Authentication - Acceptable Verifier-CSP Communications, v1.0

Credential Service Providers must function as the authenticator verifier or must have a mutually authenticated secure channel with the authenticator verifier over which all communications occur.

Assessment Step

1
Verifier CSP Communication (VerifierCSPCommunication)
Are the CSP and verifier the same entity or do they use a mutually authenticated secure channel to communicate?
Artifact
A1
Provide evidence (e.g. policies, operational details, processes) that the CSP is the verifier or that a mutually authenticated secure channel is used for communications between the CSP and verifier.

Conformance Criteria (1)

C1
In situations where the verifier and CSP are separate entities, communications between the verifier and CSP SHALL occur through a mutually-authenticated secure channel (such as a client-authenticated TLS connection) using approved cryptography.
Citation
NIST SP 800-63B
Section 5.2.6