Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Tip

This change only affects customers whom are connecting to our Hl7 API over the Public Internet , which is the minority. Majority of connections are made over and not using HSCN.

New endpoints

We plan to introduce three new endpoints on Port 443:

...

  • up-to-date client software toosl tools that support to the state of the art cipher suitssuites,

  • have static IPs that we can allow-list and

  • can’t allocate budget to implement mTLS in short term

...

deprecated-ciphers.no-mtls.hl7.uk.patientsknowbest.com is intended as a short term solution for customers whom are on ore out of date software systems hence still who are not as yet up to date with their software systems and still require support for using ciphers that are considered to be weak and cannot update their system in short term.

Note

We urge all our customers to get their systems up to date as it is a common best interest to exchange data as safely as possible.

Standard ports

Using standard ports (443) will allow us to consolidate our server certificate management and fully automate the renewall process for all our endpoints.

...

Legend

  • (tick) supported,

  • (error) not-supported,

  • (question) might be supported, but our stats indicates that nobody is using it in production,

  • ‼️some customers are using it, but we cannot support these ciphers on the new endpoints.(error) *: not supported (for technical reasons)

Name (OpenSSL)

mtls

no-mtls

deprecated-ciphers.no-mtls

TLS_AES_128_GCM_SHA256

Status
colourGreen
titlerecommended

(tick)

(tick)

(tick)

TLS_AES_256_GCM_SHA384

Status
colourGreen
titlerecommended

(tick)

(tick)

(tick)

TLS_CHACHA20_POLY1305_SHA256

Status
colourGreen
titlerecommended

(tick)

(tick)

(tick)

ECDHE-ECDSA-AES128-GCM-SHA256

Status
colourGreen
titlerecommended

(tick)

(tick)

(tick)

ECDHE-ECDSA-AES256-GCM-SHA384

Status
colourGreen
titlerecommended

(tick)

(tick)

(tick)

ECDHE-ECDSA-CHACHA20-POLY1305

Status
colourGreen
titlerecommended

(tick)

(tick)

(tick)

ECDHE-RSA-AES128-GCM-SHA256

Status
colourGreen
titlesecure

(tick)

(tick)

(tick)

ECDHE-RSA-AES256-GCM-SHA384

Status
colourGreen
titlesecure

(tick)

(tick)

(tick)

ECDHE-RSA-CHACHA20-POLY1305

Status
colourGreen
titlesecure

(tick)

(tick)

(tick)

ECDHE-ECDSA-AES128-SHA256

Status
colourYellow
titleweak

(error)

(error)

(question)

(error)

ECDHE-ECDSA-AES256-SHA384

Status
colourYellow
titleweak

(error)

(error)

(question)

(error)

ECDHE-RSA-AES128-SHA256

Status
colourYellow
titleweak

(error)

(error)

(tick)

ECDHE-RSA-AES256-SHA384

Status
colourYellow
titleweak

(error)

(error)

(question)

(tick)

AES128-SHA256

Status
colourYellow
titleweak

(error)

(error)

(tick)

AES256-SHA256

Status
colourYellow
titleweak

(error)

(error)

(tick)

ECDHE-ECDSA-AES128-SHA

Status
colourYellow
titleweak

(error)

(error)

(question)

(error)

ECDHE-RSA-AES128-SHA

Status
colourYellow
titleweak

(error)

(error)

(question)

(error)

ECDHE-RSA-AES256-SHA

Status
colourYellow
titleweak

(error)

(error)

(question)

(error)

DHE-RSA-AES128-SHA256

Status
colourYellow
titleweak

(error)

(error)

‼️

(error) *

DHE-RSA-AES128-GCM-SHA256

Status
colourYellow
titleweak

(error)

(error)

‼️

(error) *

DES-CBC3-SHA

Status
colourYellow
titleweak

(error)

(error)

(error)

EDH-RSA-DES-CBC3-SHA

Status
colourYellow
titleweak

(error)

(error)

(error)

AES128-SHA

Status
colourYellow
titleweak

(error)

(error)

(error)

DHE-RSA-AES128-SHA

Status
colourYellow
titleweak

(error)

(error)

(error)

AES256-SHA

Status
colourYellow
titleweak

(error)

(error)

(error)

DHE-RSA-AES256-SHA

Status
colourYellow
titleweak

(error)

(error)

(error)

DHE-RSA-AES256-SHA256

Status
colourYellow
titleweak

(error)

(error)

(error)

AES128-GCM-SHA256

Status
colourYellow
titleweak

(error)

(error)

(error)

AES256-GCM-SHA384

Status
colourYellow
titleweak

(error)

(error)

(error)

DHE-RSA-AES256-GCM-SHA384

Status
colourYellow
titleweak

(error)

(error)

(error)

ECDHE-ECDSA-AES256-SHA

Status
colourYellow
titleweak

(error)

(error)

(error)

ECDHE-ECDSA-DES-CBC3-SHA

Status
colourYellow
titleweak

(error)

(error)

(error)

ECDHE-RSA-DES-CBC3-SHA

Status
colourYellow
titleweak

(error)

(error)

(error)