2 ms·
He's right though, to acquire a cert that a bank will accept you need to be an AISP [0] or a PISP (or both) [1]. In other words: you need a license from a regu
by sjaak 4y ago
He's right though, to acquire a cert that a bank will accept you need to be an AISP [0] or a PISP (or both) [1]. In other words: you need a license from a regulatory body of one of the PSD2 countries
To talk to a bank's PSD2 API you often need /both/ a QWAC and a QSEALC cert. A QWAC cert is basically a normal TLS (client) cert with some PSD2 specific OIDs like the QC Statement (0.4.0.1862) [2] that a bank can use to identify who you are and which authority gave you a license (for AISP / PISP activities). The QSEALC is typically used to sign the http requests at the application level in the form of an extra http header (X-Signature or something similar).
The above is all moot though, if you just want to do payouts I recommend you stay far away from PSD2
[0] Account Information Service Provider = AISP; Payment Initiation Service Provider = PISP
[1] https://www.entrust.com/-/media/documentation/datasheets/qualified-website-certificates-ss.pdf?la=en&hash=8E4D55A8470C3769CB5A2E2AE5D69036 https://www.entrust.com/-/media/documentation/datasheets/qua...
[2] see 5.1 in here https://www.etsi.org/deliver/etsi_ts/119400_119499/119495/01.06.01_60/ts_119495v010601p.pdf https://www.etsi.org/deliver/etsi_ts/119400_119499/119495/01...