...
2.0 Pre-Production Domain Names
Section | Question | Answer | Additional Information to be Supplied to Ozone | Provided by |
---|---|---|---|---|
Domain Names | TPP facing Domain Name Ozone will allocate a domain name for your pre-production environment based on your BIC. | <Link TBC> |
|
|
Domain Names | LFI Facing Domain Name Ozone will allocate a domain name for | <Link TBC> |
|
|
Domain Names | Ozone Connect Base URL LFI to specify the base url on which Ozone Connect is hosted | <Link TBC> |
|
|
Domain Name | Authorisation URL The OIDC There can be only one auth URI for an instance. The auth uri must follow the stipulations placed by FAPI 2.0 (e.g. https only, no query parameters) | <Link TBC> |
|
|
3.0 Pre-Production Certificates
...
The table below sets out the steps for each certificate where Ozone holds the Transport & Signing Private keys.
Section | Certificate | Steps | Additional Information to be Supplied Ozone & LFI |
---|---|---|---|
Transport Server Certificate | S1 This is the certificates that is deployed onto the |
OFP
| These steps are repeated for
|
Ozone
to download certificates from OFTF JWKS
Ozone
to deploy complete certificates and chains
|
|
| ||||||
Transport Server Certificate | S3 The certificate is used by Ozone’s |
|
| ||||||
Transport Client Certificate | C4 This certificate is used by |
|
| |
Signing Certificate | Sig2 Used by the |
OFP
This includes signed messages from the resource server and the signature on the The TPP will use the public key in the JWKS to verify the signature |
|
| |
Signing Certificate | Sig3 Used by the |
OFP
This is used to sign the jwt-auth header for:
|
OFP
|
|
| |||
Transport Server Certificate | S2 This certificate is used by | Process fully managed by |
|
3.2 Pre-Production LFI Held Transport & Signing Private keys
The table below sets out the steps for each certificate where the LFI holds the Transport & Signing Private keys.
Section | Certificate | Steps | Additional Information to be Supplied by LFI |
---|
Section | Certificate | Steps | Additional Information to be Supplied by LFI |
---|---|---|---|
Transport Client Certificate | C3 This certificate is used by Ozone to recognise the LFI when it calls the | These steps are repeated for
|
|
Ozone will provide the subject for the certificate.
|
|
|
|
|
Cert Subject
| |
Transport Server Certificate | S4 The certificate is used by the LFI to identify its Ozone Connect service to |
API Hub. |
|
Cert Subject
| |
Signing Certificate | Sig3 Used by the LFI to sign requests and responses sent to |
API Hub. This is used to sign the
|
|
Cert Subject
|
3.3 Pre-Production LFI Held Encryption Private key
The table below sets out the steps for LFI to generate the encryption private key.
Section | Certificate | Steps | Additional Information to be Supplied by LFI |
---|---|---|---|
Encryption Key |
Used by the |
OFP
The The |
|
|
Ozone
will provide the subject for the certificate.
|
|
|
|
Cert Subject
|