Update: The new security feature changes mentioned in this article have been delayed 1 week. Message from Salesforce:
"Please note the date change for this update - we will now go live with these features on Monday Nov. 26, 2007."
Salesforce.com is deploying additional security features over the weekend that may have an impact on applications integrated with Salesforce via the API, such as i-Dialogue portals, landing pages, and content management systems.
Starting next Monday, November 19th, 2007, Monday, November 26th, 2007 Salesforce.com users must modify their settings to implicitly trust i-Dialogue portals that connect to Salesforce. This feature, known as "whitelisting", requires entering the Internet address of the i-Dialogue portal.
Salesforce announced that any service connecting via the API within the past 4 months will automatically be added to the whitelist, so existing i-Dialogue customers may not need to update their settings.
Question: Will my i-Dialogue portal stop integrating with Salesforce.com on Monday, November 19th26th, 2007?
Answer: No. Salesforce has assured all AppExchange partners that existing integrations will be trusted by default. But without 100% assurance, we are prepared to guide customers through whitelisting steps if necessary.
Question: What is the IP Address for my i-Dialogue portal so that I may configure it for whitelist trusting?
Answer: We are sending IP address details directly to existing customers before the weekend to give customers time to prepare.
Update the Salesforce Profile for the API login user under the section "Trusted IP Ranges".
Question: How will I know if my i-Dialogue portal is no longer synchronizing with Salesforce?
Answer: Web-to-Lead and Web-to-Case web forms will continue to work, but portals and web sites that retrieve their content from Salesforce will be unable to access content updates if whitelisting is not configured correctly. Information on web sites (such as MLS portals) will appear unchanged from Sunday, November 18th25th.
Our internal operations team will know within minutes if synchronization has failed and will take action to contact customers directly.
Question: Are there alternative ways to secure access to my Salesforce instance?
Answer: Yes. You can always generate an API token to be used as a password for remote applications that do not always access from the same IP Address.
Question: Are i-Dialogue IP addresses static?
Answer: Yes.
Question: Will new i-Dialogue portals need whitelist configuration?
Answer: Yes. Our provisioning process has been updated to include instructions for whitelisting i-Dialogue Portal and CMS instances.