Federation - No Support for Back-Channel Assertion Presentation with Assertion References, v1.0

Identity Providers that do not allow direct RP to IdP communication must not use assertion references.

Assessment Step

1
No Back Channel (NoBackChannel)
Does the IdP exclusively use front channel communication? (all communication from IdP to RP flows through the user's browser)
Artifact
A1
Provide evidence (e.g. policies, operational samples) that the IdP communicates with the RP exclusively through the user agent.

Conformance Criteria (1)

C1
The IdP MUST transmit all assertions directly without references.
Citation
NIST SP 800-63C
Sections 7.1 and 7.2