CloudSOC CASB Gateway

 View Only
Expand all | Collapse all

Salesforce Securlet Token Authentication Broken due to sandbox refresh

  • 1.  Salesforce Securlet Token Authentication Broken due to sandbox refresh

    Posted Oct 15, 2019 12:04 AM

    Hi,

     

    I am reaching out to the community to seek some advice.

     

    Our organisation has set-up Salesforce connection with CASB via Securlet. We have set-up a few Salesforce instances to authenticate with CASB - this inlcude the production environment and some Salesforce sandbox/UAT environment. Due to business requirement, the Sandbox Salesforce gets refreshed monthly or quarterly. When the sandbox is refreshed, the Securlet connection broke, this is due to 

    • the account ID (or Organisation ID) from Salesforce changed
    • the Salesforce system admin email account changed (additional text were appended to the email address)

     

    We are currently manually re-establish the connection but this is very manual as we have to remove the account and also uninstalling the Saleforce Elastica Securlet then reinstalling the Elastica Securlet again. Also, doing so, we lost previous data as well even without selecting the "Purge Data" checkbox.

     

    So you can see this is very troublesome and not ideal for BAU. I wonder whether any community out there have the same scenario and whether there is a better ways in doing this eg. scripting to reenable data connection automatically instead of doing this manually? 

     

    Thanks in advance.



  • 2.  RE: Salesforce Securlet Token Authentication Broken due to sandbox refresh
    Best Answer

    Broadcom Employee
    Posted Oct 15, 2019 04:23 PM

    Unfortunately, this scenario does require a securlet deactivation and reactivation like you are already doing. Also, there currently is no automated or scriptable way to do this; it must be done manually. I do not believe this is a use case that was considered when developing the securlets. It may be worth submitting a feature request to add a funtionality to help with this business case.