An initialization vector adds a layer of cryptographic security to encrypted information sent in URL query strings. Possible applications include (but are not limited to) DocPop, the OnBase Patient Window, and the OnBase Web Viewer. An Epic External System Setting is not required to be configured to enable initialization vectors as initialization vectors are enabled by default. However, initialization vectors can be disabled by using the Epic Encryption Initialization Vector Required Epic External System Setting.
Note: If using Java Web Encryption (including AES 128 JWE and AES
256 JWE), the Epic Encryption Initialization Vector Required
setting is always treated as true.
CAUTION: It is highly recommended that initialization
vectors remain enabled if you have any OnBase
applications that will receive Epic authentication information through a URL query
string.
To disable initialization vectors for URL integrations: