Collab: request Partner Admin access for Device Provider (HYF) to upload Root/Sub CA

Hi MOSIP team — I’ve onboarded as a Device Provider partner (organization: HYF) on the Collab environment (pmp.collab.mosip.net). To upload my CA-signed partner certificate, my Root CA and Intermediate (Sub) CA first need to be in the PMS Certificate Trust Store, but the Device Provider portal has no CA-upload option and I don’t have Partner Admin / Keycloak access.

Could you please grant my account the Partner Admin role on Collab so I can upload my Root + Sub CA to the trust store myself? (Same blocker as thread /t/partner-device-certificate-signing-for-sbi-compliance-testing-synergy-environment/2825.) If self-upload isn’t possible, I’m happy to instead attach my Root + Sub CA certs for your team to load. Chain: HYF Root CA → HYF Sub CA → HYF partner cert (X.509 v3, org=HYF).

Thanks!

Hi shahid

Thank you reaching out to us, Our team will look into this issue and get back to you shortly.

Regards,
Mrudula
on behalf of Team MOSIP

Hi @mrudula
I’m still waiting for the response.

Hi @mrudula,

The forum only allows image uploads, so I’m pasting the certificates inline instead — this is actually easier to action, since your admin can copy them straight into the trust store. Both are public certificates (no private keys).

Request: please load these into the PMS Certificate Trust Store on Collab (pmp.collab.mosip.net) and map them under the DEVICE domain for Device Provider partner HYF. Once they’re in the trust store, I’ll be able to upload my CA-signed partner certificate from my own dashboard.

Chain: HYF Root CA → HYF Sub CA → HYF partner cert (X.509 v3, O=HYF).

HYF Root CA (hyf-test-root-ca.crt):

-----BEGIN CERTIFICATE-----
MIIFXTCCA0WgAwIBAgIULl2AivyVbEgNyUYvLXfkhEgY3CkwDQYJKoZIhvcNAQEL
BQAwNjELMAkGA1UEBhMCQ04xDDAKBgNVBAoMA0hZRjEZMBcGA1UEAwwQSFlGIFRl
c3QgUm9vdCBDQTAeFw0yNjA3MDkwNTU4NTZaFw0zNjA3MDYwNTU4NTZaMDYxCzAJ
BgNVBAYTAkNOMQwwCgYDVQQKDANIWUYxGTAXBgNVBAMMEEhZRiBUZXN0IFJvb3Qg
Q0EwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCvWVGaB7VA79JUU3HO
iDsR5do3Ybs7PbV0ngHNo+AnTE9gO3wc/EprHmist5+JENZgW864USwWXDuvAKFi
3pFztBfA6ahBoj98uJ0sOgHinnNaHtVPJAz+jm1PhpuD0ZCOr6kb5uJb1QqrK7NT
N0gbS/xCXYxxpiCU8uQJY7oFmgnDBhw8785kCAfvXh5JIo+bie9YXTelxkfsTuLG
13HQs97UluDG/BRQhvfBUcNAe6AMrrqElbTgx+Cf8pNJmwfHzky49rxmAac8TFuU
DgiDy+odGB7UFYYKpmkP793OOGp8V/z37IyCUWqGgSs2NuooxtuezcnqhtP9laEk
FptlzymghbSNvRfddFxmlNd3wSVhwLKwBBsPN4aHHdhYjBN7AUS7KpX53DPf5K32
Fw/P7r2gvw/utrXqSDjJUDI57Ba9APNdu1v/sRWswkldl3jRd6vYucqIcizNm+a8
7E4SToCil5SGxpdHunu2F+fBAevpThMe4F71HuvNg3aKmrYcwhKIdFfmvm2Kw16r
8YiqGrpggPORzd4L/cxTzOQuPkJMmT77i4bfocgCADKmiby+37IPHr6qLws7hwXz
baSOvdMh1RZEZ+SraIJ40+FOuXSV5FRC3E6KxtrozIxq+U1oH/mFnK49ddP+AWCS
kLZyzZ6W75WayQyL+fZb3T/KYwIDAQABo2MwYTAfBgNVHSMEGDAWgBQHXr/su/KZ
2ZDsDza5pOHSFovshjAPBgNVHRMBAf8EBTADAQH/MA4GA1UdDwEB/wQEAwIBBjAd
BgNVHQ4EFgQUB16/7LvymdmQ7A82uaTh0haL7IYwDQYJKoZIhvcNAQELBQADggIB
AGAa/w/sHGasXLuTIkQ2CUY6ckIiIh429L/U12Dt+btHua4ARqMwEekdE/RvtVgm
Fo5QhKcy4clb+ukrqKkwKlvPjTMHRbwEjWmd0VemCdTCb/zsXGTCBe/X0UjsIA0A
AxNePmGZ7SypX8RooAgfRn1DRqr/h/ZFEUnqyn3sM+GYzx323lJiZU1W9kPuaXbc
W8I1qFGy4cbcICpxTamu+Hq8QFDV1QpLgZFaF154ZpBsxZ2j33Wr+3mUcg2jOrkh
kgI28xr80BhEt5+FdIOaGSuOYS3vpn8FHDuLJCgAXEnRZ3Mh9dkDbZ0j47xjyXqH
GMLaPFC+mbhxbwZa6qnFvatnkFpE+Yyzr/0kVNIbY9gADbQh/7SkTZWw5zZI47Gg
NBqw25JV5xLx0yDOdmZPeivPg3wbtqjD+Sel4J7wVUU73Ppwzke4FnCzOoLg1jkL
pXp++namAHRMHE/dFp0Jl5rv3sdcajBSK9mDa38KXeUv3D93Qa7Wlc7d7BzqNa/B
GiRptEDRvHKLrwt4DYYsf0vpnpIjQ3k83JbVdGBUp/qSKS14zPZ79nSi3NDOVo9q
WOZ/zc5cNtoufEqBtSCj57jpV4CjnoHyMthBSBX7707kBIUvOQwJqD/kMQtuQjwp
LTG6xg9uxBXVGzlOzD21/p0JgyKMl+WEqUUsAFdvgNXI
-----END CERTIFICATE-----

