The National Stock Exchange (NSE) on October 26, 2023, issued a circular regarding the Encryption/Decryption of Interactive Messages.
To enhance the security posture for interactive messages, encryption of these messages on an end-to-end basis is necessary. Accordingly, a software solution-based approach (a combination of TLS 1.3 security protocol and AES-256 bits-based symmetric encryption) is being implemented for the encryption of interactive message traffic between member applications and Exchange. While encryption of messages within member environments towards their clients will need to be done by respective members.
The following important instructions for implementation have been stated:
• An interim coexistence phase for accepting both encrypted and non-encrypted message traffic shall be provided by the Exchange, after which the Exchange shall discontinue the non-encrypted message flow.
• Members using via Direct connection via NNF API protocols shall be required to download a CA certificate for validation of Gateway Router server certificate from the extranet path /common/Encryption_CA_Certificate. The CA certificate shall be available for download from November 3, 2023, at 18:00 hours onwards.
• Direct connection users can use the above certificate to verify the Gateway Router server certificate after SSL connection with Gateway Router. It is an additional step to ensure that the direct connection user is connected to the authenticated Gateway Router.
[Circular No: 136/2023]