TLS Certificate for SMS Gateway Question

4 views
Skip to first unread message

Zach Skidmore

unread,
Apr 17, 2026, 11:19:34 AM (2 days ago) Apr 17
to pwm-general
Hi everyone,
Our institution uses PWM and have it integrated with an SMS Gateway (Twilio). We have the gateway's TLS certificate imported into our configuration it works, but I would like to avoid outages every time Twilio rotates the TLS Certificate (it appears they do this even before the current one expires). I know I can update it when it rotates, but that means its an outage we react to everytime. Has anyone found a way to avoid this approach? Twilio's TLS certificate is a Digicert which is trusted by common OSes, so it would be nice if PWM didn't require it to be imported, but it appears that it does. 

Thanks!

-Zach

Jason Rivard

unread,
Apr 17, 2026, 1:17:25 PM (2 days ago) Apr 17
to pwm-general
If you have this setting set to CA when you do the import PWM will import the root CA cert instead of the endpoint cert, and use the CA cert for validation.  As long as they keep the CA this should work at the expense of degraded security. 

 Settings ⇨ Security ⇨ Application Security ⇨ Certificate Validation Mode

If you have an older (version and you should definitely not be running anything but the latest in production) or started the config in an older version the default is not CA.

Zach Skidmore

unread,
Apr 17, 2026, 2:15:49 PM (2 days ago) Apr 17
to pwm-general
Jason,

Thanks for this info!

-Zach
Reply all
Reply to author
Forward
0 new messages