HYF Sub CA (hyf-test-sub-ca.crt, signed by the Root CA above):

-----BEGIN CERTIFICATE-----
MIIFXzCCA0egAwIBAgIUPVyl5Ti7YmsxLF2WYwfAdvhsl9UwDQYJKoZIhvcNAQEL
BQAwNjELMAkGA1UEBhMCQ04xDDAKBgNVBAoMA0hZRjEZMBcGA1UEAwwQSFlGIFRl
c3QgUm9vdCBDQTAeFw0yNjA3MDkwNTU4NTZaFw0zMTA3MDgwNTU4NTZaMDUxCzAJ
BgNVBAYTAkNOMQwwCgYDVQQKDANIWUYxGDAWBgNVBAMMD0hZRiBUZXN0IFN1YiBD
QTCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAN1AYvu6+V0Z/SpqN1Rt
eX1WSgTNqGM5vhrM6iZ1Q1RQGKtjiVnNMHvMBSzGZU6g3tL5N+G15R2PjGViuTta
JSv5icr1fyltcjfED71Xcs4NV5Cl2ozabAdqfq8zlwaGNQEt8Dqw/Cm/758k+Bht
iuC0FSQJAk7U9j0DybG5DVKpioWWsgoYAGhSJvWGrPKQH8nLBoUAoZKDXipTXodK
ucmKu4kImgCZ/JkE9NMZm4qAAZffwKhFkAIFutNg4XOnZiyXcaetz6ciILb7tWEc
dvy3Ccax9Z4lr3XjaOfGr3MrF89RB+DyWTSp2et29KoXJVYbhxmtGLWfjQZupvgA
7CSKNazh47ehcVahlIFUHDXmCw1eaApkrO7ViPW/IdHL47ezPMiEzMOAIf7gBMij
4umXP/L10J/7ZZ5hs2FkhwgsnwWBEbpi6C1oz+XMS7qvO+Av3SZT+0a79EdFLNrj
4Z0V+fD7b7sucCzDm81D3nCFjGDsf5gbLY/oHcVySCt/PXn7GcQ5Ef6EwVpb6gIE
sGdqAxgbBTfqqsHM4apj97Zn+UXh44qs5UCU/9v/zahuUaQfOkZl/JPWQYRr5OXO
H21tPomyRuA+oFHQzIkh4BfCGxSp9P6Z8WUEWrHIlxUJftqKx+39rJa6Dp4sLnQI
ixtAG+j/Ro/+CnaxBEyz8HEVAgMBAAGjZjBkMBIGA1UdEwEB/wQIMAYBAf8CAQAw
DgYDVR0PAQH/BAQDAgEGMB0GA1UdDgQWBBQR3kIvuzEOSt/aZ6i3uu6RNOY4ZzAf
BgNVHSMEGDAWgBQHXr/su/KZ2ZDsDza5pOHSFovshjANBgkqhkiG9w0BAQsFAAOC
AgEAOdNzNrzT+O3mApBvP7SmBkgX3yU1DVNEYb5vZjPfMuzq7pSZt9Cujn/TtwHY
c8eAtRKdUCfd0i3BzGG1dA+DuPSRgUS+avhSAZn5xoj0sthaOoB7hnMZC8f+B820
4ChSIt2mjQbytCIVIbOhGr7yr0YDymJlro+LnnjQ8WpnRwO4YCncEsADpDjmuHN5
dAtLbVHavt9wnqfULNtivZez9kuNNWgiPxTUQYGlRfv00U8Gy6driaPXBOeKojSX
hqL3eVLF9EriuvZf9F14cOVl4GjeycC81Q6G3g5pfeekfX3FYlMGm//z9iuFT3au
Zt2CNXzKLLNOfv2iX4nljFt2M/dTP6dzjEGUt4hENmtDspmIAq7fLhqMOq7xVKx5
e79m23M1Z8EraKMGLYx1kDEeBRkU0SLp3ALdaEzkFMANh3K6GAEDoFMiZ4ufT2dI
2jXDn0lVwbASvwTc7llbUrfYmiHoeZFE2QXepIZpyyJxIR1yoDqCZP9DDVvmsJXm
NUQENDWd4kKzN4k4o5gU4bRXZjOz77Qt/ZuCsX8fY6Vv4bYBesSfODlnEopPzn2L
SI7M0AGI1TynEw/bwy7GQXnIJK8j5OND8l7y5uvOmL/szfLDdbavCw5CNK/wt2rA
