Federation - Protection Against Assertion Misuse, v1.0

Relying Parties must protect themselves against injection attacks attempting to use captured or manufactured assertions.

Assessment Step

1
Protection Against Assertion Misuse (ProtectionAgainstAssertionMisuse)
Does the RP protect itself from manufactured or captured assertions? This typically requires verifying signatures of all assertion data and only using data signed and encoded properly. If an RP only requires directly requesting assertions from the IdP it will be less susceptible to malformed assertion attacks.
Artifact
A1
Provide evidence (e.g., policies, operational details) that the RP protects itself from malformed assertions.

Conformance Criteria (1)

C1
The RP SHALL protect itself against injection of manufactured or captured assertions by use of cross-site scripting protection or other accepted techniques.
Citation
NIST SP 800-63C
Section 7.2