{"version":1,"sourceCommit":"cdf425958bf00d03036f9880cbc22efa74cf3815","sources":{"tests/coverage.yaml":"2bee3db74c9be9908710bbe18935c73454f1ed4c5c0f06bdab1cf18deaef843c","tests/cases.yaml":"431d9aa863d5d882d37266667a8fd20547d1fe6d037274b8d59ff66347f5ecd4","tests/specs.yaml":"acee5ce8c348fbc5e02f77bd2f5b8703a632dd69aea857b14b97812ff6cc39d9","tests/predicates.yaml":"ea0aec770d743d0c8315c706ae80fb5979a103021ebdc4fcf86187c052e90262","profiles/browser_sso_idp.json":"8841ab92288146c657efb5f3df5ded60970c890448459f0a80fd141eb7fd5c5f","profiles/browser_sso_sp.json":"159c8e15f6a3e06b434d2e2464c75d40829ed8f54b0de23e1b1f4d566aa3228b","profiles/metadata_idp.json":"5b1e904ef9b19bc6267bca6d54f44e9ea06dcd76acb35dad39cb1b1a5f1198fd","profiles/metadata_sp.json":"3deeb97b95062dec6670aa5b5211a1c9b26406b28283047cf87788dba426dc93","profiles/single_logout_idp.json":"0158baceb4c032f36c8a9fdbeb89916163a3b61ae567e898b5cd6ed6df06f846","profiles/single_logout_sp.json":"4d8d77c4e0d22d69d6e44c2b896b4c4df45c46d2486311d4b519ae1ce9ebb92a","profiles/ecp_idp.json":"f930459e44962ea682d00fc4b8efac5440682ddb550da4ac54c114d523281d5e"},"profiles":{"browser_sso_idp":"Web Browser SSO — IdP","browser_sso_sp":"Web Browser SSO — SP","metadata_idp":"Metadata — IdP","metadata_sp":"Metadata — SP","single_logout_idp":"Single Logout — IdP","single_logout_sp":"Single Logout — SP","ecp_idp":"ECP — IdP"},"profileVersions":{"browser_sso_idp":"functional-case-v1","browser_sso_sp":"functional-case-v1","metadata_idp":"functional-case-v1","metadata_sp":"functional-case-v1","single_logout_idp":"functional-case-v1","single_logout_sp":"functional-case-v1","ecp_idp":"functional-case-v1"},"rows":[{"id":"IIP-G01.a:idp","requirement":"IIP-G01","section":"2.1","sectionName":"Common / General","anchor":"#IIP-G01","obligation":"IIP-G01.a","role":"idp","level":"MUST","summary":"Allow for reasonable clock skew when interpreting xsd:dateTime values and enforcing policy based on them","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"],"cases":[{"id":"IIP-G01-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"]}]},{"id":"IIP-G01.a:sp","requirement":"IIP-G01","section":"2.1","sectionName":"Common / General","anchor":"#IIP-G01","obligation":"IIP-G01.a","role":"sp","level":"MUST","summary":"Allow for reasonable clock skew when interpreting xsd:dateTime values and enforcing policy based on them","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp","single_logout_sp"],"cases":[{"id":"IIP-G01-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp","metadata_sp","single_logout_sp"]}]},{"id":"IIP-G02.a:idp","requirement":"IIP-G02","section":"2.1","sectionName":"Common / General","anchor":"#IIP-G02","obligation":"IIP-G02.a","role":"idp","level":"MUST","summary":"Accept, without error, xs:string values of any valid XML characters up to 256 characters","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-G02-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-G02.a:sp","requirement":"IIP-G02","section":"2.1","sectionName":"Common / General","anchor":"#IIP-G02","obligation":"IIP-G02.a","role":"sp","level":"MUST","summary":"Accept, without error, xs:string values of any valid XML characters up to 256 characters","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-G02-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-G02.b:sp","requirement":"IIP-G02","section":"2.1","sectionName":"Common / General","anchor":"#IIP-G02","obligation":"IIP-G02.b","role":"sp","level":"MUST","summary":"A Service Provider must not truncate received xs:string values of up to 256 characters","condition":null,"testability":"CONFIG","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-G02-b-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-G02.c:idp","requirement":"IIP-G02","section":"2.1","sectionName":"Common / General","anchor":"#IIP-G02","obligation":"IIP-G02.c","role":"idp","level":"MUST","summary":"An Identity Provider must not truncate received xs:string values of up to 256 characters","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-G02-c-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-G03.a:idp","requirement":"IIP-G03","section":"2.1","sectionName":"Common / General","anchor":"#IIP-G03","obligation":"IIP-G03.a","role":"idp","level":"MUST_NOT","summary":"Do not send SAML protocol messages containing a DTD","condition":null,"testability":"AUTOMATED","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp","single_logout_idp"],"cases":[{"id":"IIP-G03-a-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp","ecp_idp","single_logout_idp"]}]},{"id":"IIP-G03.a:sp","requirement":"IIP-G03","section":"2.1","sectionName":"Common / General","anchor":"#IIP-G03","obligation":"IIP-G03.a","role":"sp","level":"MUST_NOT","summary":"Do not send SAML protocol messages containing a DTD","condition":null,"testability":"AUTOMATED","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp","single_logout_sp"],"cases":[{"id":"IIP-G03-a-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp","single_logout_sp"]}]},{"id":"IIP-G03.b:idp","requirement":"IIP-G03","section":"2.1","sectionName":"Common / General","anchor":"#IIP-G03","obligation":"IIP-G03.b","role":"idp","level":"MUST","summary":"Have the ability to reject SAML protocol messages containing a DTD","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-G03-b-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-G03.b:sp","requirement":"IIP-G03","section":"2.1","sectionName":"Common / General","anchor":"#IIP-G03","obligation":"IIP-G03.b","role":"sp","level":"MUST","summary":"Have the ability to reject SAML protocol messages containing a DTD","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-G03-b-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-MD01.a:idp","requirement":"IIP-MD01","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD01","obligation":"IIP-MD01.a","role":"idp","level":"MUST","summary":"Support acquisition of metadata rooted in md:EntityDescriptor via the Metadata Query Protocol","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD01-a-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD01.b:sp","requirement":"IIP-MD01","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD01","obligation":"IIP-MD01.b","role":"sp","level":"SHOULD","summary":"(SP) Should support acquisition of metadata rooted in md:EntityDescriptor via MDQ","condition":null,"testability":"CONFIG","sourceIds":["MDQ","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD01-b-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD01.c:idp","requirement":"IIP-MD01","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD01","obligation":"IIP-MD01.c","role":"idp","level":"MUST","summary":"Implementations claiming MDQ support must request and utilize metadata from one or more MDQ responders for any peer from which a SAML message is received","condition":{"predicate":"claims_mdq_support","predicate_kind":"CLAIM_BASED"},"testability":"CONFIG","sourceIds":["MDQ","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD01-c-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD01.c:sp","requirement":"IIP-MD01","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD01","obligation":"IIP-MD01.c","role":"sp","level":"MUST","summary":"Implementations claiming MDQ support must request and utilize metadata from one or more MDQ responders for any peer from which a SAML message is received","condition":{"predicate":"claims_mdq_support","predicate_kind":"CLAIM_BASED"},"testability":"CONFIG","sourceIds":["MDQ","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD01-c-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD02.a:idp","requirement":"IIP-MD02","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD02","obligation":"IIP-MD02.a","role":"idp","level":"MUST","summary":"Support scheduled/recurring consumption of metadata over HTTP/1.1, automatically applied upon successful validation","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD02-a-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD02.a:sp","requirement":"IIP-MD02","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD02","obligation":"IIP-MD02.a","role":"sp","level":"MUST","summary":"Support scheduled/recurring consumption of metadata over HTTP/1.1, automatically applied upon successful validation","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD02-a-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD02.b:idp","requirement":"IIP-MD02","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD02","obligation":"IIP-MD02.b","role":"idp","level":"MUST","summary":"Honor HTTP/1.1 redirects with status codes 301, 302 and 307","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD02-b-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD02.b:sp","requirement":"IIP-MD02","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD02","obligation":"IIP-MD02.b","role":"sp","level":"MUST","summary":"Honor HTTP/1.1 redirects with status codes 301, 302 and 307","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD02-b-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD02.c:idp","requirement":"IIP-MD02","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD02","obligation":"IIP-MD02.c","role":"idp","level":"MUST","summary":"Support consumption of metadata rooted in both md:EntityDescriptor and md:EntitiesDescriptor via this mechanism","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD02-c-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD02.c:sp","requirement":"IIP-MD02","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD02","obligation":"IIP-MD02.c","role":"sp","level":"MUST","summary":"Support consumption of metadata rooted in both md:EntityDescriptor and md:EntitiesDescriptor via this mechanism","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD02-c-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD02.d:idp","requirement":"IIP-MD02","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD02","obligation":"IIP-MD02.d","role":"idp","level":"MUST","summary":"When rooted in md:EntitiesDescriptor, allow any number of child elements","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD02-d-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD02.d:sp","requirement":"IIP-MD02","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD02","obligation":"IIP-MD02.d","role":"sp","level":"MUST","summary":"When rooted in md:EntitiesDescriptor, allow any number of child elements","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD02-d-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD03.a:idp","requirement":"IIP-MD03","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD03","obligation":"IIP-MD03.a","role":"idp","level":"MUST","summary":"Validate authenticity and integrity of metadata by verifying an enveloped XML Signature on the root element","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD03-a-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD03.a:sp","requirement":"IIP-MD03","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD03","obligation":"IIP-MD03.a","role":"sp","level":"MUST","summary":"Validate authenticity and integrity of metadata by verifying an enveloped XML Signature on the root element","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD03-a-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD03.b:idp","requirement":"IIP-MD03","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD03","obligation":"IIP-MD03.b","role":"idp","level":"MUST","summary":"Public keys used for metadata signature verification must be configured out of band","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD03-b-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD03.b:sp","requirement":"IIP-MD03","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD03","obligation":"IIP-MD03.b","role":"sp","level":"MUST","summary":"Public keys used for metadata signature verification must be configured out of band","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD03-b-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD03.c:idp","requirement":"IIP-MD03","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD03","obligation":"IIP-MD03.c","role":"idp","level":"MUST","summary":"It must be possible to ignore other certificate contents and verify the signature based solely on the public key","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD03-c-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD03.c:sp","requirement":"IIP-MD03","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD03","obligation":"IIP-MD03.c","role":"sp","level":"MUST","summary":"It must be possible to ignore other certificate contents and verify the signature based solely on the public key","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD03-c-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD03.d:idp","requirement":"IIP-MD03","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD03","obligation":"IIP-MD03.d","role":"idp","level":"MUST","summary":"It must be possible to limit the use of a trusted key to a single metadata source","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD03-d-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD03.d:sp","requirement":"IIP-MD03","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD03","obligation":"IIP-MD03.d","role":"sp","level":"MUST","summary":"It must be possible to limit the use of a trusted key to a single metadata source","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD03-d-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD03.e:idp","requirement":"IIP-MD03","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD03","obligation":"IIP-MD03.e","role":"idp","level":"MAY","summary":"The public keys used for metadata signature verification may be contained in X.509 certificates","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD03-e-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD03.e:sp","requirement":"IIP-MD03","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD03","obligation":"IIP-MD03.e","role":"sp","level":"MAY","summary":"The public keys used for metadata signature verification may be contained in X.509 certificates","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD03-e-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD04.a:idp","requirement":"IIP-MD04","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD04","obligation":"IIP-MD04.a","role":"idp","level":"MUST","summary":"Be capable of rejecting metadata whose root element lacks the validUntil attribute","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD04-a-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD04.a:sp","requirement":"IIP-MD04","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD04","obligation":"IIP-MD04.a","role":"sp","level":"MUST","summary":"Be capable of rejecting metadata whose root element lacks the validUntil attribute","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD04-a-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD04.b:idp","requirement":"IIP-MD04","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD04","obligation":"IIP-MD04.b","role":"idp","level":"MUST","summary":"Be capable of rejecting metadata whose root validUntil is in the past","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD04-b-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD04.b:sp","requirement":"IIP-MD04","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD04","obligation":"IIP-MD04.b","role":"sp","level":"MUST","summary":"Be capable of rejecting metadata