Prove
PKI / Dual Trust
Trust-chain assurance for the transition from the Entrust-issued Open Banking PKI to the Keyfactor-issued OBL PKI.
Entrust chainPASS
Keyfactor chainPASS
Dual trustPASSBoth chains accepted at the edge
4096-bit RSA compatPASSIssuing CA handshake on F5
Not trusting Keyfactor12of 36 PKI-dependent systems
Certificate chain
Keyfactor · Root CA
- Subject
- CN=Open Banking Limited Root CA G3, O=Open Banking Limited, C=GB
- Issuer
- CN=Open Banking Limited Root CA G3, O=Open Banking Limited, C=GB
- Serial
- 7E:20:AB:14:C3:00:00:00:00:01
- Key
- RSA 4096-bit
- Validity
- 01 Feb 2026 → 01 Feb 2046
- OCSP
- GOOD
- CRL
- NOT REVOKED
- Trust-store presence
- 39 / 52 systems
Trusting applications
Open Banking API GatewayF5 Load BalancerCertificate Validation ServiceAccount Information API
Systems not yet trusting Keyfactor
PKI-dependent systems whose trust store contains only the Entrust chain
- TPP Registration ServiceOpen Banking PlatformProductionCritical
- Jans IAMIdentity & AccessProductionCritical
- Payment APIPayments EngineeringProductionHigh
- NGINX Reverse ProxyPlatform EngineeringProductionHigh
- Directory Sync JobPlatform EngineeringProductionHigh
- Certificate Expiry WatcherData PlatformProductionLow
- SIEM ForwarderAPI PlatformProductionLow
- SSA Verification Library ServicePKI ServicesSandboxMedium
- Egress DNS ResolverSREProductionLow
- Legacy DCR AdapterOpen Banking PlatformProductionLow
- Consent DashboardPlatform EngineeringProductionMedium
- Sandbox Reverse ProxyData PlatformSandboxHigh