Enforce production TLS certificate verification
Understand mandatory certificate and hostname verification for production outbound connections.
Exact navigationAutomatic core protection — no separate staff menu route
What this guide covers
Understand mandatory certificate and hostname verification for production outbound connections. The workflow below follows the supported application or module flow and does not invent a menu or bypass validation.
Exact step-by-step process
- Use the supported Britixo CRM release or workflow that produces this security control.
- Verify the expected protection through an authorised test.
- Record the result in the deployment or security audit evidence.
Fields, choices and supported possibilities
- Certificate chain
- Hostname
- Validity period
- Trusted CA store
Code-backed validations and workflow rules
- Production connections require a valid hostname, validity period and trusted certificate chain.
- Correct the endpoint, CA chain or certificate rather than disabling verification.
- Self-signed certificates require an approved private-CA deployment, not a code bypass.
Expected result and verification
- The protection is active without weakening another security control.
Security, audit and troubleshooting checks
- Use the exact authorised account, role and record before saving or sending.
- Verify the saved status and downstream record; a browser success message alone is not sufficient evidence.
- Never expose passwords, API keys, access tokens, protected attachments or raw server paths in support tickets.
- Do not edit module or core database records directly to bypass validation, permissions, migrations or state rules.
