Udap.Client
0.4.4
dotnet add package Udap.Client --version 0.4.4
NuGet\Install-Package Udap.Client -Version 0.4.4
<PackageReference Include="Udap.Client" Version="0.4.4" />
paket add Udap.Client --version 0.4.4
#r "nuget: Udap.Client, 0.4.4"
// Install Udap.Client as a Cake Addin #addin nuget:?package=Udap.Client&version=0.4.4 // Install Udap.Client as a Cake Tool #tool nuget:?package=Udap.Client&version=0.4.4
Udap.Client
📦 Nuget Package: Udap.Client
Udap.Config simple dependency injection example configuration
If you chose to load a trust anchor yourself or non at all then registration can be a simple as the following.
builder.Services.AddScoped<TrustChainValidator>();
builder.Services.AddHttpClient<IUdapClient, UdapClient>();
The Udap.Client returns a UdapDiscoveryDocumentResponse
. For convenience it contains a IsError property. If you need to understand why there is an error then you can investigate the Error
, Exception
, ErrorType
, and HttpErrorReason
depending on the reason for the error. There are also events you can subscribe to to get details about JWT and Certificate chaining errors. The Problem events come from the TrustChainValidator
and are very useful. See example below.
var udapClient = serviceProvider.GetRequiredService<IUdapClient>();
var loggerFactory = serviceProvider.GetRequiredService<ILoggerFactory>();
var logger = loggerFactory.CreateLogger(typeof(Program));
udapClient.Problem += element => logger.LogWarning(element.ChainElementStatus
.Summarize(TrustChainValidator.DefaultProblemFlags));
udapClient.Untrusted += certificate2 => logger.LogWarning("Untrusted: " + certificate2.Subject);
udapClient.TokenError += message => logger.LogWarning("TokenError: " + message);
var response = await udapClient.ValidateResource(options.BaseUrl, trustAnchorStore, community);
if (response.IsError)
{
logger.LogError(response.HttpErrorReason);
}
else
{
logger.LogInformation(JsonSerializer.Serialize(
response,
new JsonSerializerOptions{WriteIndented = true}));
}
Experiment with this example code in the 1_UdapClientMetadata CLI Project
Example command line run: dotnet run --baseUrl https://fhirlabs.net/fhir/r4 --trustAnchor "C:\SureFhirLabs_CA.cer" --community udap://ECDSA/
NOTE The above example trust anchor (download) is used by most communities in the https://fhirlabs.net/fhir/r4 test server.
Udap.Client configuration with a ITrustAnchorStore implementation
Implement the ITrustAnchorStore to load trust anchors from a store. Below is dependency injection example of a file system store implementation. Note the CertStore folder in this project with anchors and intermediates folders. Also take note of the appsettings.json
configuration. Notice each community has an Anchors and Intermediates collection of file references. In accompanying example project all communities issue certificates through a sub-certificate authority, yet the configuration only configured one Intermediate. Why is this? If the published certificate at the resource ./well-known/udap
endpoint contains a AIA extension then the .NET X509Chain.Build
method will follow the URL in the extension. This is true on Windows and Linux. Some Certificate Authorities may not follow this practice and you will have to configure for the intermediate certificate.
Note: An anchor must be chosen for each community. When you receive signed metadata the client will proceed to build a certificate chain from the first x5c header certificate and the anchor as the root certificate.
There is another way for intermediate certificates to be discovered. That is within the x5c header of the signed metadata. While the first certificate in the x5c header must be the signing certificate, the rest of the certificates may be the rest of the chain. But again you must have an anchor deliberately chosen and loaded into the client. The client will no load and trust an anchor from the x5c header.
