关于创建含QWAC、QSealC配置文件及PSD2特定属性的eIDAS测试证书的技术咨询
Hey there! Let's break down how to create a test eIDAS certificate that checks all the boxes for ETSI TS 119 495—including QWAC/QSealC profiles and PSD2-specific attributes. Since this is strictly for testing, we'll use open-source tools and self-signed CA setups (definitely don't use this for production!)
First, make sure you have the right tools in place:
- Install the latest version of
OpenSSL(v3.0+ recommended, as it supports the X.509 extensions required for eIDAS) - Create a dedicated working directory to store all your CA and certificate files (keeps things organized!)
eIDAS certificates need to chain up to a qualified root CA. For testing, we'll create a self-signed root CA.
First, create a root CA config file (e.g., eidas_root_ca.cnf) with core eIDAS attributes:
[req] distinguished_name = req_distinguished_name x509_extensions = v3_ca prompt = no [req_distinguished_name] C = EU O = Test eIDAS Root CA CN = Test eIDAS Root CA - PSD2 Testing [v3_ca] subjectKeyIdentifier = hash authorityKeyIdentifier = keyid:always,issuer basicConstraints = critical,CA:true keyUsage = critical,keyCertSign,cRLSign
Then run these commands to generate the root CA key and certificate:
# Generate root CA private key (keep this secure even for testing!) openssl genrsa -out eidas_root_ca.key 4096 # Create self-signed root CA certificate openssl req -x509 -new -nodes -key eidas_root_ca.key -sha256 -days 365 -out eidas_root_ca.crt -config eidas_root_ca.cnf
Qualified certificates like QWAC/QSealC must be issued by a subordinate qualified CA. Let's create one signed by our root CA.
Make a subordinate CA config (eidas_sub_ca.cnf):
[req] distinguished_name = req_distinguished_name x509_extensions = v3_sub_ca prompt = no [req_distinguished_name] C = EU O = Test eIDAS Subordinate CA (QWAC/QSealC) CN = Test eIDAS Sub CA - PSD2 Testing [v3_sub_ca] subjectKeyIdentifier = hash authorityKeyIdentifier = keyid:always,issuer basicConstraints = critical,CA:true,pathlen:0 keyUsage = critical,keyCertSign,cRLSign certificatePolicies = 2.23.136.1.1.1 ; eIDAS qualified policy OID
Generate the subordinate CA key, CSR, and sign it with the root CA:
# Generate sub CA private key openssl genrsa -out eidas_sub_ca.key 4096 # Create CSR for the sub CA openssl req -new -key eidas_sub_ca.key -out eidas_sub_ca.csr -config eidas_sub_ca.cnf # Sign the CSR with the root CA openssl x509 -req -in eidas_sub_ca.csr -CA eidas_root_ca.crt -CAkey eidas_root_ca.key -CAcreateserial -out eidas_sub_ca.crt -days 180 -sha256 -extfile eidas_sub_ca.cnf -extensions v3_sub_ca
QWAC (Qualified Website Authentication Certificate) is used for TLS authentication in PSD2. Create a config file (qwac_psd2.cnf) with all required extensions:
[req] distinguished_name = req_distinguished_name req_extensions = v3_req prompt = no [req_distinguished_name] C = EU O = Test Payment Service Provider CN = psd2.test.example.com businessCategory = PSD2 Payment Service Provider jurisdictionCountryName = EU [v3_req] subjectAltName = @alt_names keyUsage = critical,digitalSignature,keyEncipherment extendedKeyUsage = serverAuth,clientAuth basicConstraints = critical,CA:false certificatePolicies = 2.23.136.1.1.2 ; QWAC policy OID qualifiedCertificate = critical,yes qcStatements = @qc_statements psd2Attributes = @psd2_attrs [alt_names] DNS.1 = psd2.test.example.com IP.1 = 192.168.1.100 ; Optional, for local test environments [qc_statements] qcStatement.1 = 1.3.6.1.4.1.14562.1.1.1 ; QWAC profile OID qcStatement.2 = 1.3.6.1.4.1.14562.1.2.1 ; PSD2 role OID [psd2_attrs] psd2Role = 1.3.6.1.4.1.14562.1.2.1.1 ; AISP role psd2Role = 1.3.6.1.4.1.14562.1.2.1.2 ; PISP role psd2AuthorisationNumber = EU.XX.YYYYYYYYYYYYYYYYYYY ; Test auth number (match your country's format)
