Server to Server Root Certificate Authority Change 2025
IMPORTANT: The security of your data and the data of your customers is critically important to us. We are continually reviewing and implementing greater technology security measures to ensure your data is protected. We will be implementing new security infrastructure to further protect your data and ensure the availability of the Westpac/Qvalent services. |
What are the changes?
As part of continuous security improvements, Westpac has changed the Root Certificate Authority (CA) provided for the issuing of new certificates.
The following URLs will have the SSL/TLS certificates replaced:
Non-Production URLs
Product | URLs | Date of Change |
|---|---|---|
PayWay Classic API QuickGateway | COMPLETE | |
iLink REST API iLink SOAP QuickWeb Secure Token Requests | COMPLETE | |
Web browser access to all products |
| complete |
QuickStream REST API PaymentsPlus REST API PayWay REST API Bankrec API |
| complete |
Production URLs
Products | URLs | Date of Change |
|---|---|---|
Web browser access to all products |
| complete |
QuickStream REST API PaymentsPlus REST API PayWay REST API Bankrec API | Complete | |
PayWay Classic API QuickGateway | completed | |
iLink REST API iLink SOAP QuickWeb Secure Token Requests | completed |
When will this change take place?
The change will be implemented as per the above schedule, and will involve replacing the existing certificates for these URLs that were issued by Entrust with new certificates issued by DigiCert. If you experience any issues connecting to the URLs post these changes, please refer to the Further Information page, or contact the Qvalent Help Desk directly.
Why is Westpac making this change?
In 2024, Google advised that Chrome would not trust certificates issued by Entrust after 11 November, 2024 - see https://security.googleblog.com/2024/06/sustaining-digital-certificate-security.html . This announcement was subsequently mirrored by Mozilla and other service providers. As part of our continuous security improvements, as certificates are renewed, they will be issued by a different certificate provider (DigiCert).
How does this change affect my application?
When your application connects to one of the above URLs, it validates the certificate issued to these hosts comes from a trusted certificate authority.
If you do not have the new DigiCert root certificate authority hosts in your repository, then your application will not trust the Qvalent host. If this happens, your application will not connect to our web service.
What certificates are being changed?
Qvalent will begin to issue server certificates for the above hosts from the following Root and Intermediate Certificates:
Root certificate
Common Name (CN) | DigiCert Global Root G2 |
Valid Until | 15 JAN 2038 |
Thumbprint | df 3c 24 f9 bf d6 66 76 1b 26 80 73 fe 06 d1 cc 8d 4f 82 a4 |
Available from DigiCert at |
Intermediate Certificate
Common Name (CN) | DigiCert EV RSA CA G2 |
Issued By | DigiCert Global Root G2 |
Valid Until | 02 JULY 2030 |
Thumbprint | 09 0a 16 f9 ba 16 00 1b 2e c1 30 f8 05 23 e5 b5 eb 25 91 58 |
Available from DigiCert at |
What must I do?
Read this detailed change advice and ensure it reaches all application owners which connect to Qvalent services to investigate the impact of this change.
Identify all applications which interact with these URLs and take action to prepare for this change.
Validate preparedness of applications and systems for this change by ensuring all systems have the DigiCert Root CA in their application’s trust store.
This procedure varies depending on your application technology.
Please refer to the Further Information page for more detailed information regarding this change.
Perform testing with your application and the non-production URLs to ensure any changes are successful.
Contact Us
Product | Phone | Hours (AEST/AEDT) | |
|---|---|---|---|
PayWay | 1300 727 111 | 8:30am - 5:30pm, Mon - Fri | |
PaymentsPlus | 1300 325 402 | 8:30am - 5:30pm, Mon - Fri | |
QuickStream | 1300 726 370 | 7:00am - 7:00pm, Mon - Fri | |
iLink | 1300 726 370 | 7:00am - 7:00pm, Mon - Fri |
Disclaimer
These guidelines are general in nature and have been prepared without knowledge of the specific environment in which your systems operate. These guidelines are current at the time of writing, but may require update over time. Except where contrary to law, Westpac intends by this notice, to exclude liability for these guidelines and the information contained in them. While Westpac has made every effort to ensure these guidelines are free from error, Westpac does not warrant their accuracy, adequacy or completeness.