Skip to content
This repository has been archived by the owner on Nov 17, 2023. It is now read-only.

Put Client-Certificates in Organization Resources to Test Allow List Updates #143

Open
hhund opened this issue Oct 27, 2020 · 0 comments
Open
Labels
enhancement New feature or request

Comments

@hhund
Copy link
Member

hhund commented Oct 27, 2020

We might want to put the full client certificates into our organization resources instead of just a certificate hash. This would enable us to test entries in the allow list transaction bundle. For example we could test if the Organization.identifier (http://highmed.org/fhir/NamingSystem/organization-identifier) matches part of the certificates common name (CN) and if the organization name (O) matches Organization.name. In case of test failures a user task (#140, #141) could be used to decide to update the allow list anyways.

@hhund hhund added the enhancement New feature or request label Oct 28, 2020
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant