Certificate Continuity
During the transition the Bank must be able to validate legitimate certificates chaining to either the existing Entrust trust infrastructure or the new Keyfactor trust infrastructure.
Bank trust capability
Both chains must validate during the transition window
- Entrust chainTRUSTED
- Keyfactor chainTRUSTED
- Dual trust (edge)PASS
- Dual trust (all in-scope trust stores)ACTION REQUIRED
- 4096-bit RSA compatibilityPASS
12 PKI-dependent systems do not yet trust the Keyfactor chain. Open PKI / Dual Trust
Entrust trust path
137 existing TPP certificates
- TPP CertificateEntrust
- Issuing CAOpenBanking Issuing CA
- Root CAOpenBanking Root CA
- Bank Trust StoreChain present
- TRUSTED ✓Path builds and validates
Keyfactor trust path
35 existing TPP certificates
- TPP CertificateKeyfactor
- Issuing CAOpen Banking Limited Issuing CA G3
- Root CAOpen Banking Limited Root CA G3
- Bank Trust StoreChain present
- TRUSTED ✓Path builds and validates
Certificate migration risk
TPPs whose certificate trust may not survive migration unchanged
Certificate expires within the migration window. Renewal is a normal TPP lifecycle action, not a Directory migration defect.
Current certificate chains to Keyfactor but the affected Bank trust store contains the Entrust chain only. The TPP certificate will not be trusted by this Bank component. Add the required Keyfactor trust chain and execute certificate validation tests.
Affected system: Open Banking API Gateway
Certificate expired. Existing Bank registration remains present; this is a TPP certificate lifecycle event, not a Directory migration defect.