...
What is happening?Starting in September October 2024, we will begin enabling TLSv1.3 and disabling CBC ciphers which are now considered insecure, please see below the schedule for disablement. This approach will prevent any TLS connections that use only CBC ciphers from connection to access Qvalent/Westpac services as per our obligations for PCI compliance. |
...
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 (0xc02f
)
ALL QVALENT TEST ENVIRONMENTS HAVE CBC CIPHERS DISABLED AND TLSv1.3 ENABLED
How do I know if we are ready for this change?
...
Westpac Quickstream (including QuickWeb, QuickConnect, QuickVault, QuickView, QuickTerminal, QuickGateway, REST etc.)
Westpac PayWay (including PayWay Net, API, Virtual Terminal etc.)
Westpac iLink
Westpac QuickSuper
Westpac Payments Plus
Westpac Invoice Finance
Westpac BankRec
There two are different channels that need encryption to access Qvalent/Westpac services. These channels are:
...
To quickly test your browser compatibility, you can visit our test page, which has the new TLS settings implemented.
...
Secure token request for QuickWeb, QuickConnect, QuickVault, and PayWay Net.
API requests for QuickGateway, QuickVault, PayWay API, REST API or iLink HTTPS/SOAP
If you have implemented any of these features, make sure you have enabled the TLS v1.2 encryption protocol.
...
Perform a API request to the test environment.
If you do not receive a TLS handshake error message then the underlying TLS connection was successful using the updated ciphers.
PayWay
Point your test environment to connect to the PayWay. You may have implemented
PayWay Net with a secure token request, or
PayWay API
Perform a secure token request or API request using the TEST merchant.
If you do not receive a TLS handshake error message then the underlying TLS connection was successful using the updated ciphers.
...
Services | CBC disablement and TLSv1.3 enablement schedule |
---|---|
Test environments (all)
| *.staging.qvalent.com was implemented 20th May, 2024. *.support.qvalent.com will be have TLSv1.3 enabled and CBC ciphers disabled on 3rd of July 2024. |
Production environments (web browser access)
| October 2, 2024 |
Production environments (REST API integration): | October 8, 2024 |
Production environments (API integration):
| October 15, 2024 |
Production environments (Token Requests):
| October 22, 2024 |
Production environments (file transfer):
| October 29, 2024 |
...