Server to Server Root Certificate Authority Change 2025

Server to Server Root Certificate Authority Change 2025

IMPORTANT: The security of your data and the data of your customers is critically important to us. We are continually reviewing and implementing greater technology security measures to ensure your data is protected.

We will be implementing new security infrastructure to further protect your data and ensure the availability of the Westpac/Qvalent services.

What are the changes?

As part of continuous security improvements, Westpac has changed the Root Certificate Authority (CA) provided for the issuing of new certificates.

The following URLs will have the SSL/TLS certificates replaced:

Non-Production URLs

Product

URLs

Date of Change

Product

URLs

Date of Change

PayWay Classic API

QuickGateway

https://ccapi.client.staging.qvalent.com

https://ccapi.client.support.qvalent.com

COMPLETE
Completed January 2025

iLink REST API

iLink SOAP

QuickWeb Secure Token Requests

https://ws.staging.qvalent.com

https://ws.support.qvalent.com

COMPLETE
Completed January 2025

Web browser access to all products

complete
Scheduled for 30 Sep 2025 

QuickStream REST API

PaymentsPlus REST API

PayWay REST API

Bankrec API

complete
Scheduled for 30 Sep 2025 

Production URLs

Products

URLs

Date of Change

Products

URLs

Date of Change

Web browser access to all products

complete
Scheduled for 30 Sep 2025 

QuickStream REST API

PaymentsPlus REST API

PayWay REST API

Bankrec API

Complete
Scheduled for 14 Oct 2025 

PayWay Classic API

QuickGateway

https://ccapi.client.qvalent.com

completed
Scheduled for 21 Oct 2025 

iLink REST API

iLink SOAP

QuickWeb Secure Token Requests

https://ws.qvalent.com

completed
Scheduled for 21 Oct 2025 

When will this change take place?

The change will be implemented as per the above schedule, and will involve replacing the existing certificates for these URLs that were issued by Entrust with new certificates issued by DigiCert. If you experience any issues connecting to the URLs post these changes, please refer to the Further Information page, or contact the Qvalent Help Desk directly. 

Why is Westpac making this change?

In 2024, Google advised that Chrome would not trust certificates issued by Entrust after 11 November, 2024 - see https://security.googleblog.com/2024/06/sustaining-digital-certificate-security.html . This announcement was subsequently mirrored by Mozilla and other service providers. As part of our continuous security improvements, as certificates are renewed, they will be issued by a different certificate provider (DigiCert).

How does this change affect my application?

When your application connects to one of the above URLs, it validates the certificate issued to these hosts comes from a trusted certificate authority.

If you do not have the new DigiCert root certificate authority hosts in your repository, then your application will not trust the Qvalent host. If this happens, your application will not connect to our web service.

What certificates are being changed?

Qvalent will begin to issue server certificates for the above hosts from the following Root and Intermediate Certificates:

Root certificate

Common Name (CN)

DigiCert Global Root G2

Valid Until

15 JAN 2038

Thumbprint

df 3c 24 f9 bf d6 66 76 1b 26 80 73 fe 06 d1 cc 8d 4f 82 a4

Available from DigiCert at

https://cacerts.digicert.com/DigiCertGlobalRootG2.crt.pem

Intermediate Certificate

Common Name (CN)

DigiCert EV RSA CA G2

Issued By

DigiCert Global Root G2

Valid Until

02 JULY 2030

Thumbprint

09 0a 16 f9 ba 16 00 1b 2e c1 30 f8 05 23 e5 b5 eb 25 91 58

Available from DigiCert at

https://cacerts.digicert.com/DigiCertEVRSACAG2.crt.pem

What must I do?

  1. Read this detailed change advice and ensure it reaches all application owners which connect to Qvalent services to investigate the impact of this change.

  2. Identify all applications which interact with these URLs and take action to prepare for this change.

  3. Validate preparedness of applications and systems for this change by ensuring all systems have the DigiCert Root CA in their application’s trust store.

    • This procedure varies depending on your application technology.

    • Please refer to the Further Information page for more detailed information regarding this change.

  4. Perform testing with your application and the non-production URLs to ensure any changes are successful.

Contact Us

Product

Email

Phone

Hours (AEST/AEDT)

Product

Email

Phone

Hours (AEST/AEDT)

PayWay

1300 727 111

8:30am - 5:30pm, Mon - Fri

PaymentsPlus

1300 325 402

8:30am - 5:30pm, Mon - Fri

QuickStream

1300 726 370

7:00am - 7:00pm, Mon - Fri

iLink

1300 726 370

7:00am - 7:00pm, Mon - Fri

Disclaimer

These guidelines are general in nature and have been prepared without knowledge of the specific environment in which your systems operate. These guidelines are current at the time of writing, but may require update over time. Except where contrary to law, Westpac intends by this notice, to exclude liability for these guidelines and the information contained in them. While Westpac has made every effort to ensure these guidelines are free from error, Westpac does not warrant their accuracy, adequacy or completeness.