Obligation scoping

Core is a subset of Full, not a separate track

Full is every obligation that applies to a role, with nothing excluded, by definition the entire profile. Core is the minimum interoperability line SAMLscope selected from the MUST-level obligations directly needed for SSO, metadata, and algorithm interoperability. This is SAMLscope's own classification: the Kantara profile itself does not distinguish Core from Full.

IdP profile: 414 applicable obligations

Full
254Core
+160 Full-only

Core is the minimum interoperability line SAMLscope selected from the MUST-level obligations directly needed for SSO, metadata, and algorithm interoperability. Full is every obligation that applies to the role.

SP profile: 320 applicable obligations

Full
183Core
+137 Full-only

Core is the minimum interoperability line SAMLscope selected from the MUST-level obligations directly needed for SSO, metadata, and algorithm interoperability. Full is every obligation that applies to the role.

What's tested

One requirement can decompose into several obligations, each independently testable and independently scored.

  • Protocols & bindingsWeb Browser SSO, Single Logout, and Enhanced Client or Proxy, over HTTP-Redirect, HTTP-POST, and SOAP back-channel.
  • Messages & assertionsRequests, responses, assertions, identifiers, ForceAuthn, IsPassive, NameIDPolicy, ACS selection, and proxy processing.
  • MetadataAcquisition, trust, scheduled refresh, key rollover, MDQ, discovery, and algorithm declarations.
  • Signatures & encryptionSupported algorithm verification and compliance with algorithm declarations in metadata.
Roadmap

Phase 1 of 5

Later phases reuse the Phase 1 Test Runner foundation and work backward from attacker capabilities rather than adding new infrastructure.

Current1Implementation ConformanceKantara IIP v1.1
2Core ConformanceOASIS SAML Core / Bindings / Profiles
3Deployment & InteroperabilityKantara Deployment Profile v2.0
4Security & Attacker ModelOASIS Security & Privacy Considerations
5Fuzzing & Differential TestingSAMLscope-original scope

Explicitly out of scope for Phase 1

  • Attack testing (XSW, signature forgery, replay): deferred to Phase 4
  • Artifact binding and Attribute Query: deferred to Phase 2
  • Special behavior of IdP proxies and gateways: deferred to Phase 3
  • Performance, load, or intrusive testing: never in scope