+bCRMEZrN8xUf9eny5F8u0lQYAbmUsM195ORtNlKH3+1tbQ=
-----END CERTIFICATE-----

This is the same blocker reported in the two Synergy threads (2820 and 2825), both of which auto-closed unresolved — so a confirmation here would help other device providers too.
Thanks!

Hi @shahid,

We have uploaded Root CA and Sub CA certificates. could you please try uploading the partner certificate now

Regards,
Team MOSIP

Hi @Varaniya1,

Thank you — the Root CA and Sub CA are loaded, and my partner certificate uploaded successfully (Device Provider, DEVICE domain). Onboarding is moving well.

Next blocker: I’ve added my SBI (version 1.0.0) under Device Provider Services, and it’s now “Pending For Approval.” The portal won’t let me add devices until a Partner Admin approves the SBI.

Could you please approve the pending SBI for Device Provider HYF (partner ID shahid) so I can proceed to add and register my devices? Happy to share any details you need.

Thanks again for the quick help!

Hi @Varaniya1,

Following up on this — the SBI is still showing “Pending For Approval” and I’m unable to add devices until it’s approved.

To recap the exact state:

  • Root CA + Sub CA: loaded :white_check_mark:
  • Partner certificate (Device Provider, DEVICE domain): uploaded :white_check_mark:
  • SBI version 1.0.0 under Device Provider Services: Pending For Approval :hourglass_not_done:
  • Partner ID: shahid — Device Provider HYF

Two questions:

  1. Who can approve the pending SBI, or is there something still required from my side? If approval sits with a different team, I’m happy to be pointed to the right place.
  2. Separately — for verifying the JWS signatures on MOSIP’s responses (encryption certificate and device registration), could you share the response-signing certificate for the Collab environment? Our management server verifies every signed response against a configured trust anchor before using it, so we need that certificate before the first live call.

