IP Addresses for production environment
IP Addresses for test environment
HelseID is a webservice that is used via a web browser. It is available both via the Internet and via the norwegian health network (Helsenettet), but some of the identity providers we support are only available on the Internet.
To use HelseID you must either setup a proxy that automatically routes the network traffic as expected, or you can manually setup your firewall and DNS as required. Further you need to ensure that your server trusts the HelseID signing certificate by ensuring that the required root certificates are available and you must ensure that your server clock is synchronized with the NHN time server.
Ensuring correct network setup
Your network can either be setup using the NHN proxy server or you can manually setup the required firewall exceptions and DNS.
Proxy setup
Using the NHN proxy server gives access to all the required services. In most cases this is the easiest was to ensure your environment supports HelseID. Setting up the proxy server is done by using the following automatic configuration: http://config.nhn.no/kunde.pac
The following figure is an example of how to set this up manually on Windows in Internet Explorer:
Warning: We expect your IT-department to setup an automatic deployment of this configuration to all relevant web browsers, we do not recommend that users set this up manually. It is the responsibility of your organization to ensure that this configuration does not interrupt any other services you may use.
Firewall and DNS configuration for the HelseID production environment
Description | Internet | Helsenettet |
---|---|---|
HelseID | https://helseid-sts.nhn.no, 91.186.66.76 83.118.188.93 | https://helseid-sts.nhn.no, 91.186.92.124, 91.186.86.41 |
ID-porten | idporten.difi.no, 146.192.252.60 idporten.no + login.idporten.no, 139.105.36.167 (NEW❗) | Not available in Helsenettet |
ID-porten OpenID Connect provider | oidc.difi.no, 146.192.252.54 146.192.252.54 | Not available in Helsenettet |
Buypass ID provider | secure.buypass.no, 185.62.160.142 185.62.162.142 auth.tsp.buypass.no, 185.62.162.168 | secure.nhn.buypass.no, 91.186.95.67 |
Commfides ID provider | app03.commfides.com, 91.232.83.41 openid.commfides.com, 91.232.83.30 | app03.commfides.com, 91.186.95.25 openid.commfides.com, 91.186.95.25 |
BankID ID provider | csfe.bankid.no, 193.26.146.36 login.bankid.no, 79.171.82.41 auth.bankid.no, 79.171.82.40 | Not available in Helsenettet |
The port number for all addresses is 443.
Firewall and DNS configuration for the HelseID test environment
Description | Internet | Helsenettet |
---|---|---|
HelseID | helseid-sts.test.nhn.no, 91.186.67.113 83.118.188.94 | helseid-sts.test.nhn.no, 83.118.129.185 91.186.86.46 |
ID-porten | idporten-ver2.difi.no, 146.192.252.156 test.idporten.no + login.test.idporten.no, 139.105.36.135 (NEW❗) | Not available in Helsenettet |
ID-porten OpenID Connect provider | oidc-ver2.difi.no, 146.192.252.152 | Not available in Helsenettet |
Buypass ID provider | auth.tsp.test4.buypass.no, 185.62.163.159 secure.test4.buypass.no, 185.62.163.53 | Not available in Helsenettet |
Commfides ID provider | app03.test.commfides.com, 91.232.83.133 openid.test.commfides.com, 91.232.83.115 | Not available in Helsenettet |
BankID ID provider | csfe-preprod.bankid.no, 193.26.146.6 login.current.bankid.no, 79.171.82.45 auth.current.bankid.no, 79.171.82.44 | Not available in Helsenettet |
The port number for all addresses is 443.
Trusted root certificates
The HelseID signing certificate is issued by Buypass and the Buypass root certificates must be trusted in all environments using HelseID.
These root certificates are already installed in most operating systems but if you need to register them manually they can be downloaded from the following addresses:
Name | Download url |
---|---|
Buypass Class 3 Root CA | |
Buypass Class 2 Root CA |
On Windows these certificates must be placed in the Local Computer / Trusted Root Certificate Authorities / Certificates store.
Time server setup
To use HelseID the server clock must be synchronized with the NHN time server. For servers in the health network (Helsenettet) the following server is available: ntp.nhn.no.