whose root validUntil is in the past","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD04-b-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD04.c:idp","requirement":"IIP-MD04","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD04","obligation":"IIP-MD04.c","role":"idp","level":"MUST","summary":"Be capable of rejecting metadata whose root validUntil is too far into the future, where the threshold is a configurable option","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD04-c-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD04.c:sp","requirement":"IIP-MD04","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD04","obligation":"IIP-MD04.c","role":"sp","level":"MUST","summary":"Be capable of rejecting metadata whose root validUntil is too far into the future, where the threshold is a configurable option","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD04-c-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.a:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a","role":"idp","level":"MUST","summary":"Support SAML Metadata as defined in SAML V2.0 Metadata [SAML2Meta] as updated by Errata","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-a-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.a:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a","role":"sp","level":"MUST","summary":"Support SAML Metadata as defined in SAML V2.0 Metadata [SAML2Meta] as updated by Errata","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-a-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.a1:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a1","role":"idp","level":"MUST","summary":"Metadata entity identifiers must be unique across all interacting entities","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-a1-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.a1:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a1","role":"sp","level":"MUST","summary":"Metadata entity identifiers must be unique across all interacting entities","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-a1-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.a2:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a2","role":"idp","level":"MUST_NOT","summary":"A single metadata entity identifier must not refer to different entities","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-a2-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.a2:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a2","role":"sp","level":"MUST_NOT","summary":"A single metadata entity identifier must not refer to different entities","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-a2-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.a3:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a3","role":"idp","level":"MUST","summary":"Metadata extension content must be namespace-qualified as required by its extension point","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-a3-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.a3:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a3","role":"sp","level":"MUST","summary":"Metadata extension content must be namespace-qualified as required by its extension point","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-a3-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.a4:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a4","role":"idp","level":"MUST","summary":"A metadata instance root must be EntityDescriptor for one entity or EntitiesDescriptor for multiple entities","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-a4-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.a4:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a4","role":"sp","level":"MUST","summary":"A metadata instance root must be EntityDescriptor for one entity or EntitiesDescriptor for multiple entities","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-a4-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.a5:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a5","role":"idp","level":"MUST","summary":"A root EntityDescriptor or EntitiesDescriptor must contain validUntil or cacheDuration","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-a5-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.a5:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a5","role":"sp","level":"MUST","summary":"A root EntityDescriptor or EntitiesDescriptor must contain validUntil or cacheDuration","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-a5-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.a6:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a6","role":"idp","level":"RECOMMENDED","summary":"Only the root metadata element should contain validUntil or cacheDuration","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-a6-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.a6:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a6","role":"sp","level":"RECOMMENDED","summary":"Only the root metadata element should contain validUntil or cacheDuration","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-a6-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.a7:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a7","role":"idp","level":"RECOMMENDED","summary":"Multiple role descriptors of the same type should not overlap in protocolSupportEnumeration","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-a7-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.a7:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a7","role":"sp","level":"RECOMMENDED","summary":"Multiple role descriptors of the same type should not overlap in protocolSupportEnumeration","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-a7-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.a8:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a8","role":"idp","level":"MUST","summary":"AdditionalMetadataLocation namespace must identify the root namespace at the referenced location","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-a8-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.a8:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a8","role":"sp","level":"MUST","summary":"AdditionalMetadataLocation namespace must identify the root namespace at the referenced location","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-a8-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.a9:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a9","role":"idp","level":"MUST","summary":"A SAML V2.0 role protocolSupportEnumeration must include the SAML V2.0 protocol namespace URI","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-a9-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.a9:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.a9","role":"sp","level":"MUST","summary":"A SAML V2.0 role protocolSupportEnumeration must include the SAML V2.0 protocol namespace URI","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-a9-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ab:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ab","role":"idp","level":"MUST","summary":"ResponseLocation must be omitted for endpoints associated with only one message direction","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ab-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ab:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ab","role":"sp","level":"MUST","summary":"ResponseLocation must be omitted for endpoints associated with only one message direction","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ab-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ac:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ac","role":"idp","level":"MUST","summary":"If an affiliation owner is also a member, its identifier must appear as AffiliateMember","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ac-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ac:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ac","role":"sp","level":"MUST","summary":"If an affiliation owner is also a member, its identifier must appear as AffiliateMember","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ac-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ad:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ad","role":"idp","level":"SHOULD","summary":"A relying party should allow use of any same-purpose key included in metadata","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ad-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ad:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ad","role":"sp","level":"SHOULD","summary":"A relying party should allow use of any same-purpose key included in metadata","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ad-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ae:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ae","role":"idp","level":"SHOULD","summary":"A signing or encrypting party should identify the key used as specifically as possible","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ae-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ae:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ae","role":"sp","level":"SHOULD","summary":"A signing or encrypting party should identify the key used as specifically as possible","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ae-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.af:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.af","role":"idp","level":"RECOMMENDED","summary":"At least the root metadata element should be signed when no direct authenticated context exists","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-af-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.af:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.af","role":"sp","level":"RECOMMENDED","summary":"At least the root metadata element should be signed when no direct authenticated context exists","condition":null,"testability":"CONFIG","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-af-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ag:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ag","role":"idp","level":"MUST","summary":"SAML metadata signatures must be enveloped signatures","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ag-idp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ag:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ag","role":"sp","level":"MUST","summary":"SAML metadata signatures must be enveloped signatures","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ag-sp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ah:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ah","role":"idp","level":"SHOULD","summary":"Metadata processors should support RSA-SHA1 signing and verification","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ah-idp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ah:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ah","role":"sp","level":"SHOULD","summary":"Metadata processors should support RSA-SHA1 signing and verification","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ah-sp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ai:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ai","role":"idp","level":"MUST","summary":"A signed metadata element must have an identifier attribute value","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ai-idp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ai:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ai","role":"sp","level":"MUST","summary":"A signed metadata element must have an identifier attribute value","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ai-sp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.aj:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.aj","role":"idp","level":"MUST","summary":"A metadata signature must contain one same-document Reference to the signed element ID and cover all its content","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-aj-idp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.aj:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.aj","role":"sp","level":"MUST","summary":"A metadata signature must contain one same-document Reference to the signed element ID and cover all its content","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-aj-sp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ak:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ak","role":"idp","level":"SHOULD","summary":"Metadata signatures should use Exclusive Canonicalization in SignedInfo and as a Transform","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ak-idp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ak:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ak","role":"sp","level":"SHOULD","summary":"Metadata signatures should use Exclusive Canonicalization in SignedInfo and as a Transform","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ak-sp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.al:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.al","role":"idp","level":"SHOULD_NOT","summary":"Metadata signatures should not contain transforms other than enveloped-signature or Exclusive Canonicalization","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-al-idp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.al:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.al","role":"sp","level":"SHOULD_NOT","summary":"Metadata signatures should not contain transforms other than enveloped-signature or Exclusive Canonicalization","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-al-sp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.am:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.am","role":"idp","level":"MAY","summary":"A metadata signature verifier may reject signatures using other transforms","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-am-idp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.am:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.am","role":"sp","level":"MAY","summary":"A metadata signature verifier may reject signatures using other transforms","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-am-sp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.an:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.an","role":"idp","level":"MUST","summary":"If a verifier accepts other transforms, it must ensure no signed metadata content is excluded","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-an-idp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.an:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.an","role":"sp","level":"MUST","summary":"If a verifier accepts other transforms, it must ensure no signed metadata content is excluded","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-an-sp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ao:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ao","role":"idp","level":"MAY","summary":"A metadata signature may omit ds:KeyInfo","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ao-idp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ao:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ao","role":"sp","level":"MAY","summary":"A metadata signature may omit ds:KeyInfo","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ao-sp-01","mode":"AUTOMATED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ap:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ap","role":"idp","level":"MUST","summary":"A consumer must apply the shorter effective validUntil or cacheDuration from nested metadata","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ap-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ap:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ap","role":"sp","level":"MUST","summary":"A consumer must apply the shorter effective validUntil or cacheDuration from nested metadata","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ap-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.aq:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.aq","role":"idp","level":"MUST","summary":"Metadata caching must be based on cacheDuration","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-aq-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.aq:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.aq","role":"sp","level":"MUST","summary":"Metadata caching must be based on cacheDuration","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-aq-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ar:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ar","role":"idp","level":"MUST","summary":"Metadata must be considered invalid at effective validUntil","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ar-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ar:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ar","role":"sp","level":"MUST","summary":"Metadata must be considered invalid at effective validUntil","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ar-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.as:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.as","role":"idp","level":"MUST_NOT","summary":"Invalid metadata must not be used","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-as-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.as:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.as","role":"sp","level":"MUST_NOT","summary":"Invalid metadata must not be used","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-as-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.at:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.at","role":"idp","level":"MAY","summary":"Stale but not explicitly invalid metadata may be used","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-at-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.at:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.at","role":"sp","level":"MAY","summary":"Stale but not explicitly invalid metadata may be used","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-at-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.au:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.au","role":"idp","level":"MAY","summary":"When ResponseLocation is omitted, responses are handled at Location","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-au-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.au:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.au","role":"sp","level":"MAY","summary":"When ResponseLocation is omitted, responses are handled at Location","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-au-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.av:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.av","role":"idp","level":"MUST","summary":"Indexed endpoints must use unique indexes and the defined default-selection order within each same-name set","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-av-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.av:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.av","role":"sp","level":"MUST","summary":"Indexed endpoints must use unique indexes and the defined default-selection order within each same-name set","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-av-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.aw:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.aw","role":"idp","level":"MUST","summary":"Explicit KeyDescriptor use values must be interpreted as signing/TLS or encryption-key wrapping","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-aw-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.aw:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.aw","role":"sp","level":"MUST","summary":"Explicit KeyDescriptor use values must be interpreted as signing/TLS or encryption-key wrapping","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Meta","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-aw-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.b:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.b","role":"idp","level":"MUST","summary":"Support SAML Metadata as defined by the SAML V2.0 Metadata Schema","condition":null,"testability":"CONFIG","sourceIds":["SAML2MD-xsd","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-b-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.b:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.b","role":"sp","level":"MUST","summary":"Support SAML Metadata as defined by the SAML V2.0 Metadata Schema","condition":null,"testability":"CONFIG","sourceIds":["SAML2MD-xsd","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-b-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.c:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c","role":"idp","level":"MUST","summary":"Support metadata as defined by the SAML V2.0 Metadata Interoperability Profile","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-c-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.c:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c","role":"sp","level":"MUST","summary":"Support metadata as defined by the SAML V2.0 Metadata Interoperability Profile","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-c-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.c1:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c1","role":"idp","level":"MUST","summary":"Produced MDIOP metadata must stand alone as the description of secure communication requirements","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-c1-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.c1:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c1","role":"sp","level":"MUST","summary":"Produced MDIOP metadata must stand alone as the description of secure communication requirements","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-c1-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.c2:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c2","role":"idp","level":"MUST","summary":"Every role descriptor in a conforming metadata instance must meet MDIOP requirements","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-c2-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.c2:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c2","role":"sp","level":"MUST","summary":"Every role descriptor in a conforming metadata instance must meet MDIOP requirements","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-c2-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.c3:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c3","role":"idp","level":"MUST","summary":"All keys currently valid for a role must appear within that role metadata","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-c3-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.c3:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c3","role":"sp","level":"MUST","summary":"All keys currently valid for a role must appear within that role metadata","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-c3-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.c4:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c4","role":"idp","level":"MAY","summary":"Future signing or transport-authentication keys may be included for rollover","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-c4-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.c4:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c4","role":"sp","level":"MAY","summary":"Future signing or transport-authentication keys may be included for rollover","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-c4-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.c5:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c5","role":"idp","level":"SHOULD","summary":"Expired rollover keys should be removed after migration completes","condition":null,"testability":"ATTESTED","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-c5-idp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.c5:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c5","role":"sp","level":"SHOULD","summary":"Expired rollover keys should be removed after migration completes","condition":null,"testability":"ATTESTED","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-c5-sp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.c6:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c6","role":"idp","level":"MUST","summary":"Compromised keys must be removed from metadata","condition":null,"testability":"ATTESTED","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-c6-idp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.c6:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c6","role":"sp","level":"MUST","summary":"Compromised keys must be removed from metadata","condition":null,"testability":"ATTESTED","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-c6-sp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.c7:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c7","role":"idp","level":"MUST_NOT","summary":"A metadata producer must not rely on consumers to validate key status through PKIX or revocation services","condition":null,"testability":"ATTESTED","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-c7-idp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.c7:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c7","role":"sp","level":"MUST_NOT","summary":"A metadata producer must not rely on consumers to validate key status through PKIX or revocation services","condition":null,"testability":"ATTESTED","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-c7-sp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.c8:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c8","role":"idp","level":"MUST","summary":"Each metadata role key must be in its own KeyDescriptor with the appropriate use","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-c8-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.c8:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c8","role":"sp","level":"MUST","summary":"Each metadata role key must be in its own KeyDescriptor with the appropriate use","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-c8-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.c9:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c9","role":"idp","level":"MUST","summary":"KeyInfo must contain KeyValue or one X509Certificate representation","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-c9-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.c9:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.c9","role":"sp","level":"MUST","summary":"KeyInfo must contain KeyValue or one X509Certificate representation","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-c9-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ca:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ca","role":"idp","level":"MUST","summary":"An X509Data key representation must contain only one certificate","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ca-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ca:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ca","role":"sp","level":"MUST","summary":"An X509Data key representation must contain only one certificate","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ca-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.cb:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.cb","role":"idp","level":"MUST","summary":"When KeyValue and X509Certificate are both present they must represent the same key","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-cb-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.cb:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.cb","role":"sp","level":"MUST","summary":"When KeyValue and X509Certificate are both present they must represent the same key","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-cb-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.cc:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.cc","role":"idp","level":"MAY","summary":"Additional KeyInfo representations may appear as hints","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-cc-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.cc:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.cc","role":"sp","level":"MAY","summary":"Additional KeyInfo representations may appear as hints","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-cc-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.cd:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.cd","role":"idp","level":"MUST_NOT","summary":"Additional KeyInfo hints must not be required to identify a key","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-cd-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.cd:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.cd","role":"sp","level":"MUST_NOT","summary":"Additional KeyInfo hints must not be required to identify a key","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-cd-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ce:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ce","role":"idp","level":"RECOMMENDED","summary":"Certificates used as key containers should be unexpired","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ce-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ce:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ce","role":"sp","level":"RECOMMENDED","summary":"Certificates used as key containers should be unexpired","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ce-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.d:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d","role":"idp","level":"MUST","summary":"Support the Metadata Extension for Entity Attributes","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-d-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.d:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d","role":"sp","level":"MUST","summary":"Support the Metadata Extension for Entity Attributes","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-d-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.d1:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d1","role":"idp","level":"MUST","summary":"EntityAttributes assertions must be processed using the standard SAML assertion rules","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-d1-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.d1:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d1","role":"sp","level":"MUST","summary":"EntityAttributes assertions must be processed using the standard SAML assertion rules","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-d1-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.d2:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d2","role":"idp","level":"MUST_NOT","summary":"EntityAttributes under EntitiesDescriptor must not contain assertions","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-d2-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.d2:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d2","role":"sp","level":"MUST_NOT","summary":"EntityAttributes