Knowledge Base
How to generate a CSR and install an SSL/TLS certificate in Salesforce
Overview
This article helps Salesforce administrators create a Certificate Signing Request (CSR) in Salesforce and install the SSL/TLS certificate that the Certificate Authority (CA) issues for it. A CSR is the file that you send to the CA to request a certificate. By the end, the certificate is uploaded and its status is Active in Certificate and Key Management. The article covers the prerequisites, how to generate the CSR, how to install the signed certificate, and how to verify success.
What is a Certificate Signing Request (CSR)?
A Certificate Signing Request (CSR) is a file that contains your public key and the details of your organization and domain. When Salesforce generates a CSR, it also creates a private key and keeps it in Salesforce. You submit the CSR to the Certificate Authority (CA). The CA uses the CSR to issue your SSL/TLS certificate.
Prerequisites for generating a CSR and installing an SSL/TLS certificate in Salesforce
Before you generate a Certificate Signing Request (CSR) and install an SSL/TLS certificate in Salesforce, make sure that you have the following:
- Salesforce Administrator access.
- An active SSL/TLS certificate order.
- The Fully Qualified Domain Name (FQDN) to be secured, for example, www.example.com(opens in new window).
- Access to the email address that receives the domain validation email for the order.
Generate a CSR in Salesforce
Follow these steps to create a Certificate Signing Request (CSR) and key pair in Salesforce. At the end, you submit the CSR to the Certificate Authority (CA).
- In Salesforce, go to Setup > Certificate and Key Management.
- Click Create CA-Signed Certificate.
Figure 1: Salesforce Certificate and Key Management page with Create CA signed certificate - Enter a Label and a Unique Name for the certificate.
Figure 2 and 3: Label and Unique Name fields completed on the Certificate and Key Edit form - Select a Key Size of 2048 or 4096.
- Complete the certificate details. In Common Name, enter the Fully Qualified Domain Name (FQDN) to be secured. Then enter your company, city, state or province, and country code details.
- Click Save. Salesforce generates the CSR and the key pair.
- On the certificate detail page, click Download Certificate Signing Request.
Figure 5: Certificate detail page with the Download Certificate Signing Request button - Submit the CSR file to the CA with your SSL/TLS certificate order.
Install the signed SSL/TLS certificate in Salesforce
After the Certificate Authority (CA) issues your SSL/TLS certificate, upload it to the same certificate record that you created when you generated the Certificate Signing Request (CSR) in Salesforce.
- Download the issued certificate chain file from the CA.
- In Salesforce, go to Setup > Certificate and Key Management.
- Click the label of the certificate record that you used to generate the CSR.
- Click Upload Signed Certificate.
Figure 6: Certificate detail page with the Upload Signed Certificate button - Click Choose File, select the issued certificate chain file, and click Save.
Figure 7:Upload a Signed Certificate page with the Choose File option
How to verify that the SSL/TLS certificate is installed in Salesforce
To confirm that the SSL/TLS certificate is installed, go to Setup > Certificate and Key Management and open the certificate record. The installation is complete when the certificate status is Active.
Similar questions
- How do I create a CSR in Salesforce?
- How do I upload a signed certificate to Salesforce?
- How do I install a CA-signed certificate in Salesforce Certificate and Key Management?
- What are the steps to install an SSL certificate in Salesforce?
- Salesforce CA-signed certificate setup
Need assistance?
Contact our team for help with your purchase or issuing your certificate.