Da Vinci Clinical Data Exchange (CDex)
2.1.0 - STU 2.1 United States of America flag

Da Vinci Clinical Data Exchange (CDex), published by HL7 International / Payer/Provider Information Exchange Work Group. This guide is not an authorized publication; it is the continuous build for version 2.1.0 built by the FHIR (HL7® FHIR® Standard) CI Build. This version is based on the current content of https://github.com/HL7/davinci-ecdx/ and changes regularly. See the Directory of published versions

: CDex Signer Requirements

Page standards status: Trial-use Maturity Level: 2

Raw json | Download

{
  "resourceType" : "Requirements",
  "id" : "cdex-signer",
  "text" : {
    "status" : "generated",
    "div" : "<div xmlns=\"http://www.w3.org/1999/xhtml\"><p class=\"res-header-id\"><b>Generated Narrative: Requirements cdex-signer</b></p><a name=\"cdex-signer\"> </a><a name=\"hccdex-signer\"> </a><table class=\"grid\"><tr><td><b><a name=\"CONF-026\"> </a></b>CONF-026</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>Both <a href=\"StructureDefinition-cdex-task-attachment-request.html\">CDex Task Attachment Request Profile</a> and the <a href=\"http://hl7.org/fhir/us/davinci-dtr/2.2.0/StructureDefinition-dtr-std-questionnaire.html\">DTR Standard Questionnaire</a> profile have the overlapping capability to indicate that a signature is required. Signers <strong>SHALL</strong> meet both the Task <em>and</em> Questionnaire signature expectations.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#cdex-signatures\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-027\"> </a></b>CONF-027</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p><strong>SHALL</strong> use the <a href=\"StructureDefinition-cdex-digital-signature.html\">CDex Digital Signature Profile</a> with the <a href=\"StructureDefinition-cdex-signature-bundle.html\">CDex Signature Bundle Profile</a> for digitally signed Bundles and with the <a href=\"StructureDefinition-cdex-sdc-questionnaireresponse.html\">CDex SDC QuestionnaireResponse Profile</a> for digitally signed QuestionnaireResponse.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-028\"> </a></b>CONF-028</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]: The Signature.data is base64 encoded JWS-Signature [RFC 7515]: JSON Web Signature (JWS)</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-029\"> </a></b>CONF-029</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]: The JWS mime type <code>application/jose</code> <strong>SHALL</strong> be indicated in the <code>Signature.sigFormat</code> element.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-030\"> </a></b>CONF-030</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]:...<strong>SHALL</strong> use the IETF JSON Canonicalization Scheme (JCS) (see <a href=\"https://datatracker.ietf.org/doc/rfc8785\">RFC 8785</a>) to generate the canonical form of the resource.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-031\"> </a></b>CONF-031</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]:... the URI <code>application/fhir+json;canonicalization=http://hl7.org/fhir/canonicalization/json#document</code> ... <strong>SHALL</strong> be indicated in the <code>Signature.targetFormat</code> element.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-034\"> </a></b>CONF-034</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]: <code>Bundle.id</code>, and <code>Bundle.meta</code>  <strong>SHALL</strong> be removed before canonicalization. In other words, everything in a Bundle is signed <em>except</em> for these elements.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-035\"> </a></b>CONF-035</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]: For signatures representing the entire QuestionnaireResponse, <code>QuestionnaireResponse.id</code>, and <code>QuestionnaireResponse.meta</code> elements <strong>SHALL</strong> be removed before canonicalization. In other words, everything in a QuestionnaireResponse is signed <em>except</em> for these elements.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-036\"> </a></b>CONF-036</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]: For signatures representing an item in the QuestionnaireResponse, the <code>QuestionnaireResponse.item.id</code> <strong>SHALL</strong> be removed before canonicalization. In other words, everything in the <code>QuestionnaireResponse.item</code> is signed <em>except</em> for these elements.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-037\"> </a></b>CONF-037</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]: The signature <strong>SHALL</strong> include a <code>&quot;srCms&quot;</code> signer commitments&quot; header element for the Purpose(s) of the Signature (see <a href=\"https://www.etsi.org/deliver/etsi_ts/119100_119199/11918201/01.01.01_60/ts_11918201v010101p.pdf\">JAdES-B-T</a>, page 17). The Purpose can be the action being attested to, or the role associated with the signature. The value shall come from ASTM E1762-95(2013).