under EntitiesDescriptor must not contain assertions","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-d2-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.d3:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d3","role":"idp","level":"MUST_NOT","summary":"EntityAttributes must not appear more than once in one Extensions element","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-d3-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.d3:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d3","role":"sp","level":"MUST_NOT","summary":"EntityAttributes must not appear more than once in one Extensions element","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-d3-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.d4:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d4","role":"idp","level":"MUST","summary":"An EntityAttributes assertion subject must be an entity NameID whose value identifies the enclosing entity","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","SAML2Core","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-d4-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.d4:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d4","role":"sp","level":"MUST","summary":"An EntityAttributes assertion subject must be an entity NameID whose value identifies the enclosing entity","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","SAML2Core","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-d4-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.d5:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d5","role":"idp","level":"MUST_NOT","summary":"An EntityAttributes assertion subject must not contain SubjectConfirmation","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-d5-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.d5:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d5","role":"sp","level":"MUST_NOT","summary":"An EntityAttributes assertion subject must not contain SubjectConfirmation","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-d5-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.d6:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d6","role":"idp","level":"MUST","summary":"An EntityAttributes assertion must contain exactly one AttributeStatement","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-d6-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.d6:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d6","role":"sp","level":"MUST","summary":"An EntityAttributes assertion must contain exactly one AttributeStatement","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-d6-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.d7:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d7","role":"idp","level":"MUST_NOT","summary":"An EntityAttributes assertion must not contain other statement types","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-d7-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.d7:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d7","role":"sp","level":"MUST_NOT","summary":"An EntityAttributes assertion must not contain other statement types","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-d7-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.d8:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d8","role":"idp","level":"MUST","summary":"An EntityAttributes assertion must be independently signed","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-d8-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.d8:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d8","role":"sp","level":"MUST","summary":"An EntityAttributes assertion must be independently signed","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-d8-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.d9:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d9","role":"idp","level":"MAY","summary":"Other legal assertion content may appear in an EntityAttributes assertion","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-d9-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.d9:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.d9","role":"sp","level":"MAY","summary":"Other legal assertion content may appear in an EntityAttributes assertion","condition":null,"testability":"CONFIG","sourceIds":["MetaAttr","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-d9-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.e:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e","role":"idp","level":"MUST","summary":"Support the Metadata Extension for Algorithm Support","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-e-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.e:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e","role":"sp","level":"MUST","summary":"Support the Metadata Extension for Algorithm Support","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-e-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.e1:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e1","role":"idp","level":"SHOULD","summary":"An asymmetric encryption KeyDescriptor should list both data-encryption and key-transport or key-agreement algorithms","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-e1-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.e1:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e1","role":"sp","level":"SHOULD","summary":"An asymmetric encryption KeyDescriptor should list both data-encryption and key-transport or key-agreement algorithms","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-e1-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.e2:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e2","role":"idp","level":"MUST","summary":"Listed key-transport or key-agreement algorithms must be compatible with the associated encryption key","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-e2-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.e2:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e2","role":"sp","level":"MUST","summary":"Listed key-transport or key-agreement algorithms must be compatible with the associated encryption key","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-e2-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.e3:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e3","role":"idp","level":"SHOULD","summary":"A symmetric-key KeyDescriptor should list a block or stream encryption algorithm","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-e3-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.e3:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e3","role":"sp","level":"SHOULD","summary":"A symmetric-key KeyDescriptor should list a block or stream encryption algorithm","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-e3-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.e4:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e4","role":"idp","level":"MUST","summary":"Every EncryptionMethod must contain an Algorithm URI","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-e4-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.e4:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e4","role":"sp","level":"MUST","summary":"Every EncryptionMethod must contain an Algorithm URI","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-e4-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.e5:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e5","role":"idp","level":"MUST","summary":"Multiple EncryptionMethod elements of the same general type must be in preference order","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-e5-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.e5:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e5","role":"sp","level":"MUST","summary":"Multiple EncryptionMethod elements of the same general type must be in preference order","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-e5-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.e6:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e6","role":"idp","level":"SHOULD","summary":"An entity should publish DigestMethod and SigningMethod capabilities","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-e6-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.e6:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e6","role":"sp","level":"SHOULD","summary":"An entity should publish DigestMethod and SigningMethod capabilities","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-e6-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.e7:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e7","role":"idp","level":"MUST","summary":"Multiple DigestMethod or SigningMethod elements must be in preference order","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-e7-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.e7:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e7","role":"sp","level":"MUST","summary":"Multiple DigestMethod or SigningMethod elements must be in preference order","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-e7-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.e8:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e8","role":"idp","level":"MUST","summary":"A consumer using peer-aware XML Signature or Encryption must consult metadata for the supported intersection","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-e8-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.e8:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e8","role":"sp","level":"MUST","summary":"A consumer using peer-aware XML Signature or Encryption must consult metadata for the supported intersection","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-e8-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.e9:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e9","role":"idp","level":"SHOULD","summary":"A metadata consumer should consult algorithm elements in order","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-e9-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.e9:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.e9","role":"sp","level":"SHOULD","summary":"A metadata consumer should consult algorithm elements in order","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-e9-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ea:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ea","role":"idp","level":"SHOULD","summary":"A metadata consumer should select the first supported algorithm","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ea-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ea:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ea","role":"sp","level":"SHOULD","summary":"A metadata consumer should select the first supported algorithm","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ea-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.eb:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.eb","role":"idp","level":"MUST","summary":"Role-level signature algorithm metadata must take precedence over entity-level metadata without combining the sets","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-eb-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.eb:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.eb","role":"sp","level":"MUST","summary":"Role-level signature algorithm metadata must take precedence over entity-level metadata without combining the sets","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-eb-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ec:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ec","role":"idp","level":"MUST","summary":"DigestMethod and SigningMethod elements must contain an Algorithm URI","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ec-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ec:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ec","role":"sp","level":"MUST","summary":"DigestMethod and SigningMethod elements must contain an Algorithm URI","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ec-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ed:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ed","role":"idp","level":"MAY","summary":"A symmetric-key KeyDescriptor may list EncryptionMethod elements for other algorithm types","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ed-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ed:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ed","role":"sp","level":"MAY","summary":"A symmetric-key KeyDescriptor may list EncryptionMethod elements for other algorithm types","condition":null,"testability":"CONFIG","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ed-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.f:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f","role":"idp","level":"MUST","summary":"Support the Metadata Extensions for Login and Discovery User Interface","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-f-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.f:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f","role":"sp","level":"MUST","summary":"Support the Metadata Extensions for Login and Discovery User Interface","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-f-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.f1:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f1","role":"idp","level":"MUST","summary":"UIInfo must occur within the Extensions element of a role descriptor","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-f1-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.f1:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f1","role":"sp","level":"MUST","summary":"UIInfo must occur within the Extensions element of a role descriptor","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-f1-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.f2:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f2","role":"idp","level":"MUST","summary":"UIInfo must contain at least one child element","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-f2-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.f2:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f2","role":"sp","level":"MUST","summary":"UIInfo must contain at least one child element","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-f2-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.f3:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f3","role":"idp","level":"MUST_NOT","summary":"UIInfo must not appear more than once in one Extensions element","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-f3-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.f3:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f3","role":"sp","level":"MUST_NOT","summary":"UIInfo must not appear more than once in one Extensions element","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-f3-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.f4:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f4","role":"idp","level":"MUST_NOT","summary":"Localized UIInfo child elements must not repeat the same xml:lang for the same element type in one role","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-f4-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.f4:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f4","role":"sp","level":"MUST_NOT","summary":"Localized UIInfo child elements must not repeat the same xml:lang for the same element type in one