<details><summary><a>View Metadata</></summary>
"UdapFileCertStoreManifest": {
"Communities": [
{
"Name": "udap://stage.healthtogo.me/",
"Anchors": [
{
"FilePath": "CertStore/anchors/EMRDirectTestCA.crt"
}
]
},
{
"Name": "udap://fhirlabs.net/",
"Intermediates": [
"CertStore/intermediates/SureFhirLabs_Intermediate.cer"
],
"Anchors": [
{
"FilePath": "CertStore/anchors/SureFhirLabs_CA.cer"
}
]
},
{
"Name": "udap://expired.fhirlabs.net/",
"Anchors": [
{
"FilePath": "CertStore/anchors/SureFhirLabs_CA.cer"
}
]
},
{
"Name": "udap://revoked.fhirlabs.net/",
"Anchors": [
{
"FilePath": "CertStore/anchors/SureFhirLabs_CA.cer"
}
]
},
{
"Name": "udap://untrusted.fhirlabs.net/",
"Anchors": [
{
"FilePath": "CertStore/anchors/SureFhirLabs_CA.cer"
}
]
},
{
"Name": "udap://Iss.Miss.Match.To.SubjAltName/",
"Anchors": [
{
"FilePath": "CertStore/anchors/SureFhirLabs_CA.cer"
}
]
},
{
"Name": "udap://Iss.Miss.Match.To.BaseUrl//",
"Anchors": [
{
"FilePath": "CertStore/anchors/SureFhirLabs_CA.cer"
}
]
},
{
"Name": "udap://ECDSA/",
"Anchors": [
{
"FilePath": "CertStore/anchors/SureFhirLabs_CA.cer"
}
]
}
]
}
</details> <br/>
services.Configure<UdapFileCertStoreManifest>(context.Configuration.GetSection("UdapFileCertStoreManifest"));
services.AddSingleton<ITrustAnchorStore, TrustAnchorFileStore>();
services.AddScoped<TrustChainValidator>();
services.AddHttpClient<IUdapClient, UdapClient>();
Experiment with this example code in the 1_UdapClientMetadata CLI Project
Udap.Client advanced configuration
The TrustChainValidator a couple ways to control it's behavior when validating a chain. One is the control the Problem Flags
identified in the .NET X509ChainStatusFlags
settings. The defaults are recommended. Perhaps you are running some unit tests that do not publish a certificate revocation list. Then your code might look something like the following where we mask out OfflineRevocation
and RevocationStatusUnknown
flags.
services.Configure<UdapFileCertStoreManifest>(context.Configuration.GetSection("UdapFileCertStoreManifest"));
var problemFlags = X509ChainStatusFlags.NotTimeValid |
X509ChainStatusFlags.Revoked |
X509ChainStatusFlags.NotSignatureValid |
X509ChainStatusFlags.InvalidBasicConstraints |
X509ChainStatusFlags.CtlNotTimeValid |
X509ChainStatusFlags.UntrustedRoot |
// X509ChainStatusFlags.OfflineRevocation |
X509ChainStatusFlags.CtlNotSignatureValid;
// X509ChainStatusFlags.RevocationStatusUnknown;
services.AddSingleton<ITrustAnchorStore, TrustAnchorFileStore>();
services.AddScoped<TrustChainValidator>(sp => new TrustChainValidator(new X509ChainPolicy(), problemFlags, sp.GetService<ILogger<TrustChainValidator>>()));
services.AddHttpClient<IUdapClient, UdapClient>();
TODO: Cover X509ChainPolicy
Udap.Client Dynamic Client Registration with a ICertificateStore implementation
Example projects
Product | Versions Compatible and additional computed target framework versions. |
---|---|
.NET | net8.0 is compatible. net8.0-android was computed. net8.0-browser was computed. net8.0-ios was computed. net8.0-maccatalyst was computed. net8.0-macos was computed. net8.0-tvos was computed. net8.0-windows was computed. net9.0 is compatible. net9.0-android was computed. net9.0-browser was computed. net9.0-ios was computed. net9.0-maccatalyst was computed. net9.0-macos was computed. net9.0-tvos was computed. net9.0-windows was computed. |
-
net8.0
- Duende.IdentityModel (>= 7.0.0)
- Udap.Common (>= 0.4.4)
- Udap.Model (>= 0.4.4)
-
net9.0
- Duende.IdentityModel (>= 7.0.0)
- Udap.Common (>= 0.4.4)
- Udap.Model (>= 0.4.4)
NuGet packages (1)
Showing the top 1 NuGet packages that depend on Udap.Client:
Package | Downloads |
---|---|
Udap.Server
Package is a part of the UDAP reference implementation for .NET. |
GitHub repositories
This package is not used by any popular GitHub repositories.
