The Direct address for the D1 test case does not have a valid certificate. Below is a screenshot of the results when using the Direct Certificate Discovery Tool to verify the certificate for d...@domain1.dcdt30.healthit.gov. I ran this after I was unable to send a message to the address from my Direct address.

Regards,
Andrew J. Cookson
VP – Customer Success and Implementation

o: 703.884.2904
acoo...@secureexsolutions.com
Direct –
acoo...@directaddress.net
www.secureexsolutions.com
Disclaimer: The information contained in this transmission and any attachments may contain privileged and confidential information including patient information protected by federal and state privacy laws. This transmission is sent for the sole use of the intended recipient. If you are not the intended recipient, please immediately (1) notify the sender via reply email; (2) do not open or read the message or any attachments; and (3) delete this message and any attachments. The review, dissemination, distribution, or duplication of this transmission by anyone other than the intended recipient is strictly prohibited.

--
You received this message because you are subscribed to the Google Groups "Edge Test Tool (ETT)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to edge-test-too...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/edge-test-tool/ee1bcd6f-dd71-4f08-b3f8-30198bafaa83n%40googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/edge-test-tool/e8de3585-98da-495c-9c79-26f42f3676cfn%40googlegroups.com.
--
You received this message because you are subscribed to a topic in the Google Groups "Edge Test Tool (ETT)" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/edge-test-tool/5ZJ0p9KXQdA/unsubscribe.
To unsubscribe from this group and all its topics, send an email to edge-test-too...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/edge-test-tool/2ba61ef2-816c-48f8-95e6-d13c145c0c24n%40googlegroups.com.
--
You received this message because you are subscribed to the Google Groups "Edge Test Tool (ETT)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to edge-test-too...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/edge-test-tool/a7d1d50a-9e61-4a97-82ae-83aeeeb860f5n%40googlegroups.com.
Andrew
Which particular certificate are you trying to discover ? (LDAP or DNS ? )
Can you provide the domain name and the dig command you are using.
Thanks
Dragon
From:
Andrew Cookson <andrew....@gmail.com>
Date: Monday, July 14, 2025 at 2:47 PM
To: Nagesh Bashyam <nagesh....@drajer.com>
Cc: Edge Test Tool (ETT) <edge-te...@googlegroups.com>
Subject: Re: D1 - Valid address-bound certificate discovery in DNS
Dragon,
I am able to pull the certificates when using the discovery tool on the healthit.gov website but still cannot pull it using other Certificate discovery tools or online dig tools. Can you confirm the necessary records are publicly available?
--
You received this message because you are subscribed to a topic in the Google Groups "Edge Test Tool (ETT)" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/edge-test-tool/5ZJ0p9KXQdA/unsubscribe.
To unsubscribe from this group and all its topics, send an email to edge-test-too...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/edge-test-tool/5b2bb20b-af87-4d3f-b4f5-5f2e821c1bf4n%40googlegroups.com.
--
Andrew J. Cookson
andrew....@gmail.com
908-309-8572 (cell)
--
You received this message because you are subscribed to a topic in the Google Groups "Edge Test Tool (ETT)" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/edge-test-tool/5ZJ0p9KXQdA/unsubscribe.
To unsubscribe from this group and all its topics, send an email to edge-test-too...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/edge-test-tool/5b2bb20b-af87-4d3f-b4f5-5f2e821c1bf4n%40googlegroups.com.
Hello
For determining how to test with the Direct tools, please refer to the Direct Test Procedure.(h1) and (h2).
https://www.healthit.gov/topic/certification-ehrs/onc-health-it-certification-program-test-method
I am not sure what exactly you are asking for, so I am providing the best answer that we can.
Thanks
Dragon
From:
edge-te...@googlegroups.com <edge-te...@googlegroups.com> on behalf of Shaina Luevano <ssvall...@gmail.com>
Date: Tuesday, July 15, 2025 at 11:18 AM
