Federation - No Assumption of Propagated Termination of Subscriber Sessions, v1.0

Identity Providers must not rely on RPs to terminate subscriber sessions when the IdP terminates the subscriber session. It must not rely on such functionality for any security requirement.

Assessment Step

1
IdP No Propagated Logout Assumptions (IdPNoPropagatedLogoutAssumptions)
Does the IdP NOT make any assumptions that all RPs terminate their sessions with a subscriber when the IdP terminates it's session? The crux of the issue is that single logout protocols are inherently unreliable and should not be depended on for any critical security requirements.
Artifact
A1
Provide evidence (e.g. policies, operational samples, screenshots) that the IdP makes no assumptions about session termination at RPs.

Conformance Criteria (1)

C1
The IdP SHALL NOT assume that termination of the subscriber's session at the IdP will propagate to any sessions that subscriber would have at downstream RPs.
Citation
NIST SP 800-63C
Section 5.3, Paragraph 2