role","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-f4-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.f5:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f5","role":"idp","level":"MUST","summary":"A UI description must be standalone and not require templated additional text","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-f5-idp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.f5:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f5","role":"sp","level":"MUST","summary":"A UI description must be standalone and not require templated additional text","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-f5-sp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.f6:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f6","role":"sp","level":"SHOULD","summary":"An SP role description should describe the offered service","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-f6-sp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.f7:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f7","role":"idp","level":"SHOULD","summary":"An IdP role description should describe the serviced user community","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-f7-idp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.f8:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f8","role":"idp","level":"SHOULD","summary":"Published logos should follow the profile's usability guidance","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-f8-idp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.f8:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f8","role":"sp","level":"SHOULD","summary":"Published logos should follow the profile's usability guidance","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-f8-sp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.f9:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f9","role":"idp","level":"SHOULD","summary":"A logo without xml:lang should be treated as the default when the preferred language is unavailable","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-f9-idp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.f9:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.f9","role":"sp","level":"SHOULD","summary":"A logo without xml:lang should be treated as the default when the preferred language is unavailable","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-f9-sp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.fa:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fa","role":"idp","level":"SHOULD","summary":"InformationURL content should provide more information than Description","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-fa-idp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.fa:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fa","role":"sp","level":"SHOULD","summary":"InformationURL content should provide more information than Description","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-fa-sp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.fb:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fb","role":"idp","level":"SHOULD_NOT","summary":"Discovery hints should not definitively select an identity provider without user confirmation","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-fb-idp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.fb:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fb","role":"sp","level":"SHOULD_NOT","summary":"Discovery hints should not definitively select an identity provider without user confirmation","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-fb-sp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.fc:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fc","role":"idp","level":"MUST","summary":"DiscoHints must occur within IDPSSODescriptor Extensions","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-fc-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.fc:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fc","role":"sp","level":"MUST","summary":"DiscoHints must occur within IDPSSODescriptor Extensions","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-fc-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.fd:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fd","role":"idp","level":"MUST","summary":"DiscoHints must contain at least one child element","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-fd-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.fd:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fd","role":"sp","level":"MUST","summary":"DiscoHints must contain at least one child element","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-fd-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.fe:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fe","role":"idp","level":"MUST_NOT","summary":"DiscoHints must not appear more than once in one Extensions element","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-fe-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.fe:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fe","role":"sp","level":"MUST_NOT","summary":"DiscoHints must not appear more than once in one Extensions element","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-fe-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.ff:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ff","role":"idp","level":"MUST","summary":"Both IPv4 and IPv6 CIDR blocks must be supported in IPHint","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-ff-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.ff:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.ff","role":"sp","level":"MUST","summary":"Both IPv4 and IPv6 CIDR blocks must be supported in IPHint","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-ff-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.fg:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fg","role":"idp","level":"MUST","summary":"URLs used from metadata UI extensions must be sanitized and encoded against XSS","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-fg-idp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.fg:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fg","role":"sp","level":"MUST","summary":"URLs used from metadata UI extensions must be sanitized and encoded against XSS","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-fg-sp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.fh:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fh","role":"idp","level":"SHOULD_NOT","summary":"Metadata UI URLs should not use schemes other than https, http, or data","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-fh-idp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.fh:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fh","role":"sp","level":"SHOULD_NOT","summary":"Metadata UI URLs should not use schemes other than https, http, or data","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-fh-sp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.fi:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fi","role":"idp","level":"RECOMMENDED","summary":"Metadata UI URLs should use HTTPS","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-fi-idp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.fi:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fi","role":"sp","level":"RECOMMENDED","summary":"Metadata UI URLs should use HTTPS","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-fi-sp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.fj:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fj","role":"idp","level":"SHOULD","summary":"Display-name consumers should prefer UIInfo DisplayName, then ServiceName, then entityID or endpoint hostname","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-fj-idp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.fj:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fj","role":"sp","level":"SHOULD","summary":"Display-name consumers should prefer UIInfo DisplayName, then ServiceName, then entityID or endpoint hostname","condition":null,"testability":"BROWSER","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-fj-sp-01","mode":"BROWSER","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.fk:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fk","role":"idp","level":"MUST","summary":"Every Logo element must contain height and width attributes","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-fk-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.fk:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.fk","role":"sp","level":"MUST","summary":"Every Logo element must contain height and width attributes","condition":null,"testability":"CONFIG","sourceIds":["MetaUi","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-fk-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD05.g:idp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.g","role":"idp","level":"MUST_NOT","summary":"Other metadata extension content must not prevent consumption and use of the metadata","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD05-g-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD05.g:sp","requirement":"IIP-MD05","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD05","obligation":"IIP-MD05.g","role":"sp","level":"MUST_NOT","summary":"Other metadata extension content must not prevent consumption and use of the metadata","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD05-g-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.a:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a","role":"idp","level":"MUST","summary":"Support interpretation and application of metadata as defined by the Metadata Interoperability Profile","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-a-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.a:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a","role":"sp","level":"MUST","summary":"Support interpretation and application of metadata as defined by the Metadata Interoperability Profile","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-a-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.a1:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a1","role":"idp","level":"MUST","summary":"A consumer must process both EntityDescriptor and EntitiesDescriptor roots and every nested entity","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-a1-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.a1:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a1","role":"sp","level":"MUST","summary":"A consumer must process both EntityDescriptor and EntitiesDescriptor roots and every nested entity","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-a1-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.a2:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a2","role":"idp","level":"MUST","summary":"Each KeyDescriptor key must be treated as valid in the context of its containing role","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-a2-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.a2:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a2","role":"sp","level":"MUST","summary":"Each KeyDescriptor key must be treated as valid in the context of its containing role","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-a2-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.a3:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a3","role":"idp","level":"MUST","summary":"Signatures and transport sessions verifiable with a role signing key must be treated as valid","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-a3-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.a3:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a3","role":"sp","level":"MUST","summary":"Signatures and transport sessions verifiable with a role signing key must be treated as valid","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-a3-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.a4:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a4","role":"idp","level":"MAY","summary":"Encryption keys found in metadata may be used for the containing entity","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-a4-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.a4:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a4","role":"sp","level":"MAY","summary":"Encryption keys found in metadata may be used for the containing entity","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-a4-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.a5:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a5","role":"idp","level":"MUST_NOT","summary":"After accepting metadata, a consumer must not add key-acceptance or runtime-validity criteria","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-a5-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.a5:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a5","role":"sp","level":"MUST_NOT","summary":"After accepting metadata, a consumer must not add key-acceptance or runtime-validity criteria","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-a5-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.a6:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a6","role":"idp","level":"MUST_NOT","summary":"A consumer must not perform PKIX path validation, revocation-list, OCSP, or similar checks on accepted metadata keys","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-a6-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.a6:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a6","role":"sp","level":"MUST_NOT","summary":"A consumer must not perform PKIX path validation, revocation-list, OCSP, or similar checks on accepted metadata keys","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-a6-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.a7:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a7","role":"idp","level":"MUST","summary":"A consumer must support KeyValue and X509Certificate KeyInfo representations","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-a7-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.a7:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a7","role":"sp","level":"MUST","summary":"A consumer must support KeyValue and X509Certificate KeyInfo representations","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-a7-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.a8:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a8","role":"idp","level":"MUST","summary":"A consumer must extract the public key from an X509Certificate representation","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-a8-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.a8:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a8","role":"sp","level":"MUST","summary":"A consumer must extract the public key from an X509Certificate representation","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-a8-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.a9:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a9","role":"idp","level":"MUST_NOT","summary":"A consumer must not honor certificate information other than the public key except to identify the key","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-a9-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.a9:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.a9","role":"sp","level":"MUST_NOT","summary":"A consumer must not honor certificate information other than the public key except to identify the