Skip to content

Commit ac9f695

Browse files
[skip ci] Updates
1 parent 49b981b commit ac9f695

2 files changed

Lines changed: 165 additions & 2 deletions

File tree

feed.xml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,8 @@
55
<description>Concur docs provides comprehensive information on working with the Concur platform</description>
66
<link>https://preview.developer.concur.com/</link>
77
<atom:link href="https://preview.developer.concur.com/feed.xml" rel="self" type="application/rss+xml" />
8-
<pubDate>Thu, 26 Mar 2026 22:33:53 +0000</pubDate>
9-
<lastBuildDate>Thu, 26 Mar 2026 22:33:53 +0000</lastBuildDate>
8+
<pubDate>Tue, 31 Mar 2026 19:29:04 +0000</pubDate>
9+
<lastBuildDate>Tue, 31 Mar 2026 19:29:04 +0000</lastBuildDate>
1010
<generator>Jekyll v4.1.1</generator>
1111

1212
</channel>

tools-support/release-notes/api/2026-03-03.html

Lines changed: 163 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -429,6 +429,169 @@ <h1 id="api-release-notes-march-2026">API Release Notes, March 2026</h1>
429429

430430
<h2 id="new-this-month">New This Month</h2>
431431

432+
<h3 id="preview-ssl-certificates-renewal-for-concursolutionscom-and-apiconcursolutionscom">Preview: SSL Certificates Renewal for <code class="language-plaintext highlighter-rouge">*.concursolutions.com</code> and <code class="language-plaintext highlighter-rouge">*api.concursolutions.com</code></h3>
433+
434+
<p>Due to industry-wide changes implemented by our Certificate Authority, DigiCert, the maximum validity period for publicly trusted TLS certificates has been reduced to 199 days. As a result, SAP Concur certificates will be renewed more frequently than in previous years. SAP Concur plans to renew the certificates for <code class="language-plaintext highlighter-rouge">*.concursolutions.com</code> and <code class="language-plaintext highlighter-rouge">*api.concursolutions.com</code> in May 2026.</p>
435+
436+
<p>Additional information about the 199-day certificate validity period is available in the documentation provided by <a href="https://knowledge.digicert.com/alerts/sunsetting-client-authentication-eku-from-digicert-public-tls-certificates">DigiCert</a>.</p>
437+
438+
<blockquote>
439+
<p>Note: This change is part of broader security improvements across the industry and has no impact on the security, availability, or trust of SAP Concur services.</p>
440+
</blockquote>
441+
442+
<p><strong>End-User Experience</strong></p>
443+
444+
<p>The current certificates will expire as follows:</p>
445+
446+
<ul>
447+
<li>
448+
<p>June 4, 2026 23:59 GMT for <code class="language-plaintext highlighter-rouge">*.api.concursolutions.com</code></p>
449+
</li>
450+
<li>
451+
<p>June 5, 2026 23:59 GMT for <code class="language-plaintext highlighter-rouge">*.concursolutions.com</code></p>
452+
</li>
453+
</ul>
454+
455+
<p>SAP Concur will renew it ahead of this date to ensure continued service availability.</p>
456+
457+
<p>New certificates are planned to be issued as follows:</p>
458+
459+
<ul>
460+
<li>
461+
<p>10PM PDT on May 13 2026 for <code class="language-plaintext highlighter-rouge">*.api.concursolutions.com</code></p>
462+
</li>
463+
<li>
464+
<p>10PM PDT on May 20, 2026 for <code class="language-plaintext highlighter-rouge">*.concursolutions.com</code></p>
465+
</li>
466+
</ul>
467+
468+
<p><strong>Certificate Updates</strong>
469+
As a part of this renewal, the following updates will be introduced:</p>
470+
471+
<p><code class="language-plaintext highlighter-rouge">*.api.concursolutions.com</code></p>
472+
473+
<ul>
474+
<li>
475+
<p>As part of the recent DigiCert account migration from SAP Concur to SAP, the <strong>organization information</strong> associated with *.api.concursolutions.com certificates has been updated. For details, please refer to the <strong>Certificates Download Links</strong> section below.</p>
476+
</li>
477+
<li>
478+
<p>This change affects only the certificate metadata and does not impact service functionality or security.</p>
479+
</li>
480+
</ul>
481+
482+
<p><code class="language-plaintext highlighter-rouge">*.concursolutions.com</code></p>
483+
484+
<ul>
485+
<li>
486+
<p>The Client Authentication extended key usage has been removed from the certificate.</p>
487+
</li>
488+
<li>
489+
<p>This extension was not used as the certificate functions as a TLS server certificate for server authentication only. Its removal does not impact service functionality.</p>
490+
</li>
491+
<li>
492+
<p>For additional information on certificate extended key usage, please refer to the documentation from <a href="https://knowledge.digicert.com/alerts/sunsetting-client-authentication-eku-from-digicert-public-tls-certificates">DigiCert</a>.</p>
493+
</li>
494+
</ul>
495+
496+
<p><strong>Certificate Pinning Guidance</strong></p>
497+
498+
<p>Clients who have not pinned the expiring certificate do not need to take any action as their expiring certificate will be renewed automatically. <strong>Most clients do not pin the certificate</strong>.</p>
499+
500+
<p>SAP ICS customers who follow the certificate handling processes described in the following note do not need to take any action:</p>
501+
502+
<p><a href="https://launchpad.support.sap.com/#/notes/2914977">2914977 - FAQ: Concur Certificates, Authentication, and Connectivity</a>.</p>
503+
504+
<p>Clients who have pinned an expiring certificate must update to the new certificate before it is issued at</p>
505+
506+
<ul>
507+
<li>
508+
<p>10PM PDT on May 13 2026 <code class="language-plaintext highlighter-rouge">*.api.concursolutions.com</code></p>
509+
</li>
510+
<li>
511+
<p>10PM PDT May 20, 2026 <code class="language-plaintext highlighter-rouge">*.concursolutions.com</code></p>
512+
</li>
513+
</ul>
514+
515+
<blockquote>
516+
<p>Note: Certificate pinning is not recommended, and you do so at your own risk.
517+
To support security for SAP Concur solutions, security certificates are renewed regularly. Pinned certificates are not renewed automatically and, if a pinned certificate is not renewed before it expires, the pinned certificate can cause a disruption of service.</p>
518+
</blockquote>
519+
520+
<blockquote>
521+
<p>Recommendation: If your implementation requires certificate pinning, we strongly recommend pinning the Root CA certificate, rather than the leaf/end certificate.
522+
Pinning the leaf/end certificate may result in service disruption due to the shorter renewal cycle. Pinning to the Root CA provides greater stability while maintaining security.</p>
523+
</blockquote>
524+
525+
<p><strong>Certificate Download Links</strong></p>
526+
527+
<p>To avoid disruption of service, clients who pin their security certificates must pin both the RSA and ECDSA certificates. Clients may obtain the new certificates from the following web pages.</p>
528+
529+
<p>These are <strong>root and intermediate certificates</strong> for both <code class="language-plaintext highlighter-rouge">*.concursolutions.com</code> and <code class="language-plaintext highlighter-rouge">*.api.concursolutions.com</code>.</p>
530+
531+
<p><strong>RSA Certificates Download Links</strong></p>
532+
533+
<ul>
534+
<li>
535+
<p>Intermediate: <a href="https://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crt.pem?_gl=1*i7c9wi*_gcl_au*MTI2NjY3MzYyMC4xNzMyNTAwNTAw">DigiCert Global G2 TLS RSA SHA256 2020 CA1</a></p>