Version | Downloads | Last updated |
---|---|---|
0.4.4 | 82 | 1/15/2025 |
0.4.3 | 27 | 1/14/2025 |
0.4.2 | 26 | 1/14/2025 |
0.4.1 | 71 | 1/13/2025 |
0.4.0 | 233 | 12/14/2024 |
0.3.96 | 297 | 11/6/2024 |
0.3.95 | 224 | 11/2/2024 |
0.3.94 | 134 | 10/31/2024 |
0.3.93 | 319 | 10/13/2024 |
0.3.92 | 115 | 10/13/2024 |
0.3.91 | 109 | 10/10/2024 |
0.3.89 | 142 | 10/10/2024 |
0.3.87 | 146 | 10/5/2024 |
0.3.86 | 162 | 10/5/2024 |
0.3.85 | 126 | 10/4/2024 |
0.3.84 | 118 | 10/3/2024 |
0.3.83 | 111 | 10/3/2024 |
0.3.82 | 173 | 9/20/2024 |
0.3.81 | 216 | 9/19/2024 |
0.3.80 | 164 | 9/19/2024 |
0.3.79 | 155 | 9/19/2024 |
0.3.78 | 150 | 9/19/2024 |
0.3.77 | 190 | 9/17/2024 |
0.3.76 | 120 | 9/17/2024 |
0.3.75 | 129 | 9/12/2024 |
0.3.74 | 123 | 9/12/2024 |
0.3.73 | 143 | 9/10/2024 |
0.3.72 | 294 | 9/7/2024 |
0.3.71 | 133 | 9/5/2024 |
0.3.70 | 127 | 9/5/2024 |
0.3.69 | 133 | 9/5/2024 |
0.3.68 | 151 | 9/4/2024 |
0.3.67 | 120 | 9/4/2024 |
0.3.66 | 113 | 9/4/2024 |
0.3.65 | 117 | 9/4/2024 |
0.3.64 | 119 | 9/2/2024 |
0.3.63 | 126 | 8/31/2024 |
0.3.62 | 144 | 8/29/2024 |
0.3.61 | 139 | 8/28/2024 |
0.3.60 | 199 | 8/2/2024 |
0.3.59 | 149 | 8/1/2024 |
0.3.58 | 111 | 8/1/2024 |
0.3.57 | 241 | 7/19/2024 |
0.3.56 | 126 | 7/19/2024 |
0.3.54 | 133 | 7/18/2024 |
0.3.53 | 142 | 7/15/2024 |
0.3.52 | 133 | 7/15/2024 |
0.3.51 | 132 | 7/12/2024 |
0.3.50 | 208 | 7/1/2024 |
0.3.49 | 144 | 7/1/2024 |
0.3.48 | 350 | 5/22/2024 |
0.3.47 | 243 | 5/15/2024 |
0.3.46 | 117 | 5/14/2024 |
0.3.45 | 180 | 5/12/2024 |
0.3.44 | 123 | 5/12/2024 |
0.3.43 | 106 | 5/12/2024 |
0.3.42 | 118 | 5/12/2024 |
0.3.41 | 193 | 5/6/2024 |
0.3.40 | 175 | 5/4/2024 |
0.3.39 | 137 | 5/1/2024 |
0.3.38 | 146 | 4/30/2024 |
0.3.37 | 218 | 4/11/2024 |
0.3.36 | 136 | 4/10/2024 |
0.3.35 | 261 | 4/9/2024 |
0.3.34 | 162 | 4/8/2024 |
0.3.33 | 160 | 4/7/2024 |
0.3.32 | 154 | 4/5/2024 |
0.3.31 | 151 | 4/4/2024 |
0.3.30 | 127 | 4/4/2024 |
0.3.29 | 185 | 4/3/2024 |
0.3.28 | 120 | 4/3/2024 |
0.3.27 | 135 | 4/2/2024 |
0.3.26 | 111 | 4/2/2024 |
0.3.25 | 164 | 4/2/2024 |
0.3.24 | 197 | 3/24/2024 |
0.3.22 | 246 | 3/6/2024 |
