-
Type:
Change Request
-
Resolution: Persuasive
-
Priority:
Medium
-
US Core (FHIR)
-
DSTU2
-
US Realm Task Force
-
Home
-
D.24 General Securit
-
-
Hans Buitendijk/Danielle Friend: 8-0-1
-
Enhancement
-
Non-substantive
-
Yes
-
DSTU2
Existing Wording: Systems SHALL use TLS version 1.0 or higher for all transmissions not taking place over a secure network connection.
(Using TLS even within a secured network environment is still encouraged to provide defense in depth.) US Federal systems SHOULD conform with FIPS PUB 140-2.
Proposed Wording: Systems SHALL use TLS version 1.2 or higher for all transmissions not taking place over a secure network connection.
(Using TLS even within a secured network environment is still encouraged to provide defense in depth.) US Federal systems SHOULD conform with FIPS PUB 140-2.
Comment:
US Government is required to use TLS version 1.2.
Summary:
US Government is required to use TLS version 1.2.
- is duplicated by
-
FHIR-11112 US Govn't requires TLS 1.2, not 1.0 - 2016-09 core #266
-
- Duplicate
-
- is voted on by
-
BALLOT-3504 Negative - Russell Davis : 2018-Sep-FHIR QUALITY R1
- Balloted