Uploaded image for project: 'FHIR Specification Feedback'
  1. FHIR Specification Feedback
  2. FHIR-36620

question about support of TSL

    XMLWordPrintableJSON

Details

    • Icon: Change Request Change Request
    • Resolution: Persuasive
    • Icon: Highest Highest

    Description

      Does this sentence "PAS Servers SHOULD support server-server OAuth and MAY support mutually authenticated TLS"

      conflict with the DV P&S principles which state:

      When the identity of the requesting or receiving party is important, implementations SHOULD use one or more of the following as defined in the specific Da Vinci IG:
      the SMART on FHIR Framework ,
      mutually authenticated TLS ,
      the ONC FHIR At Scale Taskforce (FAST) security tiger team recommended solutions, or
      the OAuth Server to Server Authentication as defined in the Bulk Data exchange IG.

      Attachments

        Activity

          People

            Unassigned Unassigned
            celine_lefebvre Celine Lefebvre
            Celine Lefebvre
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: