{
  "resourceType": "StructureDefinition",
  "id": "ext-applicable-certificates",
  "url": "http://pcm.fhir.health.gov.il/StructureDefinition/ext-applicable-certificates",
  "version": "0.3.2",
  "name": "ExtApplicableCertificates",
  "title": "Ext: Applicable certificates",
  "status": "active",
  "description": "PCM-managed read-only projection of one or more certificate thumbprints (x5t#S256, base64url SHA-256 of the DER certificate) explicitly associated with this resource under the current participant-registration policy. The association may be established by the current manual process or by a future automated process without changing this representation. The extension is certificate inventory metadata: it does not describe PCM's complete trust store, prove current certificate presentation or authorization, or declare that an OAuth access token is certificate-bound.",
  "fhirVersion": "4.0.1",
  "kind": "complex-type",
  "abstract": false,
  "context": [
    {
      "expression": "Organization",
      "type": "element"
    },
    {
      "expression": "Endpoint",
      "type": "element"
    }
  ],
  "type": "Extension",
  "baseDefinition": "http://hl7.org/fhir/StructureDefinition/Extension",
  "derivation": "constraint",
  "differential": {
    "element": [
      {
        "id": "Extension",
        "path": "Extension",
        "short": "Ext: Applicable certificates",
        "definition": "PCM-managed read-only projection of one or more certificate thumbprints (x5t#S256, base64url SHA-256 of the DER certificate) explicitly associated with this resource under the current participant-registration policy. The association may be established by the current manual process or by a future automated process without changing this representation. The extension is certificate inventory metadata: it does not describe PCM's complete trust store, prove current certificate presentation or authorization, or declare that an OAuth access token is certificate-bound."
      },
      {
        "id": "Extension.extension",
        "path": "Extension.extension",
        "min": 1
      },
      {
        "id": "Extension.extension:thumbprint",
        "path": "Extension.extension",
        "sliceName": "thumbprint",
        "min": 1,
        "max": "*"
      },
      {
        "id": "Extension.extension:thumbprint.extension",
        "path": "Extension.extension.extension",
        "max": "0"
      },
      {
        "id": "Extension.extension:thumbprint.url",
        "path": "Extension.extension.url",
        "fixedUri": "thumbprint"
      },
      {
        "id": "Extension.extension:thumbprint.value[x]",
        "path": "Extension.extension.value[x]",
        "short": "Associated certificate thumbprint (x5t#S256)",
        "comment": "PCM derives this base64url value without padding from the SHA-256 hash of the DER-encoded X.509 certificate associated with the resource. The applicable create/update request profiles prohibit client-supplied values; PCM alone populates and maintains the authoritative inventory.",
        "min": 1,
        "type": [
          {
            "code": "string"
          }
        ]
      },
      {
        "id": "Extension.url",
        "path": "Extension.url",
        "fixedUri": "http://pcm.fhir.health.gov.il/StructureDefinition/ext-applicable-certificates"
      },
      {
        "id": "Extension.value[x]",
        "path": "Extension.value[x]",
        "max": "0"
      }
    ]
  }
}