Skip to main content

Updating Encryption and Signing Certificates

AS2 Partner Certificates are the certificates exchanged between you and your trading partners for message encryption and digital signing. Plan certificate renewal with each partner so both systems use matching certificates and keys when the change takes effect.

Files.com manages renewal of the default HTTPS endpoint certificate that secures your AS2 URL. If you supply your own TLS/SSL certificate for a custom domain, you are responsible for replacing it before it expires.

Coordinate changes to corresponding certificates and keys on both sides of the partnership to minimize communication outages.

For example, when you replace your certificate and private key, your trading partner applies your new public certificate at the same time. When your trading partner replaces their certificate and private key, you apply their updated public certificate at the agreed time.

You do not need to update your own certificates when a trading partner's certificate expires, and vice versa. You only need to update and exchange the corresponding portions of the expiring certificate.

Coordinate with your trading partner before a certificate's expiration and agree on a change window for applying the updated certificates.

When a test or dev site is available to you, test and verify any certificate changes on the AS2 configuration of that site before applying them to your production site. You can also use a test or dev AS2 partnership connection, where you and your trading partner have agreed upon test or dev AS2 Identities for testing purposes.

Updating Your AS2 Identity Certificate

When replacing the certificate associated with your AS2 Identity, exchange the public portion of your new certificate with every trading partner connected to that AS2 Identity. Confirm each partner's renewal requirements and schedule before making the change, since their systems determine whether to accept your certificate and signatures.

Edit your AS2 identity to generate a new certificate using our online generator, or generate one using the openssl command and then import it.

Export the public portion of the new certificate and send it to all trading partners that are associated with this AS2 Identity. As this portion is public, it can be sent or shared via email or secure Share Link.

Updating a Trading Partner's AS2 Certificate

The expiration date shown in the AS2 Trading Partners table helps you plan renewal with your partner. At the Normal incoming signature validation level, including when Auto selects Normal, Files.com verifies signatures against the configured partner certificate without checking its chain, signing purpose, or validity dates. A certificate that is expired or not yet valid can still validate incoming signatures as long as it remains configured. This prevents a certificate date from interrupting business exchanges while both teams coordinate a replacement.

Normal still requires a valid signature from the configured partner certificate and unchanged signed content. It rejects unsigned messages and messages signed with a different key. Certificate expiration does not end acceptance of the configured signing key.

To stop accepting incoming messages from a partner, delete their trading partner configuration. To continue the partnership with a different signing key, replace the configured public certificate with one for the new key and keep incoming signature validation set to Normal. Coordinate the replacement with your partner because Files.com also uses this certificate to encrypt outgoing messages to them.

For a planned renewal, import the partner's new public certificate into their Trading Partner configuration during the agreed change window.

Contact your trading partner and ask them to provide their updated public certificate in PEM or CRT format. A PEM or CRT format certificate begins with -----BEGIN CERTIFICATE----- and ends with -----END CERTIFICATE-----. As this portion is public, it can be sent or shared via email or secure Share Link.