SAP Knowledge Base Article - Public

2533915 - SAP SuccessFactors SSL Certificate Renewal Schedule and Public Certificate Repository

Symptom

In our ongoing efforts to build and manage transparency with our customers, we are happy to publish our SSL certificate life-cycle in advance to enable your environment with the latest secured SSL certificates. This KB article will be used to consolidate and publish all SSL certificates with their tentative deployment date and public certificate download links.

SSL certificates are used for encrypting files from one point to another; this is mainly used in integrations and file transfers. These digitally bind a cryptographic key to an organization’s details for secure transfer.

Note: The SSL certificate renewal does not impact the BizX Single Sign On (SSO) certificate.

IMPORTANT NOTES

Schedules and Email Notifications

  • The certificate will be attached to this article only 28-30 days prior to expiration.
  • SSL Certificate Renewal Notifications will be published 45 and 30 days prior to the certificate expiration date to remind you of the "call to action".
    This means, you might have received the first email already, but the certificate is still not available. You will receive a second email. And these emails are always sent out to all customers in that domain.
  • We will initiate the deployment process around 15 days prior to the certificate expiration date.
  • You will receive a final notification 7 days prior to the deployment of the certificate.

Uploading the certificate

After downloading the certificate from the Attachments section of this KBA, it should be handed to your internal IT resources. The reason is because the certificate updates are applied on your third-party servers, and this is done by those servers' admins - which is generally deferred to the customers' IT.

SuccessFactors Support team does not possess the specific knowledge required to guide or assist in the installation of these certificates on third-party servers or tools.

FAQ

This article offers an FAQ section with relevant information on this topic. We recommend going through it before opening a support case.

Environment

SAP SuccessFactors HCM Suite

Resolution

Schedule for Updating the SSL Certificates:

Certificate Common NameTentative Deployment DatePublic Certificate Link
   
Current Certificates
jam15.sapsf.cnApril-2025

Certificate Link: Navigate to the Attachments section and download the "jam15.sapsf.cn2026.cer" file

Validity Start Date: 02-Apr-2025

Validity End Date: 04-May-2026

*.sapjam.com

Oct-2025

Certificate Link: Navigate to the Attachments section and download the "sapjam.com2026.cer" file

Validity Start Date: 16-Oct-2025

Validity End Date: 17-Nov-2026 

demodeveloper.sapjam.com

April-2025

Certificate Link: Navigate to the Attachments section and download the "demodeveloper.sapjam.com2026.cer" file

Validity Start Date: 06-Apr-2025

Validity End Date: 08-May-2026

*.sapsf.cn

Part 2 Oct-2025

---------------

Part 1 Apr-2026

Certificate Link: Navigate to the Attachments section and download the "sapsf.cn2026.cer" file

Validity Start Date: 16-Oct-2025 

Validity End Date: 17-Nov-2026 

---------------

Certificate Link: Navigate to the Attachments section and download the "a_sapsf.cn2026.cer" file

Validity Start Date: 12-Dec-2025

Validity End Date: 10-Nov-2026

*.sapsf.com

Part 2 Apr-2025

----------------

Part 1 Apr-2026

Certificate Link: Navigate to the Attachments section and download the "sapsf.com2026.cer" file

Validity Start Date: 02-Apr-2025

Validity End Date: 04-May-2026

---------------

Certificate Link: Navigate to the Attachments section and download the "a_sapsf.com2026.cer" file

Validity Start Date: 24-Nov-2025

Validity End Date: 25-Oct-2026

*.lms.sapsf.cn

Oct-25

Certificate Link: Navigate to the Attachments section and download the ""lms.sapsf.cn2026.cer" file

Validity Start Date: 16-Oct-2025 

Validity End Date: 17-Nov-2026 

*.successfactors.eu

Part 2 Oct-2025

--------------

Part 1 Apr-2026

Certificate Link: Navigate to the Attachments section and download the "successfactors.eu2026.cer" file

Validity Start Date: 16-Oct-2025

Validity End Date: 17-Nov-2026

---------------

Certificate Link: Navigate to the Attachments section and download the "a_successfactors.eu2026.cer" file

Validity Start Date: 3-Nov-2025 

Validity End Date: 15-Sep-2026 

*.successfactors.com

Part 2 Oct-2025

---------------

Part 1 Apr-2026 

Certificate Link: Navigate to the Attachments section and download the "successfactors.com2026.cer" file

