TCP/IP SSL connection between Cloverleaf and Epic

Clovertech Forums Cloverleaf TCP/IP SSL connection between Cloverleaf and Epic

  • Creator
    Topic
  • #121821
    Jorge Medina
    Participant

      Novice SSL user here asking if anyone ever setup SSL connection from Cloverleaf to Epic? Or vice -versa?

      With Cloverleaf as the client:  in Epic I built a TLS1.2 configuration with no client auth, RSA key type and ciphers.  In Cloverleaf using protocol pdl-tcpip, Mode ClientAnon, TLSv1.2 and added all ciphers. Did not work. Changed mode to Client, did not work. Tried a few other configurations, which did not work. Now I realize I don’t know what I’m doing.

      If anyone has done this configuration, if you could provide some knowledge bytes, I would be eternally grateful to you. 🙂

      Thank you in advance.

      Jorge Medina

    Viewing 1 reply thread
    • Author
      Replies
      • #121822
        David Barr
        Participant

          For connections from Cloverleaf to Epic we’re using ClientAuth mode, TLS 1.2.

          This is what the TLS settings look like on the Epic side:

          Server, TLS 1.2 – Client authentication required Key type: RSA Cipher List/Suites: AES/STRONG Cert validity: 2023/10/16-2025/10/15 CN: epicprd.Valleymed.net Issued by: UW-Valley Medical Center Issuing CA2 CA validity: CN: Issued by:

          For Epic to Cloverleaf we’re using Server mode, same version.

        • #121823
          Jorge Medina
          Participant

            Thanks David.

            The configuration was almost the same I had except for ClientAuth. When I switched to ClientAuth it crashed the process. Upping the log configuration I found this error:

            “You do not seem to be licensed to run Add-on Module cl-aom-ssl.”

             

            Sure enuff, we do not have the license:
            [hci@swlxcltst1 ~]$ hcilictest cl-aom-ssl
            cl-aom-ssl: Feature is NOT present in license file
            [hci@swlxcltst1 ~]$

            I am opening a ticket w/support to look into securing the needed license.

        Viewing 1 reply thread
        • You must be logged in to reply to this topic.