Security Certificates Management
Library: Track & Trace Documentation Library
Document: Security Certificates Management
Version: 1
Effective date: November 22, 2024
Contents
- 1 Description
- 2 Types of Certificates
- 3 Storing
- 4 Monitoring
- 5 Certificates Renewal
- 6 Document Control
- 7 Conversion and Preservation Notes
1 Description
Security certificates are used by the Track and Trace system either for encrypting the communication between systems, Transport Layer Security certificates, or for authentication purposes.
2 Types of Certificates
2.1 Encryption Certificates
tat.jti.com— certificate used to host thetat.jti.comHTTPS domain- The
tat.jti.comcertificate must also be installed both on API Management and the SAP PO proxy. This needs to be confirmed
- The
- TPM certificates used to encrypt the communication with TPM—future development
- GLA certificates used to encrypt the communication with GLA—future development
2.2 Authentication Certificates
- Certificates used by satellite systems to authenticate to InexTrack
- Certificates used by Vault to authenticate to ID Issuers
3 Storing
The certificates are stored in a JTI Track & Trace dedicated instance of Azure Key Vault.
This is a common place where all certificates, usernames and passwords are stored and is integrated with other Azure components, like DevOps, which can natively connect to Azure Key Vault and retrieve credentials when required.
3.1 Azure Key Vault Example
The source includes a Microsoft Azure portal screenshot of the dedicated Track & Trace Key Vault.
Navigation items visible in the screenshot
- Overview
- Activity log
- Access control (IAM)
- Tags
- Diagnose and solve problems
- Access policies
- Events
- Objects
Available actions
- Delete
- Move
- Refresh
- Open in mobile
Key Vault details visible in the screenshot
| Property | Value |
|---|---|
| Resource group | npr-msfwex33-02-lnt-apim |
| Location | West Europe |
| Subscription | MSFAZQ33 TnT APIM |
| Subscription ID | 5bc32e1a-8734-4c95-b44d-505e824237a5 |
| Vault URI | https://keyvault-msfwex33-02-tnt-vault.azure.net/ |
| SKU, pricing tier | Standard |
| Directory ID | 705d073a-2eca-4fb3-ab59-65ca29abbc26 |
| Directory name | JT International |
| Soft-delete | Enabled |
| Purge protection | Enabled |
| BRN tag | IT18200118 |
Security note: The source screenshot also contains an internal ownership tag. Consult the original controlled document or Azure resource when the current ownership information is required.
4 Monitoring
The expiration date of certificates is monitored via an automatic process which sends reminder emails to a predefined distribution list.
- Certificates are stored in the Track & Trace Azure Key Vault
- There is an automated process which generates automatic alerts 30 days before the certificate expires, based on the certificate expiration date
- The automatic alerts are sent to a dedicated distribution list:
DL GDC TnT Security Certificate Expiration- To receive notifications, subscribe to the distribution list through the form
4.1 Certificate Expiration Warning
The source contains an example of a high-importance automatic notification email.
Email subject
Certificat tpm-sen-prd will expire soon
Email content
Certificate Expiration Warning
Dear Colleagues,
This is automatic notification message regarding expiration check for security certificates for business applications of T&T.
Name of certificate: tpm-sen-prd
Expiration period: 30 days
Please check Azure Key Vault to fix issue.
4.2 Distribution List
The source contains a screenshot of the DL IT GDC TTDC group.
| Property | Value |
|---|---|
| Group | DL IT GDC TTDC |
| Number of members | 13 |
| Available action | Send email |
| Tabs | About, Members |
| Selected tab | Members |
The screenshot shows the following job titles and roles among the visible members:
| Job title | Group role |
|---|---|
| GDC T&T Delivery Center Director | Owner |
| Development Manager | Member |
| Development Manager | Member |
| Development Manager | Member |
| Systems Development Team Manager | Member |
| Development Engineer | Member |
| Development Manager | Member |
| Development Manager | Member |
| Development Manager | Member |
| Quality Assurance Team Manager | Member |
Screenshot preservation note: The group contains 13 members, but only 10 entries are visible in the source screenshot. The screenshot includes individual names; these are not repeated here because distribution-list membership may change. Consult the live directory for the current member list.
5 Certificates Renewal
Before expiration, certificates must be renewed and the new certificates must be installed prior to the expiration date.
The installation procedure is different between Authentication certificates and Encryption Certificates.
5.1 Encryption Certificates Installation
- TTDC renews the certificate using the appropriate renewal process for each certificate
- TTDC installs the new certificate on the required machine or resource prior to the expiration date
5.2 Authentication Certificates Installation
- TTDC initiates the certificate renewal and provides the new certificate to the party who needs to install this certificate on the satellite system
- The new certificate must be installed by the owner of the satellite system
6 Document Control
6.1 Contact Person
As of July 2025, questions and feedback regarding this standard should be submitted to the contact person identified in the source document.
6.2 Revision History
| Version | Effective date | Purpose of change | Author |
|---|---|---|---|
| 1 | November 22, 2024 | First version of the document | Author identified in the source document |