1
Certificate Authority
Generate the self-signed CA (CN = staging hostname), or import an existing one to keep issuing client certificates against it.
2
Register the CA in eCDN
The platform only accepts client certificates signed by a CA you've registered. Pick one path:
- Log in to Business Manager on the staging instance: …
- Go to Administration > Site Development > Code Upload Certificate (tab).
- Click Add Certificate.
- Certificate Name: any internal label, e.g. …
- Paste the CA files generated in step 1 — the full contents of ….crt into Certificate and ….key into Private Key (plain PEM — not the JSON-escaped version), then Save. Use the buttons below to copy them directly, or open the files downloaded in step 1.
- The CA appears in the list. Multiple CAs can be active at once — leave old ones in place until all users have rotated, then delete them here.
3
Pipeline & client certificates
…
…
Wire it into the pipeline
- Secrets to create: SFCC_P12_B64 (use the Copy base64 button on the cert above), SFCC_P12_PASS, SFCC_CLIENT_ID, SFCC_CLIENT_SECRET. Never commit the .p12.
- Host: https://… — never cert.staging.*.
- Rotation: every cert dies with the CA on …. The snippets below include a 14-day expiry guard so the pipeline fails loudly before the cert does.
- Developers (manual uploads): Prophet/VS Code dw.json → "p12": "./<user>.p12", "passphrase": "…"; Cyberduck → import .p12 into Keychain.
GitHub Actions — deploy step
Jenkins — declarative stage
Connect upload tools (Prophet, Cyberduck, sfcc-ci, CI/CD) to https://… with the .p12.