Now generate the QWAC key, CSR, and sign it with the subordinate CA:
# Generate QWAC private key openssl genrsa -out qwac_psd2.key 2048 # Create QWAC CSR openssl req -new -key qwac_psd2.key -out qwac_psd2.csr -config qwac_psd2.cnf # Sign the CSR with the subordinate CA openssl x509 -req -in qwac_psd2.csr -CA eidas_sub_ca.crt -CAkey eidas_sub_ca.key -CAcreateserial -out qwac_psd2.crt -days 90 -sha256 -extfile qwac_psd2.cnf -extensions v3_req
QSealC (Qualified Seal Certificate) is for non-repudiation of PSD2 messages. Create a config file (qsealc_psd2.cnf):
[req] distinguished_name = req_distinguished_name req_extensions = v3_req prompt = no [req_distinguished_name] C = EU O = Test Payment Service Provider CN = PSD2 Test Seal - Example PSP businessCategory = PSD2 Payment Service Provider jurisdictionCountryName = EU [v3_req] keyUsage = critical,digitalSignature,nonRepudiation extendedKeyUsage = codeSigning,emailProtection basicConstraints = critical,CA:false certificatePolicies = 2.23.136.1.1.3 ; QSealC policy OID qualifiedCertificate = critical,yes qcStatements = @qc_statements psd2Attributes = @psd2_attrs [qc_statements] qcStatement.1 = 1.3.6.1.4.1.14562.1.1.2 ; QSealC profile OID qcStatement.2 = 1.3.6.1.4.1.14562.1.2.1 ; PSD2 role OID [psd2_attrs] psd2Role = 1.3.6.1.4.1.14562.1.2.1.3 ; PIISP role (adjust as needed) psd2AuthorisationNumber = EU.XX.YYYYYYYYYYYYYYYYYYY ; Same test auth number as QWAC
Generate the QSealC key, CSR, and sign it:
# Generate QSealC private key openssl genrsa -out qsealc_psd2.key 2048 # Create QSealC CSR openssl req -new -key qsealc_psd2.key -out qsealc_psd2.csr -config qsealc_psd2.cnf # Sign the CSR with the subordinate CA openssl x509 -req -in qsealc_psd2.csr -CA eidas_sub_ca.crt -CAkey eidas_sub_ca.key -CAcreateserial -out qsealc_psd2.crt -days 90 -sha256 -extfile qsealc_psd2.cnf -extensions v3_req
To confirm your certificates meet ETSI requirements, use OpenSSL to inspect the extensions:
# Check QWAC extensions openssl x509 -in qwac_psd2.crt -text -noout | grep -A 20 "X509v3 extensions" # Check QSealC extensions openssl x509 -in qsealc_psd2.crt -text -noout | grep -A 20 "X509v3 extensions"
Look for critical markers on qualifiedCertificate, matching QWAC/QSealC policy OIDs, correct qcStatements profiles, and psd2Attributes with your test roles and authorisation number.
Quick Reminders
- Production Warning: These are test-only certificates—real PSD2 endpoints won't trust self-signed CAs. For production, you need to use an officially qualified eIDAS CA.
- OID Accuracy: Double-check the latest ETSI draft to ensure OIDs haven't been updated.
- Sandbox Compatibility: Some PSD2 sandboxes may require test certificates signed by their own CAs—always check their documentation first.
内容的提问来源于stack exchange,提问作者Amalka Subasinghe