</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-038\"> </a></b>CONF-038</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]: The <code>&quot;srCms&quot;</code> header <strong>SHALL</strong> contain an <code>&quot;id&quot;: &quot;urn:oid:1.2.840.10065.1.12.1.5&quot;</code> (Verification Signature)</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-039\"> </a></b>CONF-039</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]: The <code>Signature.type.code</code> elements <strong>SHALL</strong> contain the same values as the <code>&quot;srCms&quot;</code> header ids.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-040\"> </a></b>CONF-040</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[The signature header] <strong>SHALL</strong> include an <code>&quot;alg&quot;</code> parameter for the JSON Web Algorithms (JWA) (see <a href=\"https://tools.ietf.org/html/rfc7518\">RFC 7518</a>). <code>&quot;alg&quot;: &quot;RS256&quot;</code> is preferred.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-042\"> </a></b>CONF-042</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[The signature header] <strong>SHALL</strong> have <code>&quot;x5c&quot;</code> (X.509 certificate chain) equal to an array of one or more base64-encoded (not base64url-encoded) DER representations of the public certificate or certificate chain (see <a href=\"https://tools.ietf.org/html/rfc7517\">RFC 7517</a>).</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-043\"> </a></b>CONF-043</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[The signature header] <strong>SHALL</strong> include a <code>&quot;sigT&quot;</code> header parameter with a timestamp of the signature.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-044\"> </a></b>CONF-044</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[The signature header] <strong>SHALL</strong> include a <code>&quot;srCms&quot;</code> signer commitments as defined above.[ commitments header element for the Purpose(s) of the Signature]</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-046\"> </a></b>CONF-046</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[The signature] <strong>SHALL</strong> support JWS compact serialization format for single signatures</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-048\"> </a></b>CONF-048</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>The [signature] certificate <strong>SHALL</strong> include a Subject Alternative Name (SAN)</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-049\"> </a></b>CONF-049</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[The] Subject Alternative Name (SAN) ... <strong>SHALL</strong> match the <code>Signature.who.identifier</code>[element].</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-045\"> </a></b>CONF-045</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHOULD\">SHOULD</a></td><td><div><p>[The signature] <strong>SHOULD</strong> use the hashing algorithm SHA256. The signature validation policy will apply to the signature and determine the acceptability</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-047\"> </a></b>CONF-047</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHOULD\">SHOULD</a></td><td><div><p>[The signature] <strong>SHOULD</strong> support <a href=\"https://datatracker.ietf.org/doc/html/rfc7515#section-3.2\">JWS JSON Serialization</a> format to represent multiple signatures with identical parameter values except <code>&quot;x5c&quot;</code>.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-032\"> </a></b>CONF-032</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-MAY\">MAY</a></td><td><div><p>Implementers that support both XML and JSON wire formats <strong>MAY</strong> support cross format signatures by:</p>\n<ul>\n<li>Validating the JSON Web Signatures in the JSON format.</li>\n<li>Canonicalizing the XHTML<code>text.div</code> narrative element following the <a href=\"https://hl7.org/fhir/6.0.0-ballot3/xml.html#canonical\">FHIR R6 XML Canonicalization rules</a> prior to the JSON canonicalization of the resource.</li>\n<li>identifying this canonicalization method by the URI <code>application/fhir+json;canonicalization=http://hl7.org/fhir/canonicalization/json+xml#document</code> in the <code>Signature.targetFormat</code> element.</li>\n</ul>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-070\"> </a></b>CONF-070</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]: The signature is a [Detached] Signature (where the content that is signed is removed from the JWS)</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-071\"> </a></b>CONF-071</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]: The <code>Bundle.signature</code> or the QuestionnaireResponse [signatureRequired] extension is removed before signing.</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr><tr><td><b><a name=\"CONF-072\"> </a></b>CONF-072</td><td><a href=\"http://hl7.org/fhir/uv/xver-r5.r4/0.1.0/CodeSystem-conformance-expectation.html#conformance-expectation-SHALL\">SHALL</a></td><td><div><p>[Implementers <strong>SHALL</strong> follow the following FHIR R6 <a href=\"https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON\">JSON Signature rules</a>]: When FHIR Resources are signed, the signature is across the <a href=\"https://hl7.org/fhir/6.0.0-ballot3/json.html#canonical\">Canonical JSON</a> form of the resource(s)</p>\n</div><p>Links: </p><ul><li>References: <a href=\"signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse\">signatures.html</a></li></ul></td></tr></table></div>"
