Skip to content

Is anyone doing any validation of "who" is sending messages to a NON SSL TCP Listener channel? #5980

Discussion options

You must be logged in to vote

On your last comment - Are you already allowing by the explicit IP addresses of the other sides integration engine (rather than allow all from the other side)? If yes, short of what you mentioned in your initial post of checking MSH stuff, you would have to ask the client to participate in some shared credentialing within the HL7 message itself that would likely need to be token based and thereby expire and require renewal, I suppose other schemes would work of course. That is likely a heavy lift on their side.

If management said "you must validate the messages" I would move the hl7 over HTTPS with JWTs.

Replies: 1 comment 8 replies

Comment options

You must be logged in to vote
8 replies
@JeffBenedict
Comment options

@pacmano1
Comment options

@pacmano1
Comment options

Answer selected by JeffBenedict
@JeffBenedict
Comment options

@pacmano1
Comment options

@jonbartels
Comment options

@JeffBenedict
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants