Findings
FND-1045 · PKI · Production

Keyfactor issuing CA absent from trust store

CriticalIn Remediation
View evidence

Detected vs required

Detected configuration

/etc/pki/ob-truststore.jks contains Entrust G2 root + issuing CA only

Required target

ob-dual-trust-2026 bundle (Entrust G2 + Keyfactor OB Root + Keyfactor OB Issuing CA)

Impact

TPPs presenting Keyfactor-issued transport certificates will be rejected at registration.

Remediation guidance

REM-104

Distribute the dual-trust bundle via the Trust Store Distribution Agent and verify with the Keyfactor chain test.

Remediation workflow: CHANGE PLANNED · Owner A. Whitfield · Due 2026-09-26 · OBMIG-243

Evidence

2 artefacts linked to this finding or its control on the affected system

  • EVD-2023DCR with Keyfactor transport certificate — FAILAPI test12 Sept, 16:41Pending
  • EVD-4003truststore-inventory-2026-09-12.jsonTrust-store evidence12 Sept, 09:00Approved

Context

Environment
Production
Control
PKI-001Keyfactor trust chain installed
Category
PKI
Owner
A. Whitfield
Detected
09 Sept, 10:00
Evidence ref
truststore-inventory-2026-09-12.json
Cutover blocker
No

Linked tests

TST-007Validating Keyfactor certificatePASS
TST-022Keyfactor chain on NGINXFAIL
TST-023Keyfactor chain on Payment APIFAIL
TST-024DCR with Keyfactor transport certificateFAIL