0.3.21 | 141 | 3/6/2024 |
0.3.20 | 145 | 3/5/2024 |
0.3.19 | 163 | 3/2/2024 |
0.3.18 | 152 | 3/2/2024 |
0.3.13 | 166 | 3/1/2024 |
0.3.12 | 135 | 2/24/2024 |
0.3.10 | 142 | 2/14/2024 |
0.3.8 | 218 | 2/11/2024 |
0.3.7 | 145 | 2/11/2024 |
0.3.6 | 143 | 2/10/2024 |
0.3.5 | 127 | 2/10/2024 |
0.3.4 | 134 | 2/10/2024 |
0.3.2 | 143 | 2/10/2024 |
0.3.0 | 293 | 1/31/2024 |
0.2.21 | 555 | 10/24/2023 |
0.2.20 | 151 | 10/23/2023 |
0.2.19 | 192 | 10/20/2023 |
0.2.18 | 202 | 10/11/2023 |
0.2.17 | 199 | 10/5/2023 |
0.2.16 | 268 | 9/21/2023 |
0.2.15 | 154 | 9/21/2023 |
0.2.14 | 215 | 9/20/2023 |
0.2.13 | 145 | 9/20/2023 |
0.2.12 | 166 | 9/20/2023 |
0.2.11 | 162 | 9/19/2023 |
0.2.10 | 233 | 9/13/2023 |
0.2.9 | 316 | 8/26/2023 |
0.2.8 | 189 | 8/18/2023 |
0.2.7 | 188 | 8/15/2023 |
0.2.6 | 177 | 8/12/2023 |
0.2.5 | 216 | 8/11/2023 |
0.2.4 | 194 | 8/10/2023 |
0.2.3 | 228 | 8/2/2023 |
0.2.2 | 195 | 8/1/2023 |
0.2.1 | 205 | 7/25/2023 |
0.2.0 | 252 | 7/16/2023 |
0.1.24 | 350 | 5/26/2023 |
0.1.23 | 171 | 5/22/2023 |
0.1.22 | 139 | 5/22/2023 |
0.1.21 | 170 | 5/21/2023 |
0.1.20 | 173 | 5/20/2023 |
0.1.17 | 175 | 5/9/2023 |
0.1.16 | 151 | 5/6/2023 |
0.1.15 | 168 | 5/4/2023 |
0.1.14 | 187 | 5/2/2023 |
0.1.12 | 159 | 5/1/2023 |
0.1.11 | 170 | 4/29/2023 |
0.1.9 | 168 | 4/29/2023 |
0.1.8 | 166 | 4/29/2023 |
0.1.7 | 198 | 4/28/2023 |
0.1.6 | 182 | 4/27/2023 |
0.1.5 | 191 | 4/27/2023 |
0.1.4 | 193 | 4/25/2023 |
0.1.3 | 210 | 4/23/2023 |
0.1.2 | 222 | 4/22/2023 |
0.1.1 | 241 | 4/22/2023 |
0.0.4-preview040 | 158 | 4/21/2023 |
0.0.4-preview039 | 133 | 4/13/2023 |
0.0.4-preview038 | 158 | 4/11/2023 |
0.0.4-preview037 | 144 | 4/7/2023 |
0.0.4-preview036 | 154 | 3/31/2023 |
0.0.4-preview035 | 135 | 3/31/2023 |
0.0.4-preview034 | 151 | 3/31/2023 |
0.0.4-preview033 | 159 | 3/30/2023 |
0.0.4-preview032 | 161 | 3/19/2023 |
0.0.4-preview029 | 155 | 3/18/2023 |
0.0.4-preview028 | 151 | 3/15/2023 |
0.0.4-preview027 | 142 | 3/13/2023 |
0.0.4-preview026 | 146 | 3/12/2023 |
0.0.4-preview025 | 152 | 3/10/2023 |
0.0.4-preview024 | 150 | 3/9/2023 |
0.0.4-preview022 | 174 | 3/9/2023 |
