Re: [HAPI-devel] HL7 over HTTP: First draft posted

2012-08-01 Thread James Agnew
Hi Rahul, Thanks for the feedback. My general sense is that having a signature is definitely not going to be required in many cases, which was the main motivation for putting it in an optional profile of its own. As you point out, TLS with Symmetric keys can also do a great job of mutually authen

Re: [HAPI-devel] HL7 over HTTP: First draft posted

2012-07-31 Thread Rahul Somasunderam
James, Thanks for putting this together. I'm looking at the Signature Profile and wondering if it buys us anything that Mutual Authentication (X.509) does not. Can we do away with the HL7-Signature header? R, rahul On Jul 30, 2012, at 7:20 PM, James Agnew wrote: > Hi Everyone, > > The very f

[HAPI-devel] HL7 over HTTP: First draft posted

2012-07-30 Thread James Agnew
Hi Everyone, The very first draft of a proposed specification for HL7 over HTTP has been posted here: http://hl7api.sourceforge.net/hapi-hl7overhttp/specification.html The spec as it stands incorporates most of the feedback I received on Blogspot and on the HAPI mailing list, so it's probably tim