Federation - Validation of Assertion Audience Membership, v1.0

Relying Parties must make sure that all assertions include an audience that includes the RP within it's membership.

Assessment Step

1
Assertion Audience (AssertionAudience)
Does the RP verify the audience of assertions includes itself?
Artifact
A1
Provide evidence (e.g. policies, operational details) that RPs verify the audience of assertions.

Conformance Criteria (1)

C1
All RPs SHALL check that the audience of an assertion contains an identifier for their RP to prevent the injection and replay of an assertion generated for one RP at another RP.
Citation
NIST SP 800-63C
Section 6.2.4