In this article
AS2 certificate rollover testing is critical for any organization relying on EDI with trading partners. An expired or mismatched AS2 certificate—used for signing or encrypting messages—will immediately sever automated communications, halt document flows, and often cause EDI errors that go unnoticed until orders, invoices, or shipping notices fail. Proactive rollover testing, including both sides of the transaction and coordination with every affected trading partner, is the most effective way to prevent these failures.
BOLD VAN recommends beginning the AS2 certificate renewal process up to 90 days in advance of expiration. This approach gives ample time for partner outreach, preparation of replacement certificates, controlled testing, and ensuring that both the primary and fallback VAN or integration paths will remain functional throughout the transition. Our managed EDI services include built-in tools, notifications, and support for rollover, minimizing risk and ensuring that your AS2 exchanges with partners, retailers, and logistics providers remain uninterrupted.
Why proactive AS2 certificate rollover testing matters
AS2 relies on digital certificates for two main purposes: signing outbound messages (proving authenticity) and encrypting messages for secure transmission. When a certificate expires or is replaced, both your company and each trading partner must update their systems and trust stores to accept the new certificate, or risk rejected transfers, failed MDNs (message disposition notifications), and lost business documents.
- Signing certificates authenticate messages or MDNs you send. If a partner does not update their trusted copy, your outbound messages may fail signature verification.
- Encryption certificates protect messages your partners send to you. If you drop the old private key before your partners change to the new public key, incoming messages become unreadable and are rejected or lost.
Testing is essential. A successful network connection or handshake alone does not confirm that the full signed and encrypted AS2 message round-trip will work after a rollover. Both parties must prove that:
- Encryption/decryption works with the new certificate
- Signatures on messages and MDNs can be validated end-to-end
- Test EDI transactions (such as 850 POs, 856 ASNs, or 810 invoices) are processed, acknowledged, and routed through all systems correctly
Never wait until the certificate is about to expire. Start planning 60–90 days in advance, keep a backup of the old certificate, and coordinate with every affected partner before go-live. Last-minute rollovers remain the top cause of avoidable AS2 and EDI communication failures.
What actually changes during rollover
AS2 certificate rollover is more than just an upload. It involves multiple configuration steps, all of which must be validated both in your environment and with every trading partner. Here is what actually changes and must be managed during the process:
| Area | What Changes | What You Must Verify |
|---|---|---|
| Signing Certificate | New private/public key pair for signing messages | Your system uses new private key; all partners import new public key |
| Encryption Certificate | New public certificate sent to partners | Your partners start encrypting to the new certificate before you retire the old private key |
| Certificate Trust Stores | Update partner profiles, trusted issuers, or keystores | Correct certificate usage (signing, encryption) and fingerprint confirmation |
| AS2 Profiles | Possible updates to AS2 identifier, endpoint, or algorithm preferences | Settings match trading partners’ published guides |
| MDN Behavior | MDNs signed using new certificate; partner validation updated | End-to-end round-trip validated with new certificate |
Certificate requirements can vary by platform and partner. Always confirm the expected algorithms, minimum key lengths (2048 bit RSA or stronger), and formats (PEM, DER, etc.) using each partner’s latest documentation and implementation guide.
The essential rollover and testing checklist
1. Inventory and plan (90 days out)
- Catalog all AS2 certificates in use across your trading relationships
- Record partner names, endpoints, certificate roles, expiration dates, and tech contacts
- Determine if your environment supports loading two certificates in parallel (overlap period) for a smoother transition
- Set calendar reminders at 90, 60, and 30 days out
2. Generate and stage replacement certificates (60 days out)
- Generate new keys/certificates with correct purpose and algorithms
- Do not share private keys. Export the public certificate as required by your partners and systems.
