Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

December 15th - December 29th

...

Support for NwHIN eHealth Exchange Certification Review/Remaining Issues

–Set
– Set the "mustUnderstand" attribute on the WS-Addressing Action element in the SOAP response  (CONN-1506 & CONN-1428)
•Added
    • Added supporting tests to regression suite for future compliance
–The
– The first resolution to address the Semantic Text removal was only applied to the parameter list in QueryByParameter, still required to be applied for the MatchCriterionList elements in the PD request schema
•Parameters
    • Parameters MatchAlgorithm & MinimumDegreeMatch
–Researched
– Researched and addressed the PurposeOfUse and Role scoping issue discovered as part of NIST DS testing
•Due
    • Due to the delay in receiving official guidance from Spec factory, set the prefix to be configurable with the default that it is turned off

System Administration Module or Admin GUI (Feature complete)

System Administration Module or Admin GUI documentation

Direct enhancements (Feature complete)

Direct documentation

 

Other tasks post release

...

– Reviewed CONNECT generated PD request and response against all pertinent manual EHEX certification checklists
    • Split the review by service type and consolidated the manual checklists/spreadsheets accordingly
    • Several spreadsheets were associated with PD
    • No additional findings were found

Validation of Auditing Design against EHEX Checklist

– Auditing isn’t currently a part of EHEX Certification testing manual checklist are published
– The expectation is this will soon be part future requirements
– Took currently Auditing messages and design for Audit improvements and reviewed against EHEX checklists
    • Though Audit design addresses all services supported by CONNECT, the review only focused on EHEX supported services
    • Review CONNECT generated audit messages against PD initiator and responder manual checklists from Healtheway
    • Review CONNECT generated audit messages against QD initiator and responder manual checklists from Healtheway
    • On Review CONNECT generated audit messages against RD initiator and responder manual checklists from Healtheway

Functional and Security Testing Improvements

– Followed-up with DoD SCQC team on Fortify next steps and final reviews of Release 4.4 (Updated rule engine)
– Added OWASP Dependency Checks to nightly continuous integration process for jenkins build
– Resolved CONNECT Nightly build  issue -- Bimodal Regression test ValidateSAMLResourceURIAttributeTest
– Update regression suite tests to check if all the service responses have the mustUnderstand attribute set in action header element
– Addressed post 4.4 Fortify findings
    • Mitigated "Setting Manipulation" finding eliminating ability for an attacker to control values that govern system behavior
    • Mitigated "System Information Leak: Internal“ occurring during debugging

Other tasks post release

  • Continuing to work on the team generated Technical Stories
  • Continued backlog grooming and prioritization 
  • Beginning preparation for the Change Control Board

JIRA Planning Board of Committed User Stories for Sprint 147:

...

KeySummaryIssue TypePriorityStatusStory Points (28)
FHAC-3Review CONNECT generated PD request and response against the manual eHex Participant testing checklistsTaskMajorCLOSED5
FHAC-7 *Research and follow-up on the PurposeOfUse and Role scoping issue discovered as part of NIST DS testingTaskMajorCLOSED1
FHAC-8 *Set "mustUnderstand" attribute on the WS-Addressing Action element in the SOAP response messageStoryMajorCLOSED0
FHAC-9 *CONNECT is removing SemanticsText value for MatchCriterionList elements - MatchAlgorithm and MinimumDegreeMatchStoryMajorCLOSED2
FHAC-11Review CONNECT generated audit messages against PD initiator and responder manual checklists from HealtheWayTaskMajorCLOSED3
FHAC-12 *Review CONNECT generated audit messages against QD initiator and responder manual checklists from HealtheWayTaskMajorCLOSED2
FHAC-13 *Review CONNECT generated audit messages against RD initiator and responder manual checklists from HealtheWayTaskMajorCLOSED2
FHAC-15Research Set "mustUnderstand" attribute on the WS-Addressing Action element in the SOAP response messageTaskMinorCLOSED2
FHAC-16 *As a CONNECT developer, I would like the CONNECT internal dependencies (WebServices and CommonTypes) to have snapshot releasesTechnical StoryMajorCLOSED0
FHAC-17Research Snapshot creation and how it would apply to Common Types and WebServicesTaskMajorCLOSED2
FHAC-18Apply Snapshot plan to Connect Webservices and CommonTypesTaskMajorCLOSED2
FHAC-19Follow-up with SCQC on Fortify next stepsTaskMajorCLOSED1
FHAC-20 *CI - Add OWASP Dependency Check to nightly jenkins buildTaskMajorCLOSED2
FHAC-23 *Follow-up on timestamp expiration issue reported by CMS/OFM (CONN-1580)TaskMajorCLOSED0
FHAC-24 *CONNECT Nightly build -- Bimodal Regression test ValidateSAMLResourceURIAttributeTest failingTaskMinorCLOSED1
FHAC-28 *Mitigate "Setting Manipulation" Fortify FindingTaskMajorCLOSED1
FHAC-29 *Update ValidateWSA-ActionSoapMustUnderstandTest regression suite testTaskMinorCLOSED1
FHAC-34 *Mitigate "System Information Leak: Internal" Fortify FindingsTaskMinorCLOSED1

 

Issues Not Completed

KeySummaryIssue TypePriorityStatusStory Points (2)
FHAC-14Determine whether EHEX Cert contributions are needed in the main Gateway codeTaskMajorIN PROGRESS1
FHAC-33 *Document CONNECT Development Process in WikiTaskMinorIN PROGRESS1