key","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-a9-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.aa:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.aa","role":"idp","level":"MAY","summary":"A consumer authenticating a TLS server may retain server-name checking","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-aa-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.aa:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.aa","role":"sp","level":"MAY","summary":"A consumer authenticating a TLS server may retain server-name checking","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-aa-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.ab:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.ab","role":"idp","level":"MUST","summary":"Accepted metadata must be treated as true for operational behavior until superseded","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-ab-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.ab:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.ab","role":"sp","level":"MUST","summary":"Accepted metadata must be treated as true for operational behavior until superseded","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-ab-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.b:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.b","role":"idp","level":"MUST","summary":"Be capable of interoperating with any number of SAML peers for which metadata is available, without additional inputs or separate configuration","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-b-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.b:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.b","role":"sp","level":"MUST","summary":"Be capable of interoperating with any number of SAML peers for which metadata is available, without additional inputs or separate configuration","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-b-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD06.c:idp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.c","role":"idp","level":"MUST","summary":"Metadata must be usable as a self-contained vehicle for communicating trust, with all rules for processing signatures and encrypted XML derivable from the metadata alone","condition":null,"testability":"ATTESTED","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD06-c-idp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD06.c:sp","requirement":"IIP-MD06","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD06","obligation":"IIP-MD06.c","role":"sp","level":"MUST","summary":"Metadata must be usable as a self-contained vehicle for communicating trust, with all rules for processing signatures and encrypted XML derivable from the metadata alone","condition":null,"testability":"ATTESTED","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD06-c-sp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD07.a:idp","requirement":"IIP-MD07","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD07","obligation":"IIP-MD07.a","role":"idp","level":"MUST","summary":"Consume and make use of any number of signing keys bound to a single role descriptor","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD07-a-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD07.a:sp","requirement":"IIP-MD07","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD07","obligation":"IIP-MD07.a","role":"sp","level":"MUST","summary":"Consume and make use of any number of signing keys bound to a single role descriptor","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD07-a-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD07.b:idp","requirement":"IIP-MD07","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD07","obligation":"IIP-MD07.b","role":"idp","level":"MUST","summary":"Attempt each signing key until the signature verifies or keys are exhausted, in which case verification fails","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD07-b-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD07.b:sp","requirement":"IIP-MD07","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD07","obligation":"IIP-MD07.b","role":"sp","level":"MUST","summary":"Attempt each signing key until the signature verifies or keys are exhausted, in which case verification fails","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD07-b-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD08.a:idp","requirement":"IIP-MD08","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD08","obligation":"IIP-MD08.a","role":"idp","level":"MUST","summary":"If supporting outbound encryption, consume any number of encryption keys bound to a single role descriptor","condition":{"predicate":"supports_outbound_encryption","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD08-a-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD08.a:sp","requirement":"IIP-MD08","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD08","obligation":"IIP-MD08.a","role":"sp","level":"MUST","summary":"If supporting outbound encryption, consume any number of encryption keys bound to a single role descriptor","condition":{"predicate":"supports_outbound_encryption","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD08-a-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD09.a:idp","requirement":"IIP-MD09","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD09","obligation":"IIP-MD09.a","role":"idp","level":"MUST","summary":"Be capable of publishing the cryptographic capabilities of the runtime configuration for XML Signature and Encryption","condition":null,"testability":"ATTESTED","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD09-a-idp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD09.a:sp","requirement":"IIP-MD09","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD09","obligation":"IIP-MD09.a","role":"sp","level":"MUST","summary":"Be capable of publishing the cryptographic capabilities of the runtime configuration for XML Signature and Encryption","condition":null,"testability":"ATTESTED","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD09-a-sp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD09.b:idp","requirement":"IIP-MD09","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD09","obligation":"IIP-MD09.b","role":"idp","level":"RECOMMENDED","summary":"Recommended: support dynamic generation and export in a machine-readable format per SAML2MetaAlgSup","condition":null,"testability":"ATTESTED","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD09-b-idp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD09.b:sp","requirement":"IIP-MD09","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD09","obligation":"IIP-MD09.b","role":"sp","level":"RECOMMENDED","summary":"Recommended: support dynamic generation and export in a machine-readable format per SAML2MetaAlgSup","condition":null,"testability":"ATTESTED","sourceIds":["SAML2MetaAlgSup","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD09-b-sp-01","mode":"ATTESTED","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD10.a:idp","requirement":"IIP-MD10","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD10","obligation":"IIP-MD10.a","role":"idp","level":"MUST","summary":"(IdP) Limit XML Signature and Encryption algorithms to those declared in the peer's metadata","condition":{"predicate":"peer_declares_algorithm_support","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD10-a-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD10.b:sp","requirement":"IIP-MD10","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD10","obligation":"IIP-MD10.b","role":"sp","level":"SHOULD","summary":"(SP) Should limit XML Signature and Encryption algorithms to those declared in the peer's metadata","condition":{"predicate":"peer_declares_algorithm_support","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD10-b-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD11.a:idp","requirement":"IIP-MD11","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD11","obligation":"IIP-MD11.a","role":"idp","level":"MUST","summary":"A md:KeyDescriptor with no use attribute must be valid for XML signing, TLS/SSL, and encryption-key wrapping","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD11-a-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD11.a:sp","requirement":"IIP-MD11","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD11","obligation":"IIP-MD11.a","role":"sp","level":"MUST","summary":"A md:KeyDescriptor with no use attribute must be valid for XML signing, TLS/SSL, and encryption-key wrapping","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD11-a-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD12.a:idp","requirement":"IIP-MD12","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD12","obligation":"IIP-MD12.a","role":"idp","level":"REQUIRED","summary":"Support any number of long-lived, self-signed end entity certificates","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD12-a-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD12.a:sp","requirement":"IIP-MD12","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD12","obligation":"IIP-MD12.a","role":"sp","level":"REQUIRED","summary":"Support any number of long-lived, self-signed end entity certificates","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD12-a-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD12.b:idp","requirement":"IIP-MD12","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD12","obligation":"IIP-MD12.b","role":"idp","level":"REQUIRED","summary":"Support expired certificates","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD12-b-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD12.b:sp","requirement":"IIP-MD12","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD12","obligation":"IIP-MD12.b","role":"sp","level":"REQUIRED","summary":"Support expired certificates","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD12-b-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD12.c:idp","requirement":"IIP-MD12","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD12","obligation":"IIP-MD12.c","role":"idp","level":"REQUIRED","summary":"Support certificates signed with any digest algorithm","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD12-c-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD12.c:sp","requirement":"IIP-MD12","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD12","obligation":"IIP-MD12.c","role":"sp","level":"REQUIRED","summary":"Support certificates signed with any digest algorithm","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD12-c-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-MD12.d:idp","requirement":"IIP-MD12","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD12","obligation":"IIP-MD12.d","role":"idp","level":"MUST_NOT","summary":"A certificate may be expired, not yet valid, carry critical or non-critical extensions or usage flags, and contain any subject or issuer — none of these may prevent use of the contained key","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_idp"],"cases":[{"id":"IIP-MD12-d-idp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_idp"]}]},{"id":"IIP-MD12.d:sp","requirement":"IIP-MD12","section":"2.2","sectionName":"Common / Metadata and Trust Management","anchor":"#IIP-MD12","obligation":"IIP-MD12.d","role":"sp","level":"MUST_NOT","summary":"A certificate may be expired, not yet valid, carry critical or non-critical extensions or usage flags, and contain any subject or issuer — none of these may prevent use of the contained key","condition":null,"testability":"CONFIG","sourceIds":["SAML2MDIOP","kantara-fedinterop-impl"],"profiles":["metadata_sp"],"cases":[{"id":"IIP-MD12-d-sp-01","mode":"CONFIG","milestone":"M2","profiles":["metadata_sp"]}]},{"id":"IIP-SSO01.a:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.a","role":"idp","level":"MUST","summary":"Support the SAML V2.0 Web Browser SSO Profile end to end","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.a:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.a","role":"sp","level":"MUST","summary":"Support the SAML V2.0 Web Browser SSO Profile end to end","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.b:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.b","role":"sp","level":"MUST","summary":"The AuthnRequest Issuer must be present and contain the unique identifier of the requesting service provider","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-b-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.c:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.c","role":"sp","level":"MUST_NOT","summary":"A Subject element included in an AuthnRequest must not contain any SubjectConfirmation elements","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-c-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.d:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.d","role":"idp","level":"MUST","summary":"If the identity provider does not recognize the principal named in the request Subject, it must respond with an error status and no assertions","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-d-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.e:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.e","role":"idp","level":"MUST_NOT","summary":"Information in an AuthnRequest that is not authenticated and integrity protected must not be trusted except as advisory","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-e-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.f:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.f","role":"idp","level":"MUST_NOT","summary":"If the identity provider wishes to return an error, it must not include any assertions in the Response","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-f-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.g:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.g","role":"idp","level":"MUST","summary":"A successful Response must contain at least one Assertion","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-g-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.h:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.h","role":"idp","level":"MUST","summary":"If the Response Issuer is present it must contain the unique identifier of the issuing identity provider with Format omitted or entity","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-h-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.h1:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.h1","role":"idp","level":"MUST","summary":"If the Response is signed or an enclosed assertion is encrypted, the Issuer element must be present","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-h1-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.i:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.i","role":"idp","level":"MUST","summary":"Each assertion's Issuer must contain the unique identifier of the responding identity provider with Format omitted or entity","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-i-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.i1:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.i1","role":"idp","level":"MUST","summary":"All assertions in a response must be issued by the same entity","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-i1-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.i2:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.i2","role":"idp","level":"MUST","summary":"If