Due to a change by the supplier Digicert, our api gateway server certificates are required to change to a new root CA certificate during their next rotation. From 20/03/2024 our first production certificates with the old root CA will expire.
The new root CA can be downloaded from the official Digicert website, here: https://cacerts.digicert.com/DigiCertGlobalRootG2.crt.pem
This is the link to the complete chain (with new intermediate): https://cacerts.digicert.com/DigiCertGlobalG2TLSRSASHA2562020CA1-1.crt.pem
Please add the new root CA to your truststore before 20/3/2024. Do not delete the old certificate before this date.
The actual switch itself is without any interruption or impact, but when the client is not configured correctly to trust this new root CA, the client will refuse to connect to the KBC API gateway. In this case no connectivity will happen at all.
The production hostnames in scope:
- psd2.api.cbc.be
- psd2.api.kbc.be
- psd2.api.kbcbrussels.be
- psd2.api.kbc-group.com