SAP Knowledge Base Article - Public

2533915 - SAP SuccessFactors SSL Certificate Renewal Schedule and Public Certificate Repository

Symptom

In our ongoing efforts to build and manage transparency with our customers, we are happy to publish our SSL certificate life-cycle in advance to enable your environment with the latest secured SSL certificates. This KB article will be used to consolidate and publish all SSL certificates with their tentative deployment date and public certificate download links.

SSL certificates are used for encrypting files from one point to another; this is mainly used in integrations and file transfers. These digitally bind a cryptographic key to an organization’s details for secure transfer.

Note: The SSL certificate renewal does not impact the BizX Single Sign On (SSO) certificate.

IMPORTANT NOTES

Schedules and Email Notifications

  • The certificate will be attached to this article only 28-30 days prior to expiration.
  • SSL Certificate Renewal Notifications will be published 45 and 30 days prior to the certificate expiration date to remind you of the "call to action".
    This means, you might have received the first email already, but the certificate is still not available. You will receive a second email. 
  • We will initiate the deployment process around 15 days prior to the certificate expiration date.
  • You will receive a final notification 7 days prior to the deployment of the certificate.

Uploading the certificate

After downloading the certificate from the Attachments section of this KBA, it should be handed to your internal IT resources. The reason is because the certificate updates are applied on your third-party servers, and this is done by those servers' admins - which is generally deferred to the customers' IT.

SuccessFactors Support team does not possess the specific knowledge required to guide or assist in the installation of these certificates on third-party servers or tools.

FAQ

This article offers an FAQ section with relevant information on this topic. We recommend going through it before opening a support case.

Environment

SAP SuccessFactors HXM Suite

Resolution

Schedule for Updating the SSL Certificates:

Certificate Common Name Tentative Deployment Date Public Certificate Link
Certificates Expiring in 2024 (deployed in 2023)
jam15.sapsf.cn Mar-2024

Certificate Link: Navigate to the Attachments section and download the "jam15.sapsf.cn2025.cer" file

Validity Start Date: 27-Mar-2024

Validity End Date: 28-Apr-2025

*.sapjam.com

Feb-2024

Certificate Link: Navigate to the Attachments section and download the "sapjam.com2025.cer" file

Validity Start Date: 27-Feb-2024

Validity End Date: 30-Mar-2025

demodeveloper.sapjam.com

Jun-2023

Certificate Link: Navigate to the Attachments section and download the "demodeveloper.sapjam.com2024.cer" file

Validity Start Date: 22-June-2023

Validity End Date: 25-June-2024

*.sapsf.cn

Part 1 Feb-2024

---------------

Part 2 Feb-2024

Certificate Link: Navigate to the Attachments section and download the "sapsf.cn2025.cer" file

Validity Start Date: 27-Feb-2024

Validity End Date: 30-Mar-2025

Certificate Link: Navigate to the Attachments section and download the "a_sapsf.cn2025.cer" file

Validity Start Date: 27-Feb-2024

Validity End Date: 26-Feb-2025

*.sapsf.com

Part 2 Jun-2023

----------------

Part 1 Jan-2024

Certificate Link: Navigate to the Attachments section and download the "sapsf.com2024.cer" file

Validity Start Date: 15-June-2023

Validity End Date: 18-June-2024

Certificate Link: Navigate to the Attachments section and download the "a_sapsf.com2024.cer" file

Validity Start Date: 29-Jan-2024

Validity End Date: 31-Jan-2025

*.lms.sapsf.cn

Jan-24

Certificate Link: Navigate to the Attachments section and download the ""lms.sapsf.cn2025.cer" file

Validity Start Date: 22-Jan-2024

Validity End Date: 22-Feb-2025

*.successfactors.eu

Part 2 Feb-2024

--------------

Part 1 Dec-2023

Certificate Link: Navigate to the Attachments section and download the "successfactors.eu2025.cer" file