multiple assertions are included, each assertion's Subject must refer to the same principal","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-i2-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.j:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.j","role":"idp","level":"MUST","summary":"Any assertion issued for consumption using this profile must contain a Subject with at least one bearer SubjectConfirmation","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-j-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.k:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.k","role":"idp","level":"MUST","summary":"At least one bearer SubjectConfirmation must contain a SubjectConfirmationData with a Recipient attribute containing the service provider's assertion consumer service URL and a NotOnOrAfter attribute","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-k-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.k1:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.k1","role":"idp","level":"MUST_NOT","summary":"The bearer SubjectConfirmationData must not contain a NotBefore attribute","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-k1-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.k2:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.k2","role":"idp","level":"MUST","summary":"If the containing message is in response to an AuthnRequest, the InResponseTo attribute must match the request's ID","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-k2-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.l:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.l","role":"idp","level":"MUST","summary":"The set of one or more bearer assertions must contain at least one AuthnStatement that reflects the authentication of the principal","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-l-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.l1:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.l1","role":"idp","level":"MUST","summary":"If the identity provider supports the Single Logout profile, any authentication statements must include a SessionIndex attribute","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-l1-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.m:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.m","role":"idp","level":"MUST","summary":"Each bearer assertion must contain an AudienceRestriction including the service provider's unique identifier as an Audience","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-m-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.n:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.n","role":"sp","level":"MUST","summary":"The service provider must verify any signatures present on the assertion(s) or the response","condition":null,"testability":"BROWSER","sourceIds":["SAML2Bind","SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-n-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.o:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.o","role":"sp","level":"MUST","summary":"The service provider must verify that the Recipient attribute in the bearer SubjectConfirmationData matches the assertion consumer service URL to which the Response was delivered","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-o-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.p:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.p","role":"sp","level":"MUST","summary":"The service provider must verify that the NotOnOrAfter attribute in the bearer SubjectConfirmationData has not passed, subject to allowable clock skew","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-p-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.q:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.q","role":"sp","level":"MUST","summary":"The service provider must verify that the InResponseTo attribute in the bearer SubjectConfirmationData equals the ID of its original AuthnRequest","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-q-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.r:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.r","role":"sp","level":"MUST","summary":"The service provider must verify that any assertions relied upon are valid in other respects","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-r-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.r1:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.r1","role":"sp","level":"MUST","summary":"If more than one assertion is present, each assertion must be evaluated independently","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-r1-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.s:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.s","role":"sp","level":"SHOULD","summary":"Any assertion which is not valid, or whose subject confirmation requirements cannot be met, should be discarded","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-s-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.s1:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.s1","role":"sp","level":"SHOULD_NOT","summary":"Such an assertion should not be used to establish a security context for the principal","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-s1-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.t:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.t","role":"sp","level":"SHOULD","summary":"If an AuthnStatement used to establish a security context contains a SessionNotOnOrAfter attribute, the security context should be discarded once this time is reached","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-t-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.u:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.u","role":"idp","level":"MUST","summary":"If the HTTP Artifact binding is used, dereferencing of the artifact must be mutually authenticated, integrity protected, and confidential","condition":{"predicate":"supports_artifact_binding","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-u-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.u:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.u","role":"sp","level":"MUST","summary":"If the HTTP Artifact binding is used, dereferencing of the artifact must be mutually authenticated, integrity protected, and confidential","condition":{"predicate":"supports_artifact_binding","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-u-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.u1:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.u1","role":"idp","level":"MUST","summary":"The identity provider must ensure that only the service provider to whom the Response was issued is given the message as the result of an ArtifactResolve request","condition":{"predicate":"supports_artifact_binding","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-u1-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.v:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.v","role":"idp","level":"MUST","summary":"If the HTTP POST binding is used to deliver the Response, each assertion must be protected by a digital signature","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-v-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.w:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.w","role":"sp","level":"MUST","summary":"The service provider must ensure that bearer assertions are not replayed, by maintaining the set of used ID values for the length of time for which the assertion would be considered valid","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-w-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.x:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.x","role":"idp","level":"MUST_NOT","summary":"The HTTP Redirect binding must not be used to deliver the Response","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-x-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.y:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.y","role":"idp","level":"MUST_NOT","summary":"An unsolicited Response must not contain an InResponseTo attribute","condition":{"predicate":"supports_unsolicited_responses","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-y-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.y1:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.y1","role":"idp","level":"SHOULD","summary":"If metadata is used, the unsolicited Response should be delivered to the assertion consumer service endpoint designated as the default","condition":{"predicate":"unsolicited_acs_from_metadata","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-y1-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.z:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.z","role":"idp","level":"MAY","summary":"An identity provider may initiate this profile by delivering an unsolicited Response message to a service provider","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-z-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.aa:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.aa","role":"sp","level":"SHOULD","summary":"Service providers should have a means of disabling the acceptance of unsolicited responses if circumstances warrant","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-aa-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ab:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ab","role":"idp","level":"SHOULD","summary":"The URL scheme eventually derived from RelayState should be limited to https or http","condition":{"predicate":"derives_url_from_relaystate","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Bind","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ab-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ab:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ab","role":"sp","level":"SHOULD","summary":"The URL scheme eventually derived from RelayState should be limited to https or http","condition":{"predicate":"derives_url_from_relaystate","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Bind","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ab-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ac:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ac","role":"sp","level":"SHOULD","summary":"The service provider should reveal as little of the request as possible in the RelayState value","condition":{"predicate":"relaystate_privacy_required","predicate_kind":"CLASSIFICATION_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ac-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ad:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ad","role":"idp","level":"RECOMMENDED","summary":"It is recommended that the HTTP exchanges in the request and response steps be made over TLS to maintain confidentiality and message integrity","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ad-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ad:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ad","role":"sp","level":"RECOMMENDED","summary":"It is recommended that the HTTP exchanges in the request and response steps be made over TLS to maintain confidentiality and message integrity","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ad-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ae:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ae","role":"idp","level":"MUST","summary":"The identity provider must establish the identity of the principal, unless it returns an error to the service provider","condition":null,"testability":"CONFIG","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ae-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.af:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.af","role":"sp","level":"MUST","summary":"The AuthnRequest ID must follow the SAML identifier uniqueness requirements","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-af-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ag:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ag","role":"idp","level":"MUST","summary":"If the AuthnRequest Destination is present, the recipient must check that it identifies the location at which the message was received, and discard the request if it does not","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ag-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ah:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ah","role":"idp","level":"MUST","summary":"SAML extension elements must be namespace-qualified in a non-SAML-defined namespace","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ah-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ah:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ah","role":"sp","level":"MUST","summary":"SAML extension elements must be namespace-qualified in a non-SAML-defined namespace","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ah-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ai:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ai","role":"idp","level":"MUST","summary":"If the AuthnRequest carries an XML signature, the responder must verify that the signature is valid","condition":null,"testability":"BROWSER","sourceIds":["SAML2Bind","SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ai-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.aj:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.aj","role":"idp","level":"MUST_NOT","summary":"If the signature on the request is invalid, the responder must not rely on the contents of the request","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-aj-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ak:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ak","role":"idp","level":"SHOULD","summary":"If the signature on the request is invalid, the responder should respond with an error","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ak-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.al:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.al","role":"idp","level":"SHOULD","summary":"If the signature is valid, the responder should evaluate the signature to determine the identity and appropriateness of the signer","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Bind","SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-al-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.am:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.am","role":"sp","level":"SHOULD","summary":"If a Consent attribute indicating that principal consent has been obtained is included, the request should be signed","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-am-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.an:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.an","role":"idp","level":"MUST","summary":"If a responder deems a request invalid according to SAML syntax or processing rules, then if it responds it must return a SAML response whose StatusCode value is Requester","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-an-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ao:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ao","role":"idp","level":"MUST","summary":"The identifiers the identity provider assigns — the Response ID and the Assertion ID — must follow the SAML identifier uniqueness requirements","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ao-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ap:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ap","role":"idp","level":"MUST","summary":"If the response is generated