The Service Desk Broker /token call fails with a PAM-CM-9000 error in Privileged Access Manager (PAM). This issue occurs when the broker presents an internal Certificate Authority (CA) certificate, as the cspmserver JVM does not consult the expected certificate stores to validate the connection.
PAM 4.3.1 and 4.3.2
The cspmserver JVM default truststore is not correctly updated by the CA-Bundle upload from the UI, preventing the recognition of internal CA-signed certificates for Service Desk Broker calls.
This issue is targeted to be fixed in release PAM 4.3.3
Please contact PAM Support if you need this fixed in your current PAM version 4.3.1 or 4.3.2