Validity Start Date: 27-Feb-2024

Validity End Date: 30-Mar-2025

Certificate Link: Navigate to the Attachments section and download the "a_successfactors.eu2025.cer" file

Validity Start Date: 28-Dec-2023

Validity End Date: 27-Dec-2024

*.successfactors.com

Part 1 Feb-2025

---------------

Part 2 Dec-2024

Certificate Link: Navigate to the Attachments section and download the "successfactors.com2025.cer" file

Validity Start Date: 4-Jan-2024

Validity End Date: 4-Feb-2025

Certificate Link: Navigate to the Attachments section and download the "a_successfactors.com2025.cer" file

Validity Start Date: 26-Dec-2023

Validity End Date: 27-Dec-2024

*.sapsf.eu 

Part 2 Feb -2024

----------------

Part 1 Nov-2023

Certificate Link: Navigate to the Attachments section and download the "sapsf.eu2025.cer" file

Validity Start Date: 27-Feb-2024

Validity End Date: 30-Mar-2025

Certificate Link: Navigate to the Attachments section and download the "a_sapsf.eu2024.cer" file

Validity Start Date: 21-Nov-2023

Validity End Date: 19-Oct-2024

*.lms.sapsf.com

Mar-24

Certificate Link: Navigate to the Attachments section and download the "lms.sapsf.com2025.cer" file

Validity Start Date: 27-Mar-2024

Validity End Date: 28-Apr-2025

plateau.com

Jun-23

Certificate Link: Navigate to the Attachments section and download the "plateau.com2024.cer" file

Validity Start Date: 14-May-2023

Validity End Date: 14-May-2024

*.lms.sapsf.eu 

Nov-23

Certificate Link: Navigate to the Attachments section and download the "lms.sapsf.eu2024.cer" file 

Validity Start Date: 5-Nov-2023

Validity End Date: 5-Nov-2024

Frequently Asked Questions:

Q: How do I know if I am impacted by the certificate renewal?

A: You will be impacted by the certificate renewal activity, only if:

  • You are using our APIs (SFAPI/Odata API/Adhoc API) and have some integration scenario setup for your SFSF Instance.
    • You can find list of API URLs for all datacenter HERE
  • You are using some middleware (e.g., SAP CPI/HCI/PI/PO/XI or Dell Boomi) for integration setup. Note that for CPI, if you already have SuccessFactors' root certificate installed in your tenant, you won't be impacted.
    • For Boomi, if you are using the SFSF Hosted Cloud atom of the same DC where your instance resides, you need not make any changes. However, if you are using a local atom/Dell Atom Cloud in Boomi to connect to our APIs, you may need to upload the certificates in Boomi.
  • The Successfators API domain for which the certificate is being renewed (e.g., *.successfactors.eu) is same as the domain you are using to access/connect to Successfactors API server using API URL as the endpoint URL.
  • Check KB article 2509971 - FAQs on the impact of SuccessFactors Certificate Renewal if you use APIs (SFAPI/OData API/adHoc API) for more detail.

Q: If I pin the new certificate, do I need to install the intermediate certificate?

A: Yes, if this is the first time installing a certificate. Navigate to the Attachments section and download the "DigiCertCA_Chain_2020.cer" or "DigiCertCA_Chain_Jun2021.cer" and install the new Intermediate. All certificates with a validity date starting after June 9 2021 will use the "DigiCertCA_Chain_Jun2021.cer" chain.

NOTE: a new intermediate cert was included Feb 2021 as it was updated at the end of 2020 by the CA. This was updated again June 9th 2021 without warning. It was included here after communication from the CA on June 15.

Q: Why do I need to install the intermediate certificate?

A: When installing a Digicert SSL certificate, it is essential to install the correct Intermediate CA at the same time as the SSL certificate. This ensures that the SSL certificate is fully trusted by all browsers and client computers which prevents errors from appearing when users visit a secure website.