Validity Start Date: 16-Oct-2025 

Validity End Date: 17-Nov-2026 

---------------

Certificate Link: Navigate to the Attachments section and download the "a_successfactors.com2026.cer" file

Validity Start Date: 3-Nov-2025 

Validity End Date: 15-Sep-2026 

*.sapsf.eu 

Part 2 Oct-2025

----------------

Part 1 Apr-2026

Certificate Link: Navigate to the Attachments section and download the "sapsf.eu2026.cer" file

Validity Start Date: 16-Oct-2025

Validity End Date: 17-Nov-2026

---------------

Certificate Link: Navigate to the Attachments section and download the "a_sapsf.eu2026.cer" file

Validity Start Date: 05-Jul-2025

Validity End Date: 07-Jul-2026

*.lms.sapsf.com

Oct-25

Certificate Link: Navigate to the Attachments section and download the "lms.sapsf.com2026.cer" file

Validity Start Date: 16-Oct-2025 

Validity End Date: 17-Nov-2026 

plateau.com

Apr-25

Certificate Link: Navigate to the Attachments section and download the "Plateau.com2026.cer" file

Validity Start Date: 02-Apr-2025

Validity End Date: 04-May-2026

*.lms.sapsf.eu 

April-25

Certificate Link: Navigate to the Attachments section and download the "lms.sapsf.eu2026.cer" file

Validity Start Date: 02-April-2025

Validity End Date: 04-May-2026

 

STOP Certificate Pinning

DigiCert has made an announcement on shortening certificate validity to 47 days and the schedule of certificate validity reduction is provided in this article: TLS Certificate Lifetimes Will Officially Reduce to 47 Days | DigiCert

Due to the reduction in cert validity starting March 2026 and hence more frequent certificate renewals we inform that customers, subject to the conditions stated in prior "Important Note" section, should stop certificate pinning and the communication related to the cert update from SuccessFactors and the maintenance of this KBA 2533915 will be discontinued in Dec 2026.

DigiCert recommends that you stop pinning and hard-coding root and ICA certificate acceptance. Stopping these practices makes moving to new ICA certificates or root certificate hierarchies easier.

 

Frequently Asked Questions:

Q: How do I know if I am impacted by the certificate renewal?

A: You will be impacted by the certificate renewal activity, only if:

  • You are using our APIs (SFAPI/Odata API/Adhoc API) and have some integration scenario setup for your SFSF Instance.
    • You can find list of API URLs for all datacenter HERE
  • You are using some middleware (e.g., SAP CPI/HCI/PI/PO/XI or Dell Boomi) for integration setup. Note that for CPI, if you already have SuccessFactors' root certificate installed in your tenant, you won't be impacted.
    • For Boomi, if you are using the SFSF Hosted Cloud atom of the same DC where your instance resides, you need not make any changes. However, if you are using a local atom/Dell Atom Cloud in Boomi to connect to our APIs, you may need to upload the certificates in Boomi.
  • The SuccessFactors API domain for which the certificate is being renewed (e.g., *.successfactors.eu) is same as the domain you are using to access/connect to Successfactors API server using API URL as the endpoint URL.
  • Check KB article 2509971 - FAQs on the impact of SuccessFactors Certificate Renewal if you use APIs (SFAPI/OData API/adHoc API) for more detail.

Note: The certificate update notifications are sent out to all customers as we do not have visibility on who specifically might have external Integrations that require any action for this activity.
Customers will need to check with their internal IT team on what action (if any) might need to be taken from their end, based on their IT landscape. SAP Support does not have visibility & information on such external configurations to advise on the same.

Q: If I pin the new certificate, do I need to install the intermediate certificate?

A: Yes, if this is the first time installing a certificate. Navigate to the Attachments section and download the "DigiCertCA_G2_Chain_Apr2024.cer" or "DigiCertCA_G5_Chain.cer" and install the new Intermediate.

Q: Why do I need to install the intermediate certificate?

A: When installing a Digicert SSL certificate, it is essential to install the correct Intermediate CA at the same time as the SSL certificate. This ensures that the SSL certificate is fully trusted by all browsers and client computers which prevents errors from appearing when users visit a secure website.

