Configure DICOM TLS using the BCP 195 Secure Transport Connection Profile on an Orthanc server

domain: orthanc.uclouvain.be · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Generate a server certificate and private key (or obtain them from your PKI); place both PEM files in a directory accessible to the Orthanc process
  2. In orthanc.json set DicomTlsEnabled to true, DicomTlsCertificate to the path of the server certificate PEM, DicomTlsPrivateKey to the key PEM, and optionally DicomTlsTrustedCertificates to a CA bundle for mutual TLS
  3. Configure the DICOM TLS port in DicomPort (the IANA-registered well-known port for DICOM TLS is 2762, though any port may be used) and set DicomCheckModalityHost to true to enforce hostname verification
  4. Register the TLS-enabled remote modality in the Modalities section with a UseDicomTls: true flag so that outbound C-STORE and C-FIND associations from Orthanc also use TLS
  5. Test the TLS connection using dcmtk echoscu with --tls-key and --tls-cert options and confirm the association succeeds without certificate errors

Known gotchas

Related routes

Provision and rotate mutual-TLS client certificates for OCPP 2.0.1 Security Profile 3
openchargealliance.org · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans