As part of securing the status webhook API endpoints, clarification is required on the security capabilities supported by OpenText Notification (OTN).
Can anyone share your thoughts whether the following options are supported:
- Request/Payload Signature
Does OTN sign outgoing webhook requests (e.g., using HMAC or similar methods) so that the authenticity and origin of the request can be validated?
Does OTN use static outbound IP addresses for webhook calls that can be whitelisted at the API gateway?
Is there support for configuring mutual TLS (client certificate-based authentication) for webhook communication?