Federation - Authorization of IdPs via Runtime Decision by an Authorized Party, v1.0

Relying Parties may allow authorized parties (usually a subscriber) to establish trust with an IdP of their choosing at runtime.

Assessment Step

1
Greylist IdPs (GreylistIdPs)
Does the RP allow authorized parties (typically subscribers) to choose to trust IdPs at runtime safely from IdPs that are not blacklisted or whitelisted?
Artifact
A1
Provide evidence (e.g. policies, compliance/assessment reports) that use of dynamically trusted IdPs is handled correctly.

Conformance Criteria (1)

C1
  • Every IdP that is not on a whitelist or a blacklist SHALL be placed by default in a gray area where runtime authorization decisions will be made by an authorized party, usually the subscriber.
  • The RP MAY remember a subscriber's decision to authorize a given IdP, provided that the RP SHALL allow the subscriber to revoke such remembered access at a future time.
Citation
NIST SP 800-63C
Section 4.2, Paragraph 3