Connection to Belgium ehealth STS service using PHP -- 2
Budget: $250 – $750 USD
The goal of this project is to create a php script that allows a user to obtain a saml token from the Belgium ehealth STS service using PHP. The authentication must be done using a Holder of Key certificate.
See the attachment for the reference or the following url: https://www.ehealth.fgov.be/ehealthplatform/nl/data/file/view/7cb96c7501dc2eca22c92edfe978c1978019d0ff?name=cookbook_sts_hok_v1.1.pdf
An example of a request and response is also available. Obviously the complexity resides in the calculation of the SOAP Security headers and having a full SOAP request operational.
It is an absolute MUST to have a proven experience with SOAP WS-Security (http://docs.oasis-open.org/wss-m/wss/v1.1.1/wss-SAMLTokenProfile-v1.1.1.html) on which a SAML token is created.
Only knowledge of SOAP is NOT enough. SOAP WS-Security is a complex subject and don't expect it to learn in couple of hours. So, we insist that an experience with SOAP WS-Security is a must, and more specifically with a SAML token based on Holder-of-key certificate.
The code to be delivered doesn't need any UI, we can integrate it later in our application.
Unless you possess a certificate from ehealth in the acceptance environment you won't be able to test directly and thus you will need to validate the principle first on your side. Once stable, I'll then validate it versus the ehealth acceptance environment.
See the attachment for the reference or the following url: https://www.ehealth.fgov.be/ehealthplatform/nl/data/file/view/7cb96c7501dc2eca22c92edfe978c1978019d0ff?name=cookbook_sts_hok_v1.1.pdf
An example of a request and response is also available. Obviously the complexity resides in the calculation of the SOAP Security headers and having a full SOAP request operational.
It is an absolute MUST to have a proven experience with SOAP WS-Security (http://docs.oasis-open.org/wss-m/wss/v1.1.1/wss-SAMLTokenProfile-v1.1.1.html) on which a SAML token is created.
Only knowledge of SOAP is NOT enough. SOAP WS-Security is a complex subject and don't expect it to learn in couple of hours. So, we insist that an experience with SOAP WS-Security is a must, and more specifically with a SAML token based on Holder-of-key certificate.
The code to be delivered doesn't need any UI, we can integrate it later in our application.
Unless you possess a certificate from ehealth in the acceptance environment you won't be able to test directly and thus you will need to validate the principle first on your side. Once stable, I'll then validate it versus the ehealth acceptance environment.