When your site processes payments through CyberSource, it signs in with a Merchant ID and a Transaction Security Key. CyberSource stops accepting that sign-in method on October 7, 2026. From that date, payments are signed with a P12 certificate issued to your merchant account instead.
Soapbox support installs the certificate on your site for you. You create it in your CyberSource account and send it to us.
Important: Until your certificate is installed, your site keeps using your Transaction Security Key and payments continue as normal. Payments stop on October 7, 2026 if no certificate is installed.
Step 1 — Create your certificate in CyberSource
- Sign in to the CyberSource Business Center.
- Go to Payment Configuration.
- Click Key Management.
- Generate a new key of type Simple Order API.
- Set a password for the certificate when prompted, and keep it somewhere safe.
- Download the
.p12file to your computer.
Note: CyberSource does not store this password and cannot recover it. If you lose it, create a new certificate.
Step 2 — Send the certificate to Soapbox support
- Attach the
.p12file to your support ticket. - Tell us in the ticket that the certificate is attached, but do not include the password.
- Call Soapbox support to give the password by phone.
Warning: Never send the certificate and its password together. Anyone holding both can process payments against your merchant account.
Step 3 — Confirm the certificate is installed
Soapbox support confirms when your certificate is in place. To check it yourself:
- Log in to your Soapbox administrator.
- In the right column, click Payment Processor Settings.
- For Payment Gateway, confirm CyberSource is selected.
- Read the Certificate Status row.
When a certificate is installed, Certificate Status shows its expiration date, its fingerprint, and when it was last verified. Until then it reads "No certificate installed."
Administrators using the Soapbox CMS Classic administrator see the same information as three separate fields, Certificate Fingerprint, Certificate Expires and Certificate Last Verified, under Extensions > Plugin Manager > Payment Gateway - CyberSource.
Step 4 — Confirm a payment
Make one live donation, event registration, or store purchase, and confirm it completes and appears in your transactions. This is the only way to confirm the certificate is signing payments correctly.
Keeping your certificate current
Certificates expire, and the expiration date appears in Certificate Status. The message changes as that date approaches: within 30 days it tells you how many days remain, and once the certificate has expired it warns that CyberSource payments will be declined until it is replaced.
Contact Soapbox support before the expiration date to have a replacement installed. Creating the replacement follows the same steps as above.
Related articles: