October 28th, 2024

Announcement

Infrastructure

Connector Certificate Chain changes

This announcement is only applicable to customers that are using our SOAP interface.

Effective March 2025, renewed Connector certificates do not contain Starfield C2 (subject C=US, O=Starfield Technologies, Inc., OU=Starfield Class 2 Certification Authority) in its certificate chain. This could impact TLS connections if your TLS-initiating applications only trust Starfield C2.

Only if you have customised your TLS-initiating application to only trust Starfield C2, you will need to update your trust stores to trust all Amazon CAs instead. Otherwise your application will fail to initiate a TLS connection with the connector.

As a best practice, it is also strongly recommended to not pin your trust to a certificate that you don’t completely own such as certificates for Colect service endpoints. You can read OWASP guidance on certificate pinning.