Federation - Authorization of IdPs via Whitelist, v1.0

Relying Parties may establish a set of trusted IdPs via a whitelist as long as the trusted IdPs adhere to defined federation requirements.

Assessment Step

1
Whitelist IdPs (WhitelistIdPs)
Does the RP utilize a whitelist of IdPs, while having some assurances that any IDP on the whitelist is eligible to be there? An example of a white listed model is one where a federation operator approves IdPs and the RP selects who from the approved list to trust locally.
Artifact
A1
Provide evidence (e.g. policies, compliance/assessment reports) that use of white listed IdPs is handled correctly.

Conformance Criteria (1)

C1
  • RPs MAY establish whitelists of IdPs that the RP will accept authentication and attributes from without a runtime decision from the subscriber.
  • All IdPs in an RP's whitelist SHALL abide by the provisions and requirements in the 800-63 suite.
  • The whitelist MUST identify authorized IdPs by a domain or other sufficiently unique identifier, depending on the federation protocol in use.
Citation
NIST SP 800-63C
Section 4.2, Paragraph 3