Andrew N. Shrosbree wrote:
Stephen,

Argus 4.1 (in testing right now) automatically signs all messages with the sending site's location certificate. The receivers of such signed messages have the option to configure Argus to reject an incoming message unless it has been digitally signed. Verification is done by going straight to HeSA in real time when a message is downloaded by the receiving site. Argus also checks HeSA's Certificate Revocation Lists to confirm that the signing certificate has not been revoked.

Andrew, I remember you telling us once that the HIC had requested that you investigate signing with the location key, which you felt was inappropriate at the time. What do you see the benefits as being? Mainly extra security?

You are correct: for HIC purposes, personal certs (smart card) must be used. My team is about to re-integrate into Argus the ability to perform personal signing. We left these modules dormant since 2003 because of a lack of clarity regarding how personal signing was going to be implemented in practical terms. The theory was great until cold, hard practical reality hit us all.

Many great human endeavours have taken some time to come to fruition. Climbing Mt Everest, building the Sydney Harbour Bridge, HealthConnect... Oops, I forgot, that one's been scrapped!

Greg

--
Greg Twyford
Information Management & Technology Program Officer
Canterbury Division of General Practice
E-mail: [EMAIL PROTECTED]
Ph.: 02 9787 9033
Fax: 02 9787 9200

PRIVATE & CONFIDENTIAL
***********************************************************************
The information contained in this e-mail and their attached files,
including replies and forwarded copies, are confidential and intended
solely for the addressee(s) and may be legally privileged or prohibited
from disclosure and unauthorised use. If you are not the intended
recipient, any form of reproduction, dissemination, copying, disclosure,
modification, distribution and/or publication or any action taken or
omitted to be taken in reliance upon this message or its attachments is
prohibited.

All liability for viruses is excluded to the fullest extent permitted by
law.
***********************************************************************

_______________________________________________
Gpcg_talk mailing list
[email protected]
http://ozdocit.org/cgi-bin/mailman/listinfo/gpcg_talk

Reply via email to