  },
  "extension" : [
    {
      "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-wg",
      "valueCode" : "claims"
    },
    {
      "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-fmm",
      "valueInteger" : 2,
      "_valueInteger" : {
        "extension" : [
          {
            "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom",
            "valueCanonical" : "http://hl7.org/fhir/us/davinci-cdex/ImplementationGuide/hl7.fhir.us.davinci-cdex"
          }
        ]
      }
    },
    {
      "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-standards-status",
      "valueCode" : "trial-use",
      "_valueCode" : {
        "extension" : [
          {
            "url" : "http://hl7.org/fhir/StructureDefinition/structuredefinition-conformance-derivedFrom",
            "valueCanonical" : "http://hl7.org/fhir/us/davinci-cdex/ImplementationGuide/hl7.fhir.us.davinci-cdex"
          }
        ]
      }
    }
  ],
  "url" : "http://hl7.org/fhir/us/davinci-cdex/Requirements/cdex-signer",
  "identifier" : [
    {
      "system" : "urn:ietf:rfc:3986",
      "value" : "urn:oid:2.16.840.1.113883.4.642.40.21.36.4"
    }
  ],
  "version" : "2.1.0",
  "name" : "CDexSignerRequirements",
  "title" : "CDex Signer Requirements",
  "status" : "draft",
  "date" : "2026-07-09T22:52:27+00:00",
  "publisher" : "HL7 International / Payer/Provider Information Exchange Work Group",
  "contact" : [
    {
      "name" : "HL7 International / Payer/Provider Information Exchange Work Group",
      "telecom" : [
        {
          "system" : "url",
          "value" : "http://www.hl7.org/Special/committees/claims"
        },
        {
          "system" : "email",
          "value" : "pie@lists.hl7.org"
        }
      ]
    }
  ],
  "description" : "This [Requirements](https://hl7.org/fhir/R5/requirements.html) resource lists all the CDex Signer requirements defined in the narrative sections of this IG.",
  "jurisdiction" : [
    {
      "coding" : [
        {
          "system" : "urn:iso:std:iso:3166",
          "code" : "US"
        }
      ]
    }
  ],
  "copyright" : "Used by permission of HL7 International all rights reserved Creative Commons License",
  "statement" : [
    {
      "key" : "CONF-026",
      "conformance" : [
        "SHALL"
      ],
      "conditionality" : true,
      "requirement" : "Both [CDex Task Attachment Request Profile](StructureDefinition-cdex-task-attachment-request.html) and the [DTR Standard Questionnaire](http://hl7.org/fhir/us/davinci-dtr/2.2.0/StructureDefinition-dtr-std-questionnaire.html) profile have the overlapping capability to indicate that a signature is required. Signers **SHALL** meet both the Task *and* Questionnaire signature expectations. ",
      "reference" : [
        "signatures.html#cdex-signatures"
      ]
    },
    {
      "key" : "CONF-027",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "**SHALL** use the [CDex Digital Signature Profile](StructureDefinition-cdex-digital-signature.html) with the [CDex Signature Bundle Profile](StructureDefinition-cdex-signature-bundle.html) for digitally signed Bundles and with the [CDex SDC QuestionnaireResponse Profile](StructureDefinition-cdex-sdc-questionnaireresponse.html) for digitally signed QuestionnaireResponse.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-028",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]: The Signature.data is base64 encoded JWS-Signature [RFC 7515]: JSON Web Signature (JWS)",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-029",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]: The JWS mime type `application/jose` **SHALL** be indicated in the `Signature.sigFormat` element.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-030",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]:...**SHALL** use the IETF JSON Canonicalization Scheme (JCS) (see [RFC 8785](https://datatracker.ietf.org/doc/rfc8785)) to generate the canonical form of the resource.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-031",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]:... the URI `application/fhir+json;canonicalization=http://hl7.org/fhir/canonicalization/json#document` ... **SHALL** be indicated in the `Signature.targetFormat` element.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-034",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]: `Bundle.id`, and `Bundle.meta`  **SHALL** be removed before canonicalization. In other words, everything in a Bundle is signed *except* for these elements.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-035",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]: For signatures representing the entire QuestionnaireResponse, `QuestionnaireResponse.id`, and `QuestionnaireResponse.meta` elements **SHALL** be removed before canonicalization. In other words, everything in a QuestionnaireResponse is signed *except* for these elements.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-036",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]: For signatures representing an item in the QuestionnaireResponse, the `QuestionnaireResponse.item.id` **SHALL** be removed before canonicalization. In other words, everything in the `QuestionnaireResponse.item` is signed *except* for these elements.