Once the SBI is approved, I can register devices and complete the integration test.

Thanks again for your help so far.

Hi @Varaniya1 & @mrudula,

Following up again — thank you for loading our Root and Sub CA and confirming the partner certificate earlier. Onboarding is complete except for one step that needs a Partner Admin.

Our SBI (version 1.0.0) for Device Provider HYF (partner ID shahid) has been “Pending For Approval” since 16 July. The portal won’t let us add devices until it’s approved, so we’re fully blocked on this single action.

Could you approve it, or point me to the right Partner Admin? Happy to provide any details.

Separately, so I only ask once: to make MOSIP API calls (device registration, encryption certificate), we’ll need partner API credentials (clientId / secretKey / appId) for the Collab environment — could you advise how to obtain those?

Thanks again for the quick help before.

@Varaniya1 @mrudula @swethan1718,
Following up again. Your last response here was 15 days ago; we replied the next day and followed up again and again, without a response — and this thread is now set to auto‑close tomorrow, so I’m posting to keep it open. We remain fully blocked on a single action.

Hi @shahid

Let me check on the status and provide the approval for the same for you to proceed

Regards,
Team MOSIP

Thank you @Varaniya1 — really appreciate you picking this up. Please let me know if you need anything from my side to complete the approval, and I’ll send it right over. A rough ETA would help me line up the next steps. Standing by.

Hi @shahid,

approval is done as you have requested.

Please let me know if you are facing any concerns.

Regards,
Varaniya S
Team MOSIP

Hi @Varaniya1,

Thank you so much — I can confirm the SBI (v1.0.0) is now Approved. Really appreciate the quick turnaround. :folded_hands:

I’ve now added our devices under it, and both are showing “Pending for Approval”:

  • Herofun RealScan-G10 — Finger
  • Herofun BK2121U — Iris

Could you please approve these two devices as well, so I can proceed to register them? Happy to share any details you need from my side.

Thanks again for all your help,
Shahid

Hi @shahid,

approval is done as you have requested.

Please let me know if you are facing any concerns.

Regards,
Rachik Sharma
Team MOSIP

Hi @Rachik_Raj_Sharma / @Varaniya1,

Thank you — I can confirm both devices are now approved. Really appreciate the quick turnaround. :folded_hands:

To proceed with actual device registration from our management server, two things I’ll need for the Collab environment:

  1. The response-signing certificate for Collab (so we can verify MOSIP’s signed responses against a trusted anchor before the first live call).
  2. Partner API credentials — clientId / secretKey / appId — for our management server to authenticate to the MOSIP APIs.

Could you point me to how to obtain these, or share them? Happy to provide any details.

Thanks again,
Shahid

Hi @shahid ,
Can you please provide some more info on the points below?

  1. Response-signing certificate - You can download the MOSIP signed certificate from the PMS portal directly. Is there anything else you are looking for?
  2. Partner API credentials - Can you please elaborate on this point? Why is this required? Once the certificates are uploaded you should be able to authenticate using the partner credentials.

Thanks & Regards
Rachik Sharma
Team MOSIP

Hi @Rachik_Raj_Sharma,

Thanks — that helps, and I think we’re aligned. To be specific:

2. Partner API credentials. I believe by “partner credentials” you mean the clientId / secretKey our partner account authenticates with — and that’s exactly what our management server uses: it calls POST /v1/authmanager/authenticate/clientidsecretkey to get a token before calling /v1/masterdata/registereddevices. So to confirm, for our partner shahid in Collab: what secretKey and appId should we use (with clientId = our partner ID)? Is the secretKey available in the PMS/Keycloak, or can you share it?

1. Response-signing certificate. To clarify — not our own partner certificate. Our server verifies the JWS signature on MOSIP’s responses (the registered-devices and encryption-certificate responses) against a trusted anchor before using them. For that we need MOSIP’s response-signing certificate for Collab — the public cert MOSIP signs its responses with. Is that published, or available from a keymanager endpoint?

Thanks a lot,
Shahid