Dear Partners,
Ingram Micro will be updating the certificates for Seeburger B2B gateway (Mercury PROD / Venus QA).
IMPORTANT: As part of this renewal, we are separating the certificates based on their intended usage. Partners are requested to review and update the applicable certificates as described below.
Implementation Plan
Test Environment
- Implementation Date: September 19, 2026, 07:00 PM – 08:00 PM Pacific Time // September 20, 2026 -04:00 AM – 05:00 AM CEST
- Host: venus.ingrammicro.com
- Impacted Protocols:
- AS2 – TLS and Signing/Encryption certificates
- HTTPS – TLS certificate
Production Environment
- Implementation Date: October 3, 2026, 07:00 PM – 08:00 PM Pacific Time // October 4th, 2026 04:00 AM – 05:00 AM CEST
- Host: mercury.ingrammicro.com
- Impacted Protocols:
- AS2 – TLS and Signing/Encryption certificates
- HTTPS – TLS certificate
AS2 Signing & Encryption Certificate
A dedicated certificate is being introduced for AS2 message signing and encryption, issued by the Ingram Micro Internal CA.
Partners using AS2 are requested to update the attached AS2 Signing/Encryption certificate at their end for AS2 signing, signature verification, and encryption.
- As this certificate is issued by the Ingram Micro Internal CA, partners should also import/trust the applicable Ingram Micro CA certificate chain, provided in the attached PKCS#7 (.p7b) format, where required by their application or security configuration.
AS2 / HTTPS TLS Certificate
A separate publicly trusted TLS certificate will be used for both AS2 TLS connectivity and HTTPS connectivity to the Ingram Micro B2B gateway.
Partners are requested to review their TLS trust configuration. Where supported, we recommend using CA-chain-based trust rather than pinning the individual Venus/Mercury server certificate.
Partners using standard CA-based TLS validation should ensure that the applicable public CA certificate chain is trusted in their environment.
If your application requires the individual Ingram Micro TLS server certificate to be explicitly imported or pinned, please use the attached TLS server certificate and coordinate the update with the applicable implementation window specified above.
The corresponding PKCS#7 (.p7b) certificate chain is also provided where required for CA-chain-based trust configuration.
SFTP
Please note that SFTP is not included in this certificate renewal activity, and there will be no SFTP host-key change on September 19 or October 3.
A separate communication will be provided in advance with the new SSH public host key/fingerprint and implementation schedule.
Certificate Attachments
Separate certificate packages are attached for the Test (Venus) and Production (Mercury) environments:
- Test (Venus): venus.ingrammicro.com-certificates.zip
- Production (Mercury): mercury.ingrammicro.com-certificates.zip
Each ZIP package contains the following:
- AS2/HTTPS TLS Certificate (.txt) – The same TLS server certificate is used for both AS2 TLS connectivity and HTTPS connectivity. Please rename the .txt extension to .cer before importing, where the individual server certificate is required.
- AS2/HTTPS TLS Certificate (.p7b) – PKCS#7 certificate chain for the same TLS certificate, where required for CA-based TLS trust configuration.
- AS2 Signing/Encryption Certificate (.txt) – Dedicated certificate used for AS2 message signing, signature verification, and encryption. Please rename the .txt extension to .cer before importing.
- AS2 Signing/Encryption Certificate (.p7b) – PKCS#7 certificate chain for the new Ingram Micro Internal CA-issued AS2 certificate, where required to establish CA trust.
For HTTPS-only integrations, only the AS2/HTTPS TLS certificate is applicable; the AS2 Signing/Encryption certificate is not required.
The individual certificates are provided with a .txt extension to avoid .cer attachments being filtered by email security systems. Only the file extension has been changed; the certificate content remains unchanged. Please rename .txt to .cer before importing the individual certificate.
Please ensure the applicable certificate updates are completed during the respective implementation windows specified above.