Stream: Security and Privacy
Topic: TLS 1.2 or higher
John Moehrke (Jun 26 2018 at 19:10):
The Security WG is considering setting a minimum requirement of TLS 1.2 or higher. We understand that there might be legacy systems that do not yet support TLS 1.2, but need to understand how large the impact would be. Please let me know if you have systems that would not be able to support TLS 1.2 or higher?
Note that IETF Best Current Practice allows TLS 1.1 only where the two systems do not support TLS 1.2, and only allows TLS 1.0 when the two systems do not support TLS 1.1 or TLS 1.2. https://tools.ietf.org/html/bcp195
Note that PCI recommendations specify TLS 1.1 or higher, with a recommendation to use TLS 1.2 https://blog.pcisecuritystandards.org/migrating-from-ssl-and-early-tls
Grahame Grieve (Jun 27 2018 at 04:04):
why would we make this a requirement?
Lloyd McKenzie (Jun 27 2018 at 05:30):
I'm assuming this would only apply to systems that support TLS at all...
John Moehrke (Jun 27 2018 at 12:59):
a CP has been entered by representatives of ONC ... Yes, it would be more of a forbidance against TLS less than 1.2.... so if you are not using TLS, you are not affected
Kevin Shekleton (Jun 27 2018 at 19:22):
What is a "CP"?
I think it is odd FHIR would have a requirement like this around a specific TLS version. If we're going to require a minimum TLS version, should we also start defining a whitelist or blacklist of cipher suites over these TLS connections? I ask this to try and find where the line is as to what FHIR prescribes from a security perspective given its current state today of being largely agnostic to all of this.
Grahame Grieve (Jun 27 2018 at 19:49):
ONC can make this rule for their own jurisdiction, but FHIR is for everyone. I'm not at all clear about why HL7 should make a ruling on this.
Grahame Grieve (Jun 27 2018 at 19:49):
CP = John's name for a gForge task ("change proposal")
John Moehrke (Jun 27 2018 at 20:39):
sorry... IHE uses CP... FHIR uses CR... sometimes I have the wrong hat on.
John Moehrke (Jun 27 2018 at 20:39):
I am happy saying that these normative requirements belong in IG, not in core spec...
John Moehrke (Jun 27 2018 at 20:39):
but need community support one way or the other.
John Moehrke (Jun 27 2018 at 20:44):
GF#17422: Mandatory floor of TLS 1.2 ---- Please provide followup if you want to
John Moehrke (Jul 10 2018 at 16:12):
Any other input on this proposal?
Last updated: Apr 12 2022 at 19:14 UTC