The term Qualified Certificates (QC) is used in Smart ID Certificate Manager (CM) to describe a certificate with a certain qualified status within applicable governing laws. The Qualified Certificates Profile is described in detail in rfc 3739, Internet X.509 Public Key Infrastructure: Qualified Certificates Profile (https://tools.ietf.org/html/rfc3739).
QC statements can be used when issuing both smart cards and soft tokens. The certificate procedures used may define QC statements. These statements cannot be overwritten and are visible in the token procedure chooser dialog.
This article gives an example of how to fill in QC statements and also describes how to use QC statements in certificate procedures. This task is done in the Registration Authority (RA) in Certificate Manager.
Prerequisites
Expand | ||
---|---|---|
| ||
This task requires that:
|
Step-by-step procedure
Expand | ||
---|---|---|
| ||
This is an example on how to fill in Qualified Certificates (QC) statements.
|
Expand | |||||
---|---|---|---|---|---|
| |||||
The administration officer that configures the certificate procedure to use, may specify that all certificates issued with a certificate procedure should contain a set of QC statements. As demonstrated above, it is also possible to add QC statements in the certificate request in RA. If both of these specify QC statements, the resulting certificate will contain both of these QC statements.
Refer to the specifications and requirements of the type of certificate that should be created, in order to ensure that all required QC statements are supplied. It is also possible to pre-configure a certificate format to require a set of QC statements that must be included in issued certificates, see the Technical Description for further details. |
Expand | ||
---|---|---|
| ||
One of the use-cases for QC statements is issuing certificates to be used by payment service providers in order to meet the requirements of the PSD2 Regulatory Technical Standards, as specified in ETSI TS 119 495. In particular, the following information must be included in such certificates:
The PSD2 QC statement can either be fully configured in the certificate procedure, or in the certificate request from the Registration Authority (RA). If fully specified in both (which may be an incorrect way of issuing such certificates), with different information in each, then similar to how other QC statements are handled, the resulting certificate will have two such QC statements. This may not be desired, so ensure that it is clear whether this statement should be fully configured in the certificate procedure or in the certificate request from the RA. However, for PSD2 QC statements, a common use-case is that the NCA name and identifier should likely be identical for all certificates issued per certificate procedure, while the list of PSP roles may be different per issued certificate. For this particular case, another option is available in addition to fully specifying it in either the certificate procedure or in the certificate request. To configure a combination of the NCA details and the PSP roles, do the following:
The resulting certificate will then contain only one PSD2 QC statement, with the combined information of the NCA and the PSP roles. This combination is done by examining whether the NCA details are identical or empty in each place. The Authorization Number, which is required in these certificates, must be part of the Organization Identifier in the Subject Distinguished Name, as supplied in the certificate request from the RA. The Organization Identifier must also be formatted as specified by ETSI TS 119 495 chapter 5.2.1 , and its parts of the NCA identifier must match the corresponding parts of the PSD2 QC statement in the issued certificate. |
Related information
- Create certificate procedure in Certificate Manager
- Create token procedure in Certificate Manager
- Smart ID Certificate Manager
- Registration Authority (RA) in Certificate Manager
- RA user interface in Certificate Manager
- Select fields in Registration Authority in Certificate Manager