536+
</li>
537+
<li>
538+
<p>Root: <a href="https://cacerts.digicert.com/DigiCertGlobalRootG2.crt.pem?_gl=1*102cn1j*_gcl_au*MTI2NjY3MzYyMC4xNzMyNTAwNTAw">DigiCert Global Root G2</a></p>
539+
</li>
540+
</ul>
541+
542+
<p><strong>ECDSA Certificates Download Links</strong></p>
543+
544+
<ul>
545+
<li>
546+
<p>Intermediate: <a href="https://cacerts.digicert.com/DigiCertGlobalG3TLSECCSHA3842020CA1-2.crt.pem?_gl=1*htixu2*_gcl_au*MTY5MjI4Mjk2Ni4xNzQzOTg1ODYz">DigiCert Global G3 TLS ECC SHA384 2020 CA1</a></p>
547+
</li>
548+
<li>
549+
<p>Root: <a href="https://cacerts.digicert.com/DigiCertGlobalRootG3.crt.pem?utm_medium=organic&amp;utm_source=google&amp;referrer=https://www.google.com/&amp;_gl=1*1ouisuk*_gcl_au*MTUwNDgyOTI5OS4xNzQxMjQ2NDEy">DigiCert Global Root G3</a></p>
550+
</li>
551+
</ul>
552+
553+
<p><strong>Certificate Chain</strong> consists of end-entity, Intermediate and Root certificates respectively.</p>
554+
555+
<p>When opening the following links, open the link in an Incognito or Private browser window to ensure there is no cached data causing outdated or incorrect content to appear.</p>
556+
557+
<p><strong>*.api.concursolutions.com</strong></p>
558+
559+
<ul>
560+
<li>
561+
<p>https://assets.concur.com/concurtraining/cte/en-us/api-concursolutions-com-chain_ECDSA.pem</p>
562+
</li>
563+
<li>
564+
<p>https://assets.concur.com/concurtraining/cte/en-us/api-concursolutions-com-chain_RSA.pem</p>
565+
</li>
566+
</ul>
567+
568+
<blockquote>
569+
<p>Note: For <code class="language-plaintext highlighter-rouge">*.api.concursolutions.com</code> organization change, the changes are as follows:
570+
From:
571+
<code class="language-plaintext highlighter-rouge">subject: C=US, ST=Washington, L=Bellevue, O=Concur Technologies, Inc.,</code>
572+
To:
573+
<code class="language-plaintext highlighter-rouge">subject=C=DE, ST=Baden-Württemberg, L=Walldorf, O=SAP SE</code>
574+
This is an internal administrative change and does not affect certificate validity or functionality. 
575+
The certificate used for <strong>*.api.concursolutions.com</strong> currently retains a <strong>one-year validity period</strong>, as it was renewed prior to the certificate validity policy change implemented by DigiCert. Future renewals will follow the updated validity requirements.</p>
576+
</blockquote>
577+
578+
<p><strong>*.concursolutions.com</strong></p>
579+
580+
<ul>
581+
<li>
582+
<p>https://assets.concur.com/concurtraining/cte/en-us/concursolutions-com-chain_ECDSA.pem</p>
583+
</li>
584+
<li>
585+
<p>https://assets.concur.com/concurtraining/cte/en-us/concursolutions-com-chain_RSA.pem</p>
586+
</li>
587+
</ul>
588+
589+
<p>You can access and test the certificates by following the instructions in <a href="https://help.sap.com/docs/SAP_CONCUR/c5d6d15e7ecb4b4d8238b383d59ac2f4/8beb587dbf2841b099fd907106ddcef8.html?version=2026_03&amp;locale=en-US">Concur Shared Release Notes</a>.</p>
590+
591+
<p><strong>Configuration / Feature Activation</strong></p>
592+
593+
<p>If you are not sure whether your SSL certificate is pinned, please consult with your IT department.</p>
594+
432595
<h3 id="now-available-api-deprecation-headers">Now Available: API Deprecation Headers</h3>
433596

434597
<p>For APIs in deprecation, responses will include an <code class="language-plaintext highlighter-rouge">x-api-warn</code> header that identifies the deprecated endpoint and its recommended replacement. A sunset header will specify the planned decommission date and include a link to additional deprecation details, in compliance with SAP API policies. This has been applied to both API and UI gateways. For example:</p>

0 commit comments

Comments
 (0)