Federation - Support for NIST SP 800-63C FALs, v1.0

Identity Providers SHALL only operate at FALs for which they have demonstrated the ability to operate at appropriately.

Assessment Step

1
FAL Certification (FALCertification)
Does the IdP support at least one FAL? Please specify all FALs the IdP supports as parameters. Add additional artifacts for each FAL it supports beyond the first.
Artifact
A1
Provide evidence (e.g. policies, operational samples) that the IdP supports each FAL it claims to support.
Parameter
FALs Supportedrequired
ENUM_MULTI : Select all FALs that the IdP supports.
  • FAL1
  • FAL2
  • FAL3

Conformance Criteria (1)

C1
  • The IdP SHALL NOT make any claim or indication to the RP that an assertion meets FAL3 criteria unless it is a holder-of-key assertion, digitally signed using approved cryptography, and encrypted using approved cryptography.
  • The IdP SHALL NOT make any claim or indication to the RP that an assertion meets FAL2 criteria unless it is a bearer assertion, digitally signed using approved cryptography, and encrypted using approved cryptography.
  • The IdP SHALL NOT make any claim or indication to the RP that an assertion meets FAL1 criteria unless it is a bearer assertion and digitally signed using approved cryptography.
Citation
NIST SP 800-63C
Sections 4, 6.1.2, 6.2.2, and 6.2.3