0.0.4-preview021 | 144 | 3/7/2023 |
0.0.4-preview020 | 173 | 3/7/2023 |
0.0.4-preview019 | 131 | 3/4/2023 |
0.0.4-preview018 | 170 | 3/4/2023 |
0.0.4-preview017 | 157 | 3/4/2023 |
0.0.4-preview016 | 139 | 3/1/2023 |
0.0.4-preview015 | 155 | 2/28/2023 |
0.0.4-preview014 | 162 | 2/23/2023 |
0.0.4-preview013 | 174 | 2/23/2023 |
0.0.4-preview012 | 184 | 2/21/2023 |
0.0.4-preview011 | 150 | 2/20/2023 |
0.0.4-preview010 | 146 | 2/20/2023 |
0.0.4-preview009 | 139 | 2/19/2023 |
0.0.4-preview008 | 178 | 2/14/2023 |
0.0.4-preview007 | 147 | 2/10/2023 |
0.0.4-preview006 | 157 | 2/8/2023 |
0.0.4-preview005 | 165 | 2/8/2023 |
0.0.4-preview004 | 132 | 2/7/2023 |
0.0.4-preview003 | 135 | 2/7/2023 |
0.0.4-preview002 | 150 | 2/7/2023 |
0.0.4-preview001 | 150 | 2/3/2023 |
0.0.4-preview000 | 149 | 2/2/2023 |
0.0.3-preview032 | 155 | 2/1/2023 |
0.0.3-preview031 | 148 | 2/1/2023 |
0.0.3-preview030 | 170 | 1/30/2023 |
0.0.3-preview029 | 161 | 1/21/2023 |
0.0.3-preview028 | 154 | 1/19/2023 |
0.0.3-preview027 | 171 | 1/18/2023 |
0.0.3-preview026 | 185 | 1/16/2023 |
0.0.3-preview025 | 138 | 1/15/2023 |
0.0.3-preview024 | 183 | 1/15/2023 |
0.0.3-preview020 | 163 | 1/15/2023 |
0.0.3-preview019 | 149 | 1/11/2023 |
0.0.3-preview018 | 173 | 1/11/2023 |
0.0.3-preview017 | 179 | 1/7/2023 |
0.0.3-preview016 | 160 | 1/7/2023 |
0.0.3-preview015 | 166 | 1/6/2023 |
0.0.3-preview014 | 158 | 1/6/2023 |
0.0.3-preview013 | 166 | 1/6/2023 |
0.0.3-preview012 | 173 | 1/6/2023 |
0.0.3-preview011 | 164 | 1/6/2023 |
0.0.3-preview010 | 186 | 1/3/2023 |
0.0.3-preview009 | 171 | 1/3/2023 |
0.0.3-preview008 | 175 | 1/2/2023 |
0.0.3-preview007 | 172 | 1/2/2023 |
0.0.3-preview006 | 158 | 1/2/2023 |
0.0.3-preview005 | 167 | 1/2/2023 |
0.0.3-preview004 | 174 | 1/1/2023 |
0.0.3-preview003 | 166 | 12/31/2022 |
0.0.3-preview002 | 214 | 12/28/2022 |
0.0.3-preview001 | 218 | 12/21/2022 |
0.0.3-preview000 | 167 | 11/29/2022 |
0.0.2-preview003 | 147 | 11/4/2022 |
0.0.2-preview002 | 161 | 11/4/2022 |
0.0.2-preview000 | 216 | 11/4/2022 |
0.0.1-preview002 | 192 | 11/4/2022 |
0.0.1-preview001 | 178 | 11/4/2022 |