expiring certificate should now have a "Del" link next to the name, which you can click to delete the certificate. 

For more information please check with below links. Hope this helps.

Kindly mark this as solved if the information was helpful.

Thanks,
Nagendra