- Keep a secure backup of the old key until all partners have switched to the new one
3. Notify partners and confirm import (60–45 days out)
- Send new public certificate and fingerprint to each partner, with suggested go-live date and proposed overlap period
- Request written confirmation that their system has imported the new cert and assigned it for the correct use (signing/encryption)
- Document status: sent, received, tested
4. Two-sided testing window (30–14 days out)
- Exchange signed and encrypted test messages in both directions using the new and old certificates
- Verify that signed MDNs and EDI traffic are received, validated, and processed without error
- Use a dedicated test environment if available, or coordinate low-volume production tests with the partner
- Check logs for any MDN rejections, decryption failures, or signature errors
5. Cutover and post-rollover monitoring
- Agree on a precise time and date for cutover with all partners; refer to a specific timezone (such as UTC)
- Switch your system’s primary certificate to the new one; partners must do the same
- Monitor all AS2 transactions, MDNs, and system health immediately after the cutover for at least one full business cycle
- Retire support for the old certificate only when all test results and transaction logs show success
Common pitfalls and troubleshooting tips
- Delayed partner response: Certificate sent but not imported. Reach out via multiple channels (email, phone), and confirm by running real test messages both ways.
- Wrong assignment: Signing and encryption certificates mixed up in a partner’s system. Cross-check with partner and confirm via fingerprints and test transactions.
- Format mismatches: PEM vs DER confusion or missing intermediate certificates. Clarify expectations ahead and test with provided formats and certificate chains.
- Time zone errors: Cutover at the wrong hour. Always agree on the precise UTC timestamp for activation.
- Testing only connectivity: A handshake or 200 OK from the partner does not guarantee EDI round-trip success. Always test an actual transaction with the new certificate end-to-end, including MDNs and downstream EDI delivery.
- Premature key removal: Retiring the old private key or certificate before all pending messages/MDNs are confirmed may cause permanent data loss or silent failures.
- Lack of logging: Not capturing MDN results, transmission logs, or error diagnostics can make post-cutover troubleshooting impossible. Preserve all logs associated with the change for audit and root cause analysis.
Best practices for ongoing AS2 certificate management
Manage AS2 certificates as part of your regular EDI operational process—not as an urgent IT fire drill. Assign clear ownership for certificate inventory, partner coordination, and testing. Store an up-to-date inventory in a shared, accessible location, and include partners’ technical contacts for rapid support if an exception occurs.
Keep evidence of each rollover: partner confirmations, fingerprints, test result logs, cutover approvals, and monitoring outcomes. After every change, track both success and unexpected issues for at least one complete EDI business cycle before retiring old certificates completely. Engage your EDI provider if you suspect system-level or platform-specific rollout issues—in modern environments, managed cloud VANs like BOLD VAN often centralize certificate monitoring, key distribution, and communication with trading partners, reducing key-person risk and ensuring smoother cross-partner rollouts.
If your environment includes integrations with SAP, Oracle ERP, Infor CloudSuite, ShipHero, Oracle TMS, Shopify, or other platforms supported by BOLD VAN, include all related endpoints in the certificate inventory and testing plan. Upfront transparency and shared checkpoints are essential for smooth, audit-ready rollovers.
Frequently asked questions
How far in advance should an AS2 certificate be renewed?
Start planning at least 60 to 90 days before expiration. This provides time to generate the replacement, exchange public certificates, coordinate with trading partners, complete two-sided testing, and keep a recovery window before the old certificate expires.
What should be tested during an AS2 certificate rollover?
Test the AS2 connection, encryption, decryption, message signing, signature validation, MDN receipt, EDI translation, routing, and delivery to the receiving business system. Test both outbound and inbound flows when both directions are used.
Does changing my AS2 certificate require my trading partner to change its configuration?
Usually, yes. The partner may need your new public certificate to validate signatures or encrypt messages sent to you. The exact change depends on the certificate purpose and the partner's AS2 implementation, so confirm the procedure with that partner.
Can an expired AS2 certificate cause an EDI document to be lost?
An expired certificate can cause a message or MDN to be rejected. Whether the document is queued, retried, or rejected depends on the systems involved. Review transmission logs and reconcile all affected documents rather than assuming that a later retry completed successfully.
If you're facing an upcoming AS2 certificate rollover or want to evaluate your current approach, consider how a managed EDI service like BOLD VAN can help streamline coordination, automate partner outreach, and ensure your EDI connections stay up—even as your trading partner landscape evolves. For organizations that value transparency, proactive support, and integrated AS2 testing, BOLD VAN stands ready to assist.




