Skip to content

DICOM TLS

DICOM TLS encrypts associations, and can make both sides prove who they are with certificates. Configuration › Settings › DICOM TLS.

  • TLS ports (such as 2762) are opened by every node in addition to the plain ports. Sources can match by port, so a source can accept a scanner only over TLS.
  • The node’s certificate: on Windows, from its LocalMachine\My store, by default a valid one issued to its computer name; a thumbprint or subject text can be set centrally, or per node (TlsCertificateThumbprint). On Linux, a file (TlsCertificatePath). Renewed certificates are picked up within the hour.
  • Require client certificates makes senders authenticate with a certificate that is listed: by thumbprint under Trusted certificates (self-signed modality certificates too), or, for certificates from your own authority, trusted by the operating system and with a subject containing one of the Sender certificate subjects (CN=CT01, OU=Radiology Modalities). A certificate is never accepted merely because some authority the operating system trusts issued it.
  • TLS 1.2 and 1.3. Storage commitment results can be sent over TLS too (per source).

On a destination, tick DICOM TLS:

  • The destination’s certificate is checked: its issuer must be trusted, or its thumbprint listed under Trusted certificates. Certificate name sets the name to check, when it is not the host name.
  • The node presents its own certificate, for destinations that require client certificates.
  • Accept any certificate is for testing only: it gives no protection against impersonation.

The HL7 port can use MLLP over TLS with the node certificate (Settings › HL7), and the DICOMweb port is served over HTTPS with it (Settings › DICOMweb). HL7 destinations each choose TLS.

  • HL7 senders’ certificates: with Require HL7 senders to present a certificate, the RIS or interface engine must present one that is listed by thumbprint, or that the operating system trusts and whose subject contains a listed entry (such as CN=RIS01), as for DICOM senders but with lists of their own. Combined with HL7 senders (addresses), a message must come from a listed address and a listed certificate.
  • To HL7 destinations and HL7 status update receivers, nodes present their certificate, and central servers theirs, to receivers that ask for one (mutual TLS).