What does a QWAC prove under eIDAS?
A makes it possible to authenticate a website and link that website to the natural or legal person to whom the certificate is issued. A adds the eIDAS qualified layer: the certificate must be issued by a and meet Annex IV requirements.
A working TLS connection does not complete the check. The evidence should show who the certificate identifies, which domain names are covered, which issued it, and where relying parties can check certificate validity or revocation status.
- Confirm that the certificate is explicitly indicated as a qualified .
- Check that the subject identity, address elements, and domain names match the website or service being authenticated.
- Record the certificate validity period, serial or certificate identity code, issuer, and status-service location.
- Treat evidence as website identity evidence, not as proof that the whole transaction, application, or message payload has been sealed or signed.
What is a under the EU eIDAS Regulation?
A is a qualified . eIDAS defines it as a website-authentication certificate issued by a that meets Annex IV. It links the website to the named natural or legal person and carries required certificate information such as qualified-certificate indication, issuer identity, subject identity, domain names, validity period, certificate identity code, issuer signature or seal, and certificate-status service information.
Is a the same as an ordinary TLS certificate?
No. A can be used in the website-authentication context, but its eIDAS significance comes from qualified status, the , and Annex IV content. A normal TLS certificate may secure a connection without being a qualified under eIDAS.
Defines certificate for website authentication and qualified certificate for website authentication, including the QTSP and Annex IV elements that make the certificate qualified.
Maps eIDAS Annex IV QWAC requirements to certificate-profile fields, including qualified-certificate indication, subject identity, domain names, validity, serial number, and status-service locations.