Hi @Rachik_Raj_Sharma, @Varaniya1, and @mrudula,
We’re running CTK for our Device Provider SBI (project HYF-BK2121U-Iris-Reg-v1, Registration / Iris / Double). SchemaValidator and ResponseMismatchValidator pass; every SignatureValidator case fails with:
Trust Validation Failed for [Device Info] >> PartnerType[DEVICE] and CertificateData[...]
Our device certificate chains as the MDS spec requires:
CN=DF0052000020945A.Developer.HYF (device)
→ C=CN, O=HYF, CN=HYF Device Provider (our MOSIP Signed Certificate from PMS)
→ C=IN, O=IITB, OU=MOSIP-TECH-CENTER (PMS), CN=www.mosip.io
The full chain is in the JWS x5c header, and our Partner Certificate shows Partner Type = Device Provider (uploaded 17/07/2026).
Two questions:
- Are our Root CA and Sub CA registered in the trust store under partner domain
DEVICE? We can’t see the Certificate Trust Store as a partner, and we suspect they were added underAUTHduring onboarding. - Should device certificates chain to the MOSIP Signed Certificate (as above), or to our CA-signed partner certificate under our own Root/Sub CA?
Happy to share the full chain or a sample response.
Thanks,
Shahid