To: Edge Test Tool (ETT) <edge-te...@googlegroups.com>
Subject: Re: D1 - Valid address-bound certificate discovery in DNS
Hey Souvanik,
Sorry, are you part of the ETT support team?
James,
Are there any updates on this for us? Our partner has been waiting for months and has been unable to do anything. We would really like to get them across the finish line to allow them to finish their certification.
Thank you,
Shaina
To view this discussion visit https://groups.google.com/d/msgid/edge-test-tool/5093ad48-b2e7-4108-af64-f53ca9caae7dn%40googlegroups.com.
Andrew
The specific certificates are available through LDAP.
You can verify them using the following query:
ldapsearch -x -H ldap://ldap.dcdt31.healthit.gov:10389 -b "" "(mail=d...@domain2.dcdt31.healthit.gov)" cn mail userCertificate
Please let me know how you are doing the LDAP Query? Is it similar or different ?
Thanks
Dragon
From:
Andrew Cookson <andrew....@gmail.com>
Date: Monday, July 14, 2025 at 2:47
PM
To: Nagesh Bashyam <nagesh....@drajer.com>
Cc: Edge Test Tool (ETT) <edge-te...@googlegroups.com>
Subject: Re: D1 - Valid address-bound certificate discovery in DNS
Hey Souvanik,Sorry, are you part of the ETT support team?
James,
Are there any updates on this for us? Our partner has been waiting for months and has been unable to do anything. We would really like to get them across the finish line to allow them to finish their certification.
Thank you,Shaina
On Tuesday, July 8, 2025 at 12:10:15 PM UTC-6 Souvanik Sarkar wrote:
To view this discussion visit https://groups.google.com/d/msgid/edge-test-tool/5093ad48-b2e7-4108-af64-f53ca9caae7dn%40googlegroups.com.
Shaina
We are exchanging emails with Andrew to see how it is being tested and what issues they are having.
If you are having specific issues, can you post a thread with the specific issues that you are encountering so that we can address them appropriately.
Thanks
Dragon
From:
edge-te...@googlegroups.com <edge-te...@googlegroups.com> on behalf of Shaina Luevano <ssvall...@gmail.com>
Date: Friday, July 18, 2025 at 1:39 PM
To: Edge Test Tool (ETT) <edge-te...@googlegroups.com>
Subject: Re: D1 - Valid address-bound certificate discovery in DNS
--
You received this message because you are subscribed to the Google Groups "Edge Test Tool (ETT)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
edge-test-too...@googlegroups.com.
To view this discussion visit
https://groups.google.com/d/msgid/edge-test-tool/7380345d-6058-4e58-8123-302746541229n%40googlegroups.com.
Andrew
Thanks for providing this information.
We are in communication with MaxMD on the tool to understand what the tool is doing. We have exchanged queries that are being exchanged (both successful and unsuccessful), so we will follow up with them on the topic.
As far as the other tool goes, (digwebinterface) that would be more for DNS lookups, which in the case of LDAP does not really help except to look up NS Records which succeeds. The CERT records are in LDAP and not in DNS.
We believe the Base DN search is yielding what needs to be extracted from DCDT and then the LDAP search on the DN’s yields the certificate according to the specifications unless something is mi-interpreted.
Any further insights into what exactly you are doing would be necessary for us to track down if there is an issue.
I have posted the commands that would be used typically in previous threads.
If needed we can jump on a call.
Please let us know.
Thanks
Dragon
--
You received this message because you are subscribed to the Google Groups "Edge Test Tool (ETT)" group.
To unsubscribe from this group and stop receiving emails from it, send an email to
edge-test-too...@googlegroups.com.
To view this discussion visit
https://groups.google.com/d/msgid/edge-test-tool/aee64dd1-c138-428b-be5b-ddf4787f8e3en%40googlegroups.com.
Yes, the reason they were updated is because in the previous update the CRL URL was not providing the required data back to the requester which some of the HISP’s were validating and rejecting the certificates because they were not able to verify if the certificate was valid/invalid.
Hope it helps.
Thanks
Dragon
To view this discussion visit https://groups.google.com/d/msgid/edge-test-tool/9558b8fe-872a-4601-aec9-a01309258300n%40googlegroups.com.