W007
Ref | W007 |
|---|---|
Organisation | All ASPSPs and TPPs |
Date raised | Jun 25, 2019 |
Priority | HIGH |
Summary | ASPSPs and TPPs MUST NOT validate the message signature during the period of the waiver. |
Policy/standard affected | Read/Write Data API Specifications (Payment Initiation APIs v3.1, 3.1.1, 3.1.2, and 3.1.3) |
Duration (end date) | Jun 16, 2020 (see comments) |
Status | Expired |
Approved by | IE Trustee |
Approved date | Jul 23, 2019 |
Comments | Extended by the IE Trustee on Feb 24, 2020 following recommendation from TDA |
Description | The OBIE R/W API specification (in v3.0, 3.1, 3.1.1, 3.1.2 and 3.1.3) require both TPPs and ASPSPs to sign all payment messages (JSON Web Signatures JWS). Non-repudiation requirements are met through the use of a number of extensions including RFC 7797. The OBIE specification makes use of the "b64" header parameter and currently enforces the following:
The |
|---|---|
Risk assessment |
|
Mitigating controls | Immediate action
In the longer term
OBIE will work with ASPSPs, TPPs and vendors to ensure that this is effectively communicated. |
Impact if refused |
|
Financial cost (if any) £ | Not known |
Resource cost (if any) £ | Not known |