FND-1046 · TPP Registration · Production
TPP role validated from certificate only
CriticalOpen
Detected vs required
Detected configuration
roles derived from certificate policy OIDs (Entrust-specific)
Required target
roles validated against Directory organisation authorisations
Impact
Keyfactor certificates do not carry the legacy policy OIDs; role validation will fail or be bypassed.
Remediation guidance
Validate roles using the Directory organisation lookup response and remove policy-OID inference.
Remediation workflow: OPEN · Owner J. Carter · Due 2026-09-26
Evidence
1 artefacts linked to this finding or its control on the affected system
- EVD-2015TPP role validation against Directory — FAILAPI test12 Sept, 16:45Pending
Context
- System
- TPP Registration Service
- Environment
- Production
- Control
- TPP-002 — TPP role/permission validation confirmed
- Category
- TPP Registration
- Owner
- Unassigned
- Detected
- 11 Sept, 14:22
- Evidence ref
- RoleValidator.java · Line 41
- Cutover blocker
- No
Linked tests
TST-014End-to-end TPP journey (AISP)WARNING
TST-015End-to-end TPP journey (PISP)NOT RUN
TST-016TPP role validation against DirectoryFAIL