Federation - Proper Generation of Holder-of-Key Assertions, v1.0

Identity Providers operating at higher assurance levels must support holder of key assertions, which must not include an unencrypted private or symmetric key to be used with holder-of-key presentation

Assessment Step

1
HoK Assertions (HoKAssertions)
Does the IdP implement HoK Assertions correctly, encrypting the key material the RP will use to verify the subscriber?
Artifact
A1
Provide evidence (e.g. policies, operational samples) that the IdP correctly builds HoK assertions.

Conformance Criteria (1)

C1
The assertion SHALL NOT include an unencrypted private or symmetric key to be used with holder-of-key presentation.
Citation
NIST SP 800-63C
Section 6.1.2