============================================================================= Run Date: JAN 17, 2024 Designation: EDP*2*28 Package : EDP - EMERGENCY DEPARTMENT Priority: Mandatory Version : 2 SEQ #18 Status: Released Compliance Date: FEB 17, 2024 ============================================================================= Associated patches: (v)EDP*2*29 <<= must be installed BEFORE `EDP*2*28' Subject: SSOI COMPLIANCE AND APPLICATION SECURITY UPDATES Category: - PATCH FOR A PATCH - Informational Description: ============ EDP*2.0*28 is for the Emergency Department Integration Software (EDIS) Java graphic user interface (GUI). EDP*2.0*28 is replacing EDP*2.0*18 and will enable Single Sign On Internal (SSOi) for EDIS. After release, the EDIS GUI/Web Server version will be 2.2.47. Patch EDP*2.0*28 addresses the following defects: 1. HDSO-5400- Update log4j in EDIS application 2. HDSO-5399 - EDIS SSOi Fix for Integrated Sites 3. HDSO-5405/INC19053509 - EDIS Test version is not working dup EDIS-547/INC21575624 4. HDSO-5401/HDSO-5397- SSO Fallout Error handling 5. HDSO-5402 - Convert the current VIA webservice to an RPC call for the logon process 6. HDSO-5398 - Patch 18 production deployment issue. Patch Components: ----------------- Files & Fields Associated: File Name (Number) Field Name (Number) New/Modified/Deleted ------------------ ------------------- -------------------- N/A Forms Associated: Form Name File Number New/Modified/Deleted --------- ----------- -------------------- N/A Mail Groups Associated: Mail Group Name New/Modified/Deleted --------------- -------------------- N/A Options Associated: Option Name Type New/Modified/Deleted ----------- ---- -------------------- Protocols Associated: Protocol Name New/Modified/Deleted ------------- -------------------- N/A Security Keys Associated: Security Key Name ----------------- N/A Templates Associated: Template Name Type File Name (Number) New/Modified/Deleted ------------- ---- ------------------ -------------------- N/A Remote Procedures Associated: Remote Procedure Name New/Modified/Deleted --------------------- -------------------- N/A Parameter Definitions Associated: Parameter Name New/Modified/Deleted -------------- -------------------- N/A Additional Information: ----------------------- N/A New Service Requests (NSRs): N/A Patient Safety Issues (PSIs): N/A Defect Tracking System Tickets(s) & Overview: 1. HDSO-5400- Update log4j in EDIS application Problem: -------- The logging library used by the EDIS application is out of compliance and needs to be updated. Technical Problem: ------------------ The Log4j jars need to be upgraded to the latest version allowed per the Technical Reference Model (TRM). Resolution: ----------- The build has been updated to exclude Log4j jars from the application. Instead, the jars will reside in the WebLogic server library. This will allow them to be upgraded in the future without having to push a new version of the application. 2. HDSO-5399 - EDIS SSOi Fix for Integrated Sites Problem: -------- Single Sign On Internal (SSOi) integration is not working for integrated sites that use a single VistA instance. Users are currently unable to log into EDIS if they belong to an integrated site. Technical Problem: ------------------ When the EDIS application is put into SSOi mode the site selection page does not properly account for the divisions when generating the list of available sites. Resolution: ----------- The code has been updated to take the divisions into account when generating the site list for SSOi. 3. HDSO-5405/INC19053509 - EDIS Test version is not working dup EDIS-547/INC21575624 Problem: -------- The Test version of EDIS in the Test Shortcuts folder is not operational. Site Test VistA instances are not connected to EDIS Pre-Production. Technical Problem: ------------------ Due to a limitation on the SiteIDs that can be connected to the VistA Integration Adapter (VIA) in the pre-production environment, not all sites can be connected to VIA in the pre-production environment. Resolution: ----------- VIA has been removed as a dependency from the EDIS application. Instead, the application will handle its own login functionality. This removes the requirement that a Test VistA instance needs to be connected to VIA. 4. HDSO-5401/HDSO-5397- SSO Fallout Error handling Problem: -------- The error handling for issues that can arise from the use of the PIV card when attempting to log into the EDIS application is insufficient. Technical Problem: ------------------ Users are not presented with robust messages when they are unable to log into EDIS. Resolution: ----------- More robust error handling has been added to the EDIS application so that users are informed about the cause of their inability to login. 5. HDSO-5402 - Convert the current VIA webservice to a Remote Procedure Call (RPC) for the logon process Problem: -------- The EDIS application is dependent on the VIA web services for login but the VIA web services are being decommissioned. Technical Problem: ------------------ N/A Resolution: ----------- VIA dependency has been removed from the EDIS application. Going forward, the application will handle its own login functionality. EDIS will be utilizing VistA link RPC calls in order to process Access/Verify (A/V) codes or Security Assertion Markup Language (SAML) tokens. 6. HDSO-5398 - Patch 18 production deployment issue. Problem: -------- Post deployment user could not login successfully or user could not do any activities after logging in. Technical Problem: ------------------ N/A Resolution: ----------- Issue numbers HDSO-5400, HDSO-5399, HDSO-5405/INC19053509,HDSO-5401/HDSO-5397, HDSO-5402 resolve HDSO-5398. Test Sites: ----------- VA GREATER LOS ANGELES HEALTHCARE SYSTEM - WEST LOS ANGELES FARGO VA HCS SNOW Change Order #: ------------------- CHG0443354 Software and Documentation Retrieval Instructions: -------------------------------------------------- The software for this patch is being deployed by the IO Enterprise Server Support Team. Documentation describing the new functionality is included in this Release. Documentation can be found on the VA Software Documentation Library at: https://www.domain.ext/vdl/. Documentation can also be obtained at https://download.vista.domain.ext/index.html/SOFTWARE. Documentation Title File Name ---------------------------------------------------------------- EDIS User Guide EDIS_2_2_UG.pdf EDIS Technical Manual EDIS_2_2_TM.pdf Installation Instructions: -------------------------- This is a web application Java Build. This is a centralized server promotion. No installation is required at local sites. Back-Out/Roll Back Plan: ------------------------ Any back-out/roll back will be handled by the central server deployment team. No actions are required of local sites in the event of back-out/roll back. Routine Information: ==================== No routines included. ============================================================================= User Information: Entered By : Date Entered : APR 19, 2023 Completed By: Date Completed: JAN 17, 2024 Released By : Date Released : JAN 17, 2024 ============================================================================= Packman Mail Message: ===================== No routines included