Q: How do I download or install the certificate?

A: You must have admin access to the server where you need to install the certificate. If you do not have access to your company's SSL server, notify your IT team and provide them the respective certificate download link from the above table. For SuccessFactors certificates in CPI landscape, you can follow KBA  2776681 - How to maintain SuccessFactors certificates in CPI landscape - Cloud Platform Integration”

Q: I notice a discrepancy in the validity start date and end date mentioned in this knowledge article table and my downloaded certificate. What does this indicate?

A: Sometimes, due to time zone difference, you may see a different date in the downloaded certificate. There is no impact on the certificate update activity due to this. You will be renewing the certificate well in advance, before the certificate expiry date. You will receive a final notification 7 days prior to the deployment of the certificate.

Q: When should I renew the certificates?

A: It is recommended to renew the certificates soon after they are available. Note that you can maintain both the "old" certificate and the new one at the same time on your middleware storage. This way you won't face any issues when the change occur. However, please note the "old" certificate should only be removed after the Tentative Deployment date of the certificate as per the above table and as per date informed in the e-mail notification you receive.

Q: Why does the new certificate appear in the following year list?

A: On the day it is renewed it is added to the following year list and the old certificate is removed from the current year list. We only want to have a single certificate available for download at any given time.

Q: Where do the certificates get applied and who performs the update?
A: The certificate updates are applied on your third-party servers, see image below and this is done by those server's admins which is generally deferred to the customer's IT.

KBA 2533915 1.png

Q: What if my system is migrated to CSD and uses new domain , do we need to renew SSL certs for new domain ?

No SSL cert changes required if the instance is migrated to CSD (new domain).

Only exception is API servers still use old domains. So if the customer is using the SSL certs in the context of SF API usage, then they should update them and there is an action to update SSL certs in new domain as well.

Communications specific to the following domains: *.sapsf.cn / *.sapsf.com / *.sapsf.eu / *.successfactors.com / *.successfactors.eu

Q: I have received a Part 1 of 2 and/or Part 2 of 2 communication in relation to certificate renewals – why is this and do I need to install both?
A: This is a short-term measure due to an internal change in the SAP SuccessFactors Network. Until further notice, both certificates are required.

Q: Will the certificate deployment process change?
A: No. The process remains the same as for previous certificates, the only change is that, until further notice, there will be two certificates to install (1 of 2 and 2 of 2).

Q: How will these part 1 of 2 and 2 of 2 be reflected in the above schedule?
A: Please expect the following format and naming convention (*dates and domain are used for illustration purposes only*):

KBA 2533915 2.png

Q: Are there any impacts on OAuth 2.0 Authentication? 
A: No impacts.

Q: Are there any impacts in the IPS ClientCertificate Authentication?
A: No impacts

See Also

2509971 - FAQ on the impact of SuccessFactors Certificate Renewal if you use APIs (SFAPI and OData API) - SAP for Me

3706897 - SAP SuccessFactors HCM SSL Certificate DigiCert Global Root G2 CA change to "DigiCert TLS RSA4096 Root G5" – Bizx , LMS , RMK CDN URLS - SAP for Me

Keywords

SF, success factors, BizX, biz x, cloud, PLT, platform, certificate renewal, renewal, repositoy, certificate repository , KBA , LOD-SF-PLT-PSI , Product Security Inquiries , LOD-SF-INT , Integrations , LOD-SF-LMS , Learning Management System , How To

Product

SAP SuccessFactors HCM Suite all versions

Attachments

a_sapsf.cn2024.cer
DigiCertCA_G2_Chain_Apr2024.cer
Jam15.sapsf.cn2026.cer
demodeveloper.sapjam.com2026.cer
Plateau.com2026.cer
sapsf.com2026.cer
lms.sapsf.eu2026.cer
cubetree.com2023.cer
a_sapsf.eu2026.cer
lms.sapsf.com2026.cer
sapjam.com2026.cer
successfactors.com2026.cer
successfactors.eu2026.cer
sapsf.eu2026.cer
sapsf.cn2026.cer
lms.sapsf.cn2026.cer
a_successfactors.com2026.cer
a_successfactors.eu2026.cer
a_sapsf.com2026.cer
a_sapsf.cn2026.cer
DigiCertCA_G5_Chain.cer