A2A certificates - KDPW

A2A certificates

Modernisation of A2A communication

The work undertaken by the KDPW Group in this area is aimed at continuously improving the security of the IT systems used in the services provided to you in response to new risks to cyber security. In this regard, secure connections between IT systems in the A2A model are particularly relevant, both for the communication and in the context of ensuring the continuity of services.

At the same time, we are standardising A2A communication functions across all services provided by the KDPW Group. As part of the planned changes, we will modernise the issuing and use of electronic certificates used for authentication in MQ-based communication systems.

Furthermore, the certificates will no longer be personal, their construction will be standardised (in particular by introducing uniform cryptographic algorithms), as will their secured storage, and the use of certificates will be uniform across all KDPW Group services.

The process of applying for a certificate will be handled by a dedicated application within the Services Portal online.kdpw.pl based on a private key generated directly by the applicant.
Moreover, uniform rules will be introduced as regards segregation of services within A2A communication, unification of names in queue configuration, and management of access to test environments.

The changes will be implemented in two steps:
  • In the first step, the changes covered the A2A communication of the EMIR TR, SFTR TR, ARM (excluding SWI communications), and LEI services – implementation of these changes took place on May 2023.
  • January 2025 - modernisation of SWI communication, i.e., services for KDPW direct members (including ARM and Compensation Scheme services) and KDPW_CCP clearing members.
    As part of the changes, in addition to the transfer of the model introduced in stage one of the project to the SWI services area, authentication for MQ communication in KDPW and KDPW_CCP will be separated at the KDPW Group level. This means that you will need to request a separate certificate to establish A2A communication with KDPW_CCP. We will also change the ESDK protocol by waiving verification of the digital signature of transmitted messages. The whole process will involve changes that move away from the current model of bilateral agreements and the SWI Rules.
     
12 November 2024 - Letter outlining modification to IT systems in the area of A2A communication - confirmation the date of roll-out of the complete solution
Enclosures:
1. Configuration specification for MQ A2A connections
2. Description of the ESDK protocol used for A2A communication
3. Instructions for downloading the A2A certificates used for connecting to the KDPW and KDPW_CCP services
4. Using OpenSSL to obtain a certificate for A2A communication
5. Description of the process for the implementation of changes in A2A communications covered by the ESDK protocol 
(pdf 3,68 MB)
Download file
February 7, 2024: Modifications to IT systems in the area of A2A communication
Enclosures:
1. Configuration specification for MQ A2A connections
2. Description of the ESDK protocol used for A2A communication
3. Instructions for downloading the A2A certificates used for connecting to the KDPW and KDPW_CCP services
4. Using OpenSSL to obtain a certificate for A2A communication
(pdf 891,98 KB)
Download file
May 8, 2023 - Amendments to KDPW regulations in connection with the implementation of IT system changes in A2A communication
Attachments:
1/ Specification of MQ configuration in A2A communication
2/ Instructions for downloading A2A certificates
3/ Description of the implementation of changes in A2A communication
4/ Using OpenSSL to obtain a certificate for A2A communication
contain information protected by KDPW and have been made available only to the addressees of the letter.
(pdf 126,89 KB)
Download file
March 20, 2023 - Changes to IT systems in the area of A2A communication
Annex: Specification of the planned changes for the modernisation of A2A communication
(pdf 219,03 KB)
Download file