Please enable JavaScript to view this site.

CORE HL7 TCP/IP Sender

 

The CORE HL7 TCP/IP Sender Version 3.5

 

You can now configure your CORE HL7 Sender to connect and send HL7 to a HL7 TCP/IP Listener which has implemented a TLS Certificate (formerly called SSL) for identification and encryption of HL7 data as it is being transported over TCP/IP to the Listener. The decision as whether or not to use SSL / TLS connections is one that is ONLY made by the HL7 Listener. The HL7 Sender cannot establish a secure connection to a HL7 Listener which has NOT implemented a SSL / TLS encryption certificate. To understand further it would help to review What Is A TCP/IP Listener below which will show the difference between a TCP/IP Listener, a HL7 Standard TCP/IP Listener, and a Secure Encrypted TCP/IP Listener.

 

 

 

 

To turn your profile into a SSL/TLS secure sender you first have to check The Target HL7 Listener uses a SSL (TLS) Certificate for end-to-end encryption.

 

 

 

SSL / TLS Settings

SSL / TLS Settings

 

 

Who Handles Encryption?

 

In this area you choose whether the SSL connection is one way or bidirectional, select which Encryption level you will use when sending and set the TLS Handshake timeout. First you have 2 choices which will determine whether you will be using 1 way SSL/TLS or bidirectional SSL/TLS. Choices are:

 

1. Only The HL7 Listener - For 1 Way SSL. Only the target HL7 Listener has to have a certificate.

 

 

2. The HL7 Listener Requires My Certificate As Well (Bidirectional SSL). Your profile must also have a SSL/TLS Certificate.

 

Choose the TLS Encryption Level: Here you will have 3 options, TLS 1.2 And TLS 1.3, TLS 1.2 Only, and TLS 1.3 Only. TLS settings control how your HL7 Sender and Listener secure their connection. Choosing TLS 1.2 and TLS 1.3 allows the system to negotiate the best available protocol—typically using TLS 1.3 for better performance and security, but falling back to TLS 1.2 if the other system doesn’t support the newer version. This is the most compatible option and is usually recommended unless you have strict requirements. Selecting TLS 1.2 Only or TLS 1.3 Only restricts communication to a single protocol version. TLS 1.3 is newer, faster, and more secure, but not all systems support it yet. TLS 1.2 is older but still widely used and reliable. If both systems don’t support the same version, the connection will fail, so these options are typically used only when required by the system you are connecting to.

 

Choose the Connection (TLS Handshake) Timeout: Choose the handshake timeout (5 to 10 seconds).

 

 

 

Certificate Trust Settings

 

 

 

 

 

 

 

IF you have NOT checked the Trust Any Listener Certificate Detected box you will have to actually get the certificate information from your HL7 Listener Trading Partner. This is done one of 2 ways:

 

1: Click the Import the HL7 Certificate From A Public Key File button. In order for this to work your HL7 Listener Trading Partner has to provide you with their certificate Public Key in either a .cer or .pem file.

 

2: Click the Connect to the HL7 Listener to Approve Their Certificate button. In order for this to work your HL7 Listener Trading Partner must be listening. Clicking this button will open the Retrieve and Approve window.

 

Connect and Retrieve Listener Certificate

Connect and Retrieve Listener Certificate

 

 

Click the Connect To Listener button on the toolbar.

 

 

Approve Listener Certificate

Approve Listener Certificate

 

If a secure connection is successfully established then you will see a report in the window AND the Accept This Certificate button will appear. Click this button and you will be prompted to give the certificate a name for your local storage. When you return to the Add/Edit Sender Profile window you will see this certificate information report in the Host (Listener) SSL Certificate tab.

 

Approved Listener Certificate

Approved Listener Certificate

 

Now that you have approved the Listener certificate your CORE HL7 Sender profile can ONLY connect to a secure HL7 Listener which has this exact certificate which is identified by the Certificate Thumbprint. If the HL7 Listener changes their certificate without notifying or coordinating with you, your CORE HL7 Sender will fail to connect and send HL7 messages, as it should.

  

Keyboard Navigation

F7 for caret browsing
Hold ALT and press letter

This Info: ALT+q
Nav Header: ALT+n
Page Header: ALT+h
Topic Header: ALT+t
Topic Body: ALT+b
Exit Menu/Up: ESC