You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于创建含QWAC、QSealC配置文件及PSD2特定属性的eIDAS测试证书的技术咨询

Hey there! Let's break down how to create a test eIDAS certificate that checks all the boxes for ETSI TS 119 495—including QWAC/QSealC profiles and PSD2-specific attributes. Since this is strictly for testing, we'll use open-source tools and self-signed CA setups (definitely don't use this for production!)

1. Prerequisites

First, make sure you have the right tools in place:

  • Install the latest version of OpenSSL (v3.0+ recommended, as it supports the X.509 extensions required for eIDAS)
  • Create a dedicated working directory to store all your CA and certificate files (keeps things organized!)
2. Set Up a Test eIDAS Root CA (Self-Signed)

eIDAS certificates need to chain up to a qualified root CA. For testing, we'll create a self-signed root CA.

First, create a root CA config file (e.g., eidas_root_ca.cnf) with core eIDAS attributes:

[req]
distinguished_name = req_distinguished_name
x509_extensions = v3_ca
prompt = no

[req_distinguished_name]
C = EU
O = Test eIDAS Root CA
CN = Test eIDAS Root CA - PSD2 Testing

[v3_ca]
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer
basicConstraints = critical,CA:true
keyUsage = critical,keyCertSign,cRLSign

Then run these commands to generate the root CA key and certificate:

# Generate root CA private key (keep this secure even for testing!)
openssl genrsa -out eidas_root_ca.key 4096

# Create self-signed root CA certificate
openssl req -x509 -new -nodes -key eidas_root_ca.key -sha256 -days 365 -out eidas_root_ca.crt -config eidas_root_ca.cnf
3. Create a Subordinate CA for QWAC/QSealC

Qualified certificates like QWAC/QSealC must be issued by a subordinate qualified CA. Let's create one signed by our root CA.

Make a subordinate CA config (eidas_sub_ca.cnf):

[req]
distinguished_name = req_distinguished_name
x509_extensions = v3_sub_ca
prompt = no

[req_distinguished_name]
C = EU
O = Test eIDAS Subordinate CA (QWAC/QSealC)
CN = Test eIDAS Sub CA - PSD2 Testing

[v3_sub_ca]
subjectKeyIdentifier = hash
authorityKeyIdentifier = keyid:always,issuer
basicConstraints = critical,CA:true,pathlen:0
keyUsage = critical,keyCertSign,cRLSign
certificatePolicies = 2.23.136.1.1.1 ; eIDAS qualified policy OID

Generate the subordinate CA key, CSR, and sign it with the root CA:

# Generate sub CA private key
openssl genrsa -out eidas_sub_ca.key 4096

# Create CSR for the sub CA
openssl req -new -key eidas_sub_ca.key -out eidas_sub_ca.csr -config eidas_sub_ca.cnf

# Sign the CSR with the root CA
openssl x509 -req -in eidas_sub_ca.csr -CA eidas_root_ca.crt -CAkey eidas_root_ca.key -CAcreateserial -out eidas_sub_ca.crt -days 180 -sha256 -extfile eidas_sub_ca.cnf -extensions v3_sub_ca
4. Generate QWAC Certificate with PSD2 Attributes

QWAC (Qualified Website Authentication Certificate) is used for TLS authentication in PSD2. Create a config file (qwac_psd2.cnf) with all required extensions:

[req]
distinguished_name = req_distinguished_name
req_extensions = v3_req
prompt = no

[req_distinguished_name]
C = EU
O = Test Payment Service Provider
CN = psd2.test.example.com
businessCategory = PSD2 Payment Service Provider
jurisdictionCountryName = EU

[v3_req]
subjectAltName = @alt_names
keyUsage = critical,digitalSignature,keyEncipherment
extendedKeyUsage = serverAuth,clientAuth
basicConstraints = critical,CA:false
certificatePolicies = 2.23.136.1.1.2 ; QWAC policy OID
qualifiedCertificate = critical,yes
qcStatements = @qc_statements
psd2Attributes = @psd2_attrs

[alt_names]
DNS.1 = psd2.test.example.com
IP.1 = 192.168.1.100 ; Optional, for local test environments

[qc_statements]
qcStatement.1 = 1.3.6.1.4.1.14562.1.1.1 ; QWAC profile OID
qcStatement.2 = 1.3.6.1.4.1.14562.1.2.1 ; PSD2 role OID

[psd2_attrs]
psd2Role = 1.3.6.1.4.1.14562.1.2.1.1 ; AISP role
psd2Role = 1.3.6.1.4.1.14562.1.2.1.2 ; PISP role
psd2AuthorisationNumber = EU.XX.YYYYYYYYYYYYYYYYYYY ; Test auth number (match your country's format)

Now generate the QWAC key, CSR, and sign it with the subordinate CA:

# Generate QWAC private key
openssl genrsa -out qwac_psd2.key 2048

# Create QWAC CSR
openssl req -new -key qwac_psd2.key -out qwac_psd2.csr -config qwac_psd2.cnf

# Sign the CSR with the subordinate CA
openssl x509 -req -in qwac_psd2.csr -CA eidas_sub_ca.crt -CAkey eidas_sub_ca.key -CAcreateserial -out qwac_psd2.crt -days 90 -sha256 -extfile qwac_psd2.cnf -extensions v3_req
5. Generate QSealC Certificate with PSD2 Attributes

QSealC (Qualified Seal Certificate) is for non-repudiation of PSD2 messages. Create a config file (qsealc_psd2.cnf):

[req]
distinguished_name = req_distinguished_name
req_extensions = v3_req
prompt = no

[req_distinguished_name]
C = EU
O = Test Payment Service Provider
CN = PSD2 Test Seal - Example PSP
businessCategory = PSD2 Payment Service Provider
jurisdictionCountryName = EU

[v3_req]
keyUsage = critical,digitalSignature,nonRepudiation
extendedKeyUsage = codeSigning,emailProtection
basicConstraints = critical,CA:false
certificatePolicies = 2.23.136.1.1.3 ; QSealC policy OID
qualifiedCertificate = critical,yes
qcStatements = @qc_statements
psd2Attributes = @psd2_attrs

[qc_statements]
qcStatement.1 = 1.3.6.1.4.1.14562.1.1.2 ; QSealC profile OID
qcStatement.2 = 1.3.6.1.4.1.14562.1.2.1 ; PSD2 role OID

[psd2_attrs]
psd2Role = 1.3.6.1.4.1.14562.1.2.1.3 ; PIISP role (adjust as needed)
psd2AuthorisationNumber = EU.XX.YYYYYYYYYYYYYYYYYYY ; Same test auth number as QWAC

Generate the QSealC key, CSR, and sign it:

# Generate QSealC private key
openssl genrsa -out qsealc_psd2.key 2048

# Create QSealC CSR
openssl req -new -key qsealc_psd2.key -out qsealc_psd2.csr -config qsealc_psd2.cnf

# Sign the CSR with the subordinate CA
openssl x509 -req -in qsealc_psd2.csr -CA eidas_sub_ca.crt -CAkey eidas_sub_ca.key -CAcreateserial -out qsealc_psd2.crt -days 90 -sha256 -extfile qsealc_psd2.cnf -extensions v3_req
6. Verify Your Certificates

To confirm your certificates meet ETSI requirements, use OpenSSL to inspect the extensions:

# Check QWAC extensions
openssl x509 -in qwac_psd2.crt -text -noout | grep -A 20 "X509v3 extensions"

# Check QSealC extensions
openssl x509 -in qsealc_psd2.crt -text -noout | grep -A 20 "X509v3 extensions"

Look for critical markers on qualifiedCertificate, matching QWAC/QSealC policy OIDs, correct qcStatements profiles, and psd2Attributes with your test roles and authorisation number.

Quick Reminders

  • Production Warning: These are test-only certificates—real PSD2 endpoints won't trust self-signed CAs. For production, you need to use an officially qualified eIDAS CA.
  • OID Accuracy: Double-check the latest ETSI draft to ensure OIDs haven't been updated.
  • Sandbox Compatibility: Some PSD2 sandboxes may require test certificates signed by their own CAs—always check their documentation first.

内容的提问来源于stack exchange,提问作者Amalka Subasinghe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.26 08:53:01