Q: How do I download or install the certificate?

A: You must have admin access to the server where you need to install the certificate. If you do not have access to your company's SSL server, notify your IT team and provide them the respective certificate download link from the above table. For SuccessFactors certificates in CPI landscape, you can follow KBA  2776681 - How to maintain SuccessFactors certificates in CPI landscape - Cloud Platform Integration”

Q: I notice a discrepancy in the validity start date and end date mentioned in this knowledge article table and my downloaded certificate. What does this indicate?

A: Sometimes, due to time zone difference, you may see a different date in the downloaded certificate. There is no impact on the certificate update activity due to this. You will be renewing the certificate well in advance, before the certificate expiry date. You will receive a final notification 7 days prior to the deployment of the certificate.

Q: When should I renew the certificates?

A: It is recommended to renew the certificates soon after they are available. Note that you can maintain both the "old" certificate and the new one at the same time on your middleware storage. This way you won't face any issues when the change occur. However, please note the "old" certificate should only be removed after the Tentative Deployment date of the certificate as per the above table and as per date informed in the e-mail notification you receive.

Q: Why does the new certificate appear in the following year list?

A: On the day it is renewed it is added to the following year list and the old certificate is removed from the current year list. We only want to have a single certificate available for download at any given time.

Q: Where do the certificates get applied and who performs the update?
A: The certificate updates are applied on your third-party servers, see image below and this is done by those servers's admins which is generally deferred to the customer's IT.

KBA 2533915 1.png

Q: What if my system is not in the domain of the certificate being renewed?
A: For the following domains:

   SAPSF.EU
   SAPSF.COM
   SUCCESSFACTORS.EU
   SUCCESSFACTORS.COM

It is possible to have instances in multiple of these domains. Example: Communication for sapsf.eu contains instance with sapsf.eu and successfactors.eu. In this case there is no action needed for the successfactors.eu instance.


Communications specific to the following domains: *.sapsf.cn / *.sapsf.com / *.sapsf.eu / *.successfactors.com / *.successfactors.eu  
Q1: I have received a Part 1 of 2 and/or Part 2 of 2 communication in relation to certificate renewals – why is this and do I need to install both?
A1: This is a short-term measure due to an internal change in the SAP SuccessFactors Network. Until further notice, both certificates are required.

Q3: Will the certificate deployment process change?
A3: No. The process remains the same as for previous certificates, the only change is that, until further notice, there will be two certificates to install (1 of 2 and 2 of 2).

Q4: How will these part 1 of 2 and 2 of 2 be reflected in the above schedule?
A4: Please expect the following format and naming convention (*dates and domain are used for illustration purposes only*):

KBA 2533915 2.png

See Also

2509971 - FAQ on the impact of SuccessFactors Certificate Renewal if you use APIs (SFAPI and OData API) - SAP for Me

Keywords

SF, success factors, BizX, biz x, cloud, PLT, platform, certificate , KBA , LOD-SF-PLT-PSI , Product Security Inquiries , LOD-SF-INT , Integrations , LOD-SF-LMS , Learning Management System , How To

Product

SAP SuccessFactors HCM all versions

Attachments

plateau.com2024.cer
a_sapsf.cn2024.cer
sapsf.com2024.cer
demodeveloper.sapjam.com2024.cer
DigiCertCA_Chain_Jun2021.cer
cubetree.com2023.cer
lms.sapsf.eu2024.cer
a_sapsf.eu2024.cer
a_successfactors.com2025.cer
successfactors.com2025.cer
a_successfactors.eu2025.cer
lms.sapsf.cn2025.cer
a_sapsf.com2024.cer
sapsf.eu2025.cer
successfactors.eu2025.cer
sapsf.cn2025.cer
sapjam.com2025.cer
a_sapsf.cn2025.cer
DigiCertCA_G2_Chain_Apr2024.cer
lms.sapsf.com2025.cer
jam15.sapsf.cn2025.cer