FND-1045 · PKI · Production
Keyfactor issuing CA absent from trust store
CriticalIn Remediation
Detected vs required
Detected configuration
/etc/pki/ob-truststore.jks contains Entrust G2 root + issuing CA only
Required target
ob-dual-trust-2026 bundle (Entrust G2 + Keyfactor OB Root + Keyfactor OB Issuing CA)
Impact
TPPs presenting Keyfactor-issued transport certificates will be rejected at registration.
Remediation guidance
Distribute the dual-trust bundle via the Trust Store Distribution Agent and verify with the Keyfactor chain test.
Remediation workflow: CHANGE PLANNED · Owner A. Whitfield · Due 2026-09-26 · OBMIG-243
Evidence
2 artefacts linked to this finding or its control on the affected system
- EVD-2023DCR with Keyfactor transport certificate — FAILAPI test12 Sept, 16:41Pending
- EVD-4003truststore-inventory-2026-09-12.jsonTrust-store evidence12 Sept, 09:00Approved
Context
- System
- TPP Registration Service
- Environment
- Production
- Control
- PKI-001 — Keyfactor trust chain installed
- Category
- PKI
- Owner
- A. Whitfield
- Detected
- 09 Sept, 10:00
- Evidence ref
- truststore-inventory-2026-09-12.json
- Cutover blocker
- No
Linked tests
TST-007Validating Keyfactor certificatePASS
TST-022Keyfactor chain on NGINXFAIL
TST-023Keyfactor chain on Payment APIFAIL
TST-024DCR with Keyfactor transport certificateFAIL