A2A certificates - KDPW

A2A certificates

Modernisation of A2A communication

The work undertaken by the KDPW Group in this area is aimed at continuously improving the security of the IT systems used in the services provided to you in response to new risks to cyber security. In this regard, secure connections between IT systems in the A2A model are particularly relevant, both for the communication and in the context of ensuring the continuity of services.

At the same time, we are standardising A2A communication functions across all services provided by the KDPW Group. As part of the planned changes, we will modernise the issuing and use of electronic certificates used for authentication in MQ-based communication systems.

Furthermore, the certificates will no longer be personal, their construction will be standardised (in particular by introducing uniform cryptographic algorithms), as will their secured storage, and the use of certificates will be uniform across all KDPW Group services.

The process of applying for a certificate will be handled by a dedicated application within the Services Portal online.kdpw.pl based on a private key generated directly by the applicant.
Moreover, uniform rules will be introduced as regards segregation of services within A2A communication, unification of names in queue configuration, and management of access to test environments.

The changes will be implemented in two steps:
  • In the first step, the changes covered the A2A communication of the EMIR TR, SFTR TR, ARM (excluding SWI communications), and LEI services – implementation of these changes took place on May 2023.
  • Stage two of the project will include an upgrade in the area of SWI communication, i.e., in the area concerning services for KDPW’s direct participants (including ARM and Compensation Scheme services) and KDPW_CCP clearing members.
    As part of the changes, in addition to the transfer of the model introduced in stage one of the project to the SWI services area, authentication for MQ communication in KDPW and KDPW_CCP will be separated at the KDPW Group level. This means that you will need to request a separate certificate to establish A2A communication with KDPW_CCP. We will also change the ESDK protocol by waiving verification of the digital signature of transmitted messages. The whole process will involve changes that move away from the current model of bilateral agreements and the SWI Rules.
    The changes are planned to be rolled out in late 2024.