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-037",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]: The signature **SHALL** include a `\"srCms\"` signer commitments\" header element for the Purpose(s) of the Signature (see [JAdES-B-T](https://www.etsi.org/deliver/etsi_ts/119100_119199/11918201/01.01.01_60/ts_11918201v010101p.pdf), page 17). The Purpose can be the action being attested to, or the role associated with the signature. The value shall come from ASTM E1762-95(2013).",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-038",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]: The `\"srCms\"` header **SHALL** contain an `\"id\": \"urn:oid:1.2.840.10065.1.12.1.5\"` (Verification Signature)",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-039",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]: The `Signature.type.code` elements **SHALL** contain the same values as the `\"srCms\"` header ids.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-040",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[The signature header] **SHALL** include an `\"alg\"` parameter for the JSON Web Algorithms (JWA) (see [RFC 7518](https://tools.ietf.org/html/rfc7518)). `\"alg\": \"RS256\"` is preferred.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-042",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[The signature header] **SHALL** have `\"x5c\"` (X.509 certificate chain) equal to an array of one or more base64-encoded (not base64url-encoded) DER representations of the public certificate or certificate chain (see [RFC 7517](https://tools.ietf.org/html/rfc7517)).",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-043",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[The signature header] **SHALL** include a `\"sigT\"` header parameter with a timestamp of the signature.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-044",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[The signature header] **SHALL** include a `\"srCms\"` signer commitments as defined above.[ commitments header element for the Purpose(s) of the Signature]",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-046",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[The signature] **SHALL** support JWS compact serialization format for single signatures",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-048",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "The [signature] certificate **SHALL** include a Subject Alternative Name (SAN)",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-049",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[The] Subject Alternative Name (SAN) ... **SHALL** match the `Signature.who.identifier`[element].",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-045",
      "conformance" : [
        "SHOULD"
      ],
      "requirement" : "[The signature] **SHOULD** use the hashing algorithm SHA256. The signature validation policy will apply to the signature and determine the acceptability",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-047",
      "conformance" : [
        "SHOULD"
      ],
      "requirement" : "[The signature] **SHOULD** support [JWS JSON Serialization](https://datatracker.ietf.org/doc/html/rfc7515#section-3.2) format to represent multiple signatures with identical parameter values except `\"x5c\"`.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-032",
      "conformance" : [
        "MAY"
      ],
      "requirement" : "Implementers that support both XML and JSON wire formats **MAY** support cross format signatures by:\n- Validating the JSON Web Signatures in the JSON format.\n- Canonicalizing the XHTML`text.div` narrative element following the [FHIR R6 XML Canonicalization rules](https://hl7.org/fhir/6.0.0-ballot3/xml.html#canonical) prior to the JSON canonicalization of the resource.\n- identifying this canonicalization method by the URI `application/fhir+json;canonicalization=http://hl7.org/fhir/canonicalization/json+xml#document` in the `Signature.targetFormat` element.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-070",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]: The signature is a [Detached] Signature (where the content that is signed is removed from the JWS)",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-071",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]: The `Bundle.signature` or the QuestionnaireResponse [signatureRequired] extension is removed before signing.",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    },
    {
      "key" : "CONF-072",
      "conformance" : [
        "SHALL"
      ],
      "requirement" : "[Implementers **SHALL** follow the following FHIR R6 [JSON Signature rules](https://hl7.org/fhir/6.0.0-ballot3/datatypes.html#JSON)]: When FHIR Resources are signed, the signature is across the [Canonical JSON](https://hl7.org/fhir/6.0.0-ballot3/json.html#canonical) form of the resource(s)",
      "reference" : [
        "signatures.html#digital-signature-rules-and-guidance-for-cdex-bundle-and-questionnaireresponse"
      ]
    }
  ]
}