Skip to main content

Security Certificates Management

Library: Track & Trace Documentation Library
Document: Security Certificates Management
Version: 1
Effective date: November 22, 2024

Contents


1 Description

Security certificates are used by the Track and Trace system either for encrypting the communication between systems, Transport Layer Security certificates, or for authentication purposes.

2 Types of Certificates

2.1 Encryption Certificates

  • tat.jti.com — certificate used to host the tat.jti.com HTTPS domain
    • The tat.jti.com certificate must also be installed both on API Management and the SAP PO proxy. This needs to be confirmed
  • TPM certificates used to encrypt the communication with TPM—future development
  • GLA certificates used to encrypt the communication with GLA—future development

2.2 Authentication Certificates

  • Certificates used by satellite systems to authenticate to InexTrack
  • Certificates used by Vault to authenticate to ID Issuers

3 Storing

The certificates are stored in a JTI Track & Trace dedicated instance of Azure Key Vault.

This is a common place where all certificates, usernames and passwords are stored and is integrated with other Azure components, like DevOps, which can natively connect to Azure Key Vault and retrieve credentials when required.

3.1 Azure Key Vault Example

The source includes a Microsoft Azure portal screenshot of the dedicated Track & Trace Key Vault.

  • Overview
  • Activity log
  • Access control (IAM)
  • Tags
  • Diagnose and solve problems
  • Access policies
  • Events
  • Objects

Available actions

  • Delete
  • Move
  • Refresh
  • Open in mobile

Key Vault details visible in the screenshot

PropertyValue
Resource groupnpr-msfwex33-02-lnt-apim
LocationWest Europe
SubscriptionMSFAZQ33 TnT APIM
Subscription ID5bc32e1a-8734-4c95-b44d-505e824237a5
Vault URIhttps://keyvault-msfwex33-02-tnt-vault.azure.net/
SKU, pricing tierStandard
Directory ID705d073a-2eca-4fb3-ab59-65ca29abbc26
Directory nameJT International
Soft-deleteEnabled
Purge protectionEnabled
BRN tagIT18200118

Security note: The source screenshot also contains an internal ownership tag. Consult the original controlled document or Azure resource when the current ownership information is required.

4 Monitoring

The expiration date of certificates is monitored via an automatic process which sends reminder emails to a predefined distribution list.

  • Certificates are stored in the Track & Trace Azure Key Vault
  • There is an automated process which generates automatic alerts 30 days before the certificate expires, based on the certificate expiration date
  • The automatic alerts are sent to a dedicated distribution list: DL GDC TnT Security Certificate Expiration
    • To receive notifications, subscribe to the distribution list through the form

4.1 Certificate Expiration Warning

The source contains an example of a high-importance automatic notification email.

Email subject

Certificat tpm-sen-prd will expire soon

Email content

Certificate Expiration Warning

Dear Colleagues,

This is automatic notification message regarding expiration check for security certificates for business applications of T&T.

Name of certificate: tpm-sen-prd
Expiration period: 30 days

Please check Azure Key Vault to fix issue.

4.2 Distribution List

The source contains a screenshot of the DL IT GDC TTDC group.

PropertyValue
GroupDL IT GDC TTDC
Number of members13
Available actionSend email
TabsAbout, Members
Selected tabMembers

The screenshot shows the following job titles and roles among the visible members:

Job titleGroup role
GDC T&T Delivery Center DirectorOwner
Development ManagerMember
Development ManagerMember
Development ManagerMember
Systems Development Team ManagerMember
Development EngineerMember
Development ManagerMember
Development ManagerMember
Development ManagerMember
Quality Assurance Team ManagerMember

Screenshot preservation note: The group contains 13 members, but only 10 entries are visible in the source screenshot. The screenshot includes individual names; these are not repeated here because distribution-list membership may change. Consult the live directory for the current member list.

5 Certificates Renewal

Before expiration, certificates must be renewed and the new certificates must be installed prior to the expiration date.

The installation procedure is different between Authentication certificates and Encryption Certificates.

5.1 Encryption Certificates Installation

  • TTDC renews the certificate using the appropriate renewal process for each certificate
  • TTDC installs the new certificate on the required machine or resource prior to the expiration date

5.2 Authentication Certificates Installation

  • TTDC initiates the certificate renewal and provides the new certificate to the party who needs to install this certificate on the satellite system
  • The new certificate must be installed by the owner of the satellite system

6 Document Control

6.1 Contact Person

As of July 2025, questions and feedback regarding this standard should be submitted to the contact person identified in the source document.

6.2 Revision History

VersionEffective datePurpose of changeAuthor
1November 22, 2024First version of the documentAuthor identified in the source document