Federation - Validation of Assertion Confidentiality, v1.0

Relying Parties must require assertions to be encrypted or delivered via protected and authenticated channels.

Assessment Step

1
Assertion Encryption (AssertionEncryption)
Does the RP require assertions to be encrypted or retrieves them directly from authoritative sources via authenticated and protected channels? Assertions passed through browsers must be encrypted. Assertions relayed directly from IdP to RP only have to be encrypted at FAL3.
Artifact
A1
Provide evidence (e.g. policies, operational details) that RPs only accept encrypted assertions or use an authenticated protected channel to retrieve them.

Conformance Criteria (1)

C1
  • The RP SHALL NOT accept an assertion at FAL2 or FAL3 unless the assertion is encrypted using approved cryptography.
  • The RP SHALL NOT accept any assertion that is not encrypted using approved cryptography, unless it received the assertion via an authenticated protected channel.
  • The RP SHALL NOT accept any unencrypted assertion that it received from an IdP via a third party, such as a browser.
Citation
NIST SP 800-63C
Section 6.2.3