Federation - Authorization of IdPs via Blacklist, v1.0

Relying Parties may establish a set of IdPs via a blacklist with whom they do not interoperate.

Assessment Step

1
Blacklist IdPs (BlacklistIdPs)
Does the RP utilize a blacklist of IdPs that subscribers may not utilize even if requested by the subscriber?
Artifact
A1
Provide evidence (e.g. policies, compliance/assessment reports) that use of black listed IdPs is handled correctly.

Conformance Criteria (1)

C1
  • RPs MAY also establish blacklists of IdPs that the RP will not accept authentication or attributes from, even when requested by the subscriber.
  • The blacklist MUST identify prohibited IdPs by a domain or other sufficiently unique identifier, depending on the federation protocol in use.
Citation
NIST SP 800-63C
Section 4.2, Paragraph 3