How do the three QWAC profiles differ?
ETSI EN 319 411-2 defines three EU qualified website authentication certificate policy profiles: QEVCP-w, QNCP-w, and QNCP-w-gen. The profile choice is not cosmetic because the selected policy determines which EN 319 411-1 baseline, CA/Browser Forum dependency, and qualified-certificate additions must be reflected in the CP, CPS, certificate profile, and evidence pack.
Choose QEVCP-w when the qualified website certificate is issued to a legal person and follows the Extended Validation Certificate Policy route. Choose QNCP-w when the route is based on NCP plus either OVCP or IVCP. Choose QNCP-w-gen when the service is a general-purpose qualified website authentication certificate route based on NCP plus selected web-authentication requirements in EN 319 411-1.
- QEVCP-w: legal-person QWAC route based on EVCP and the CA/Browser Forum Extended Validation Guidelines.
- QNCP-w: natural-person or legal-person QWAC route based on NCP plus OVCP or IVCP and the CA/Browser Forum Baseline Requirements.
- QNCP-w-gen: general-purpose QWAC route based on NCP plus selected web-authentication requirements in EN 319 411-1.
Clauses 4.2.2, 5.1, and 5.3 define QEVCP-w, QNCP-w, and QNCP-w-gen and map them to EVCP, NCP, OVCP, IVCP, BRG, EVCG, and web-authentication dependencies.
EN 319 411-1 supplies the EVCP, OVCP, IVCP, NCP, and web-authentication requirements that EN 319 411-2 builds on for qualified website authentication profiles.