OVERVIEW
SAP Concur is renewing SSL/TLS certificates for *.api.concursolutions.com on US2, EU2, and APJ1 data centers on November 10, 2026, as part of industry-wide PKI security improvements driven by DigiCert. Customers who have pinned leaf or end-entity certificates must take action before this date to avoid service disruption.
If your organization has built integrations with SAP Concur APIs and those integrations rely on pinned SSL certificates, upcoming changes to our certificate infrastructure require your attention before November 10, 2026.
DigiCert, our Certificate Authority, is implementing industry-wide changes that reduce maximum SSL/TLS certificate validity periods to 199 days and remove Client Authentication from publicly trusted server certificates and two shifts that affect how SAP Concur manages and renews its certificates going forward.
We are renewing the *.api.concursolutions.com certificate ahead of its current expiry as part of our preparation for the broader DigiCert Global Root G5 migration, and this is an opportunity to ensure your integrations are built to handle more frequent renewals gracefully. Understanding what is changing and taking the right steps now will protect the continuity of your Concur integrations.
WHAT'S CHANGING
- SAP Concur is renewing the SSL certificate for *.api.concursolutions.com on November 10, 2026, ahead of its current expiry date of February 23, 2027 at 23:59 GMT, as part of preparation for the DigiCert Global Root G5 migration.
- DigiCert is reducing the maximum validity period for all publicly trusted SSL/TLS certificates to 199 days in 2026, with further reductions planned to 100 days in 2027 and 47 days in 2029, meaning SAP Concur certificates will be rotated significantly more often than in the past.
- Because renewal cycles will become too short to manage with advance notifications, SAP Concur will no longer provide advance announcements for leaf certificate renewals after this cycle. Changes to Intermediate or Root CA certificates will continue to be announced in advance.
- DigiCert is removing the Client Authentication (Client Auth) Extended Key Usage from publicly trusted SSL/TLS server certificates. This change has no impact on SAP Concur services, as client authentication is not used on SAP Concur server SSL certificates.
- Certificate pinning at the leaf or end-entity level is strongly discouraged going forward. Because certificates will now rotate too frequently to manage manually, any integration that pins a leaf certificate will experience repeated service disruptions unless it is updated to pin at the Intermediate or Root CA level.
- For this renewal, the Root and Intermediate certificates remain unchanged. The current chain uses DigiCert Global G2 TLS RSA SHA256 2020 CA1 and DigiCert Global Root G2 for RSA, and DigiCert Global G3 TLS ECC SHA384 2020 CA1 and DigiCert Global Root G3 for ECDSA. These will shift to the G5 chain in April 2027.
ADVANCED NOTICE
- SAP Concur will migrate all public certificates to the DigiCert Global Root G5 chain beginning April 2027. Customers who pin certificates must add both the new RSA root (DigiCert TLS RSA4096 Root G5) and ECC root (DigiCert TLS ECC P384 Root G5) to their trust stores before that migration date. A separate communication will be issued to cover the impact for all our customers and a new community post will be made available soon.
WHO IS AFFECTED
- This update affects SAP Concur customers hosted on the US2, EU2, and APJ1 data centers. The change is specifically relevant to IT administrators, integration owners, and developers who manage API integrations with SAP Concur and who have implemented SSL certificate pinning in those integrations.
- Customers who have not pinned certificates do not need to take any action.
- Authorized Support Contacts and Notice Contacts at affected organizations are the primary recipients of this notification.
TIMELINE
- October 7, 2026: Customer emails has been distributed to Authorized Support Contacts.
- November 10, 2026 at 22:00 PDT: Target implementation date for the SSL certificate renewal for *.api.concursolutions.com.
- February 23, 2027 at 23:59 GMT: Original expiry date of the current *.api.concursolutions.com certificate (renewal is being completed early).
- April 2027: SAP Concur begins migrating all public certificates to the DigiCert Global Root G5 chain. Customers must have G5 root certificates added to their trust stores before this date.
- 2027: DigiCert plans to further reduce maximum certificate validity to 100 days.
- 2029: DigiCert plans to further reduce maximum certificate validity to 47 days.
ACTION REQUIRED
- Most customers do not pin certificates and do not need to take any action as the certificate renewal will happen automatically with no impact to service.
- If your integration pins the leaf or end-entity SSL certificate, you must migrate to pinning the Intermediate or Root CA certificate before November 10, 2026 to avoid service disruption.
- If you are unable to complete that migration before the renewal date, contact SAP Concur Support for assistance as soon as possible.
- To prepare for the April 2027 DigiCert Global Root G5 migration, all customers who pin certificates should add both the DigiCert TLS RSA4096 Root G5 and DigiCert TLS ECC P384 Root G5 root certificates to their trust stores now.
- Customers pinning both RSA and ECDSA certificates must ensure they pin both certificate types to avoid disruption.
Note: If you are not the person who manages integrations for your organization, please forward this information to the appropriate technical contact.
For full technical details, certificate download links, and step-by-step guidance on updating your trust stores, please refer to the SAP Concur Release Notes for this update. If you have questions about how these changes affect your specific integration setup, reach out to SAP Concur Support or contact your account team for tailored assistance. We encourage all customers with certificate pinning in place to act well ahead of the November 10, 2026 renewal date and to begin preparing for the April 2027 G5 root migration as early as possible.