in response to a request, the InResponseTo attribute must be present and must match the corresponding request's ID","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ap-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.aq:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.aq","role":"sp","level":"MUST","summary":"If the Response Destination is present, the recipient must check that it identifies the location at which the message was received, and discard the response if it does not","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-aq-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ar:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ar","role":"sp","level":"MUST_NOT","summary":"If the signature on the response is invalid, the requester must not rely on the contents of the response","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ar-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.as:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.as","role":"sp","level":"SHOULD","summary":"If the signature on the response is invalid, the requester should treat it as an error","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-as-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.at:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.at","role":"sp","level":"SHOULD","summary":"If the signature is valid, the requester should evaluate the signature to determine the identity and appropriateness of the signer","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-at-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.au:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.au","role":"idp","level":"SHOULD","summary":"If a Consent attribute indicating that principal consent has been obtained is included, the response should be signed","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-au-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.av:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.av","role":"idp","level":"MUST","summary":"Retrieving the resource associated with a GetComplete URI must result in an XML instance whose root element is an IDPList that does not itself contain a GetComplete element","condition":{"predicate":"emits_idplist_getcomplete","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-av-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.av:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.av","role":"sp","level":"MUST","summary":"Retrieving the resource associated with a GetComplete URI must result in an XML instance whose root element is an IDPList that does not itself contain a GetComplete element","condition":{"predicate":"emits_idplist_getcomplete","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-av-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.aw:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.aw","role":"idp","level":"MUST","summary":"When ProxyCount is zero and the identity provider cannot directly authenticate the presenter, it must return a Response whose top-level StatusCode is Responder","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-aw-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ax:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ax","role":"idp","level":"MAY","summary":"When ProxyCount is zero and direct authentication is not possible, the identity provider may return ProxyCountExceeded as a second-level StatusCode","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ax-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ay:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ay","role":"idp","level":"MUST","summary":"When creating the new AuthnRequest, the proxying identity provider must include equivalent or stricter forms of all the information included in the original request","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ay-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.az:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.az","role":"idp","level":"MUST","summary":"If the authenticating identity provider is not a SAML identity provider, the proxying provider must have some other way to ensure that elements governing user agent interaction will be honored","condition":{"predicate":"proxies_to_non_saml_provider","predicate_kind":"CLASSIFICATION_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-az-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ba:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ba","role":"idp","level":"MUST","summary":"The new AuthnRequest must contain a ProxyCount attribute with a value of at most one less than the original value","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ba-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.bb:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.bb","role":"idp","level":"SHOULD","summary":"If the original request does not contain a ProxyCount attribute, the new request should contain one","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-bb-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.bc:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.bc","role":"idp","level":"MUST","summary":"If an IDPList was specified in the original request, the new request must also contain an IDPList","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-bc-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.bd:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.bd","role":"idp","level":"MUST_NOT","summary":"The proxying identity provider must not remove any identity providers from the IDPList","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-bd-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.be:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.be","role":"idp","level":"MUST","summary":"The new assertion's Subject must contain an identifier that satisfies the original requester's preferences as defined by its NameIDPolicy element","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-be-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.bf:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.bf","role":"idp","level":"MUST","summary":"The AuthnStatement in the new assertion must include an AuthnContext containing an AuthenticatingAuthority element referencing the identity provider to which the presenter was referred","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-bf-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.bg:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.bg","role":"idp","level":"SHOULD","summary":"If the original assertion contains AuthenticatingAuthority elements, those should be included in the new assertion with the new element placed after them","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-bg-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.bh:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.bh","role":"idp","level":"MUST","summary":"If the authenticating identity provider is not a SAML provider, the proxying identity provider must generate a unique identifier value for the authenticating provider","condition":{"predicate":"proxies_to_non_saml_provider","predicate_kind":"CLASSIFICATION_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-bh-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.bi:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.bi","role":"idp","level":"SHOULD","summary":"The generated identifier value should be consistent over time across different requests","condition":{"predicate":"proxies_to_non_saml_provider","predicate_kind":"CLASSIFICATION_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-bi-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.bj:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.bj","role":"idp","level":"MUST_NOT","summary":"The generated identifier value must not conflict with values used or generated by other SAML providers","condition":{"predicate":"proxies_to_non_saml_provider","predicate_kind":"CLASSIFICATION_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-bj-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cc:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cc","role":"idp","level":"MUST","summary":"Where a data object declares that it has a particular identifier, there must be exactly one such declaration","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cc-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cc:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cc","role":"sp","level":"MUST","summary":"Where a data object declares that it has a particular identifier, there must be exactly one such declaration","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-cc-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.cd:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cd","role":"idp","level":"MUST","summary":"If a random or pseudorandom technique is employed, the probability of two randomly chosen identifiers being identical must be less than or equal to 2^-128","condition":{"predicate":"uses_random_identifier_generation","predicate_kind":"CAPABILITY_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cd-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cd:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cd","role":"sp","level":"MUST","summary":"If a random or pseudorandom technique is employed, the probability of two randomly chosen identifiers being identical must be less than or equal to 2^-128","condition":{"predicate":"uses_random_identifier_generation","predicate_kind":"CAPABILITY_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-cd-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ce:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ce","role":"idp","level":"SHOULD","summary":"The probability of two randomly chosen identifiers being identical should be less than or equal to 2^-160","condition":{"predicate":"uses_random_identifier_generation","predicate_kind":"CAPABILITY_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ce-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ce:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ce","role":"sp","level":"SHOULD","summary":"The probability of two randomly chosen identifiers being identical should be less than or equal to 2^-160","condition":{"predicate":"uses_random_identifier_generation","predicate_kind":"CAPABILITY_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ce-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.cf:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cf","role":"idp","level":"MUST","summary":"A pseudorandom generator must be seeded with unique material in order to ensure the desired uniqueness properties between different systems","condition":{"predicate":"uses_random_identifier_generation","predicate_kind":"CAPABILITY_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cf-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cf:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cf","role":"sp","level":"MUST","summary":"A pseudorandom generator must be seeded with unique material in order to ensure the desired uniqueness properties between different systems","condition":{"predicate":"uses_random_identifier_generation","predicate_kind":"CAPABILITY_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-cf-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.cg:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cg","role":"sp","level":"MUST","summary":"The AuthnRequest messages a service provider issues must conform to the SAML V2.0 protocol schema, including the required ID, Version and IssueInstant attributes","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2P-xsd","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-cg-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.dv:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dv","role":"idp","level":"MUST","summary":"The Response messages an identity provider issues must conform to the SAML V2.0 protocol schema, including the required ID, Version and IssueInstant attributes and the required Status element","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2P-xsd","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dv-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dw:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dw","role":"idp","level":"MUST","summary":"The assertions an identity provider issues must conform to the SAML V2.0 assertion schema, including the required Version, ID, IssueInstant and Issuer of an assertion and the required AuthnInstant and AuthnContext of an authentication statement","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2-xsd","SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dw-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dx:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dx","role":"idp","level":"MUST","summary":"The AuthnRequest messages a proxying identity provider issues to an upstream identity provider must conform to the SAML V2.0 protocol schema","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2P-xsd","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dx-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ch:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ch","role":"idp","level":"MUST","summary":"The value of the topmost StatusCode element must be from the top-level list provided in SAML2Core 3.2.2.2","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ch-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ci:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ci","role":"idp","level":"MUST","summary":"An xsi:type attribute must be used to indicate the actual statement type when a generic Statement element is used","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ci-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cj:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cj","role":"idp","level":"MUST","summary":"An assertion with no statements must contain a Subject element","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cj-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ck:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ck","role":"idp","level":"MUST","summary":"An xsi:type attribute must be used to indicate the actual condition type when a generic Condition element is used","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ck-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cl:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cl","role":"idp","level":"MUST","summary":"There must be at most one OneTimeUse element within a Conditions element of an assertion","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cl-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cm:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cm","role":"idp","level":"MUST","summary":"There must be at most one ProxyRestriction element within a Conditions element of an assertion","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cm-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cn:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cn","role":"idp","level":"MUST","summary":"If both NotBefore and NotOnOrAfter are present, the value for NotBefore must be earlier than the value for NotOnOrAfter","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cn-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.co:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.co","role":"sp","level":"MUST","summary":"An assertion that is determined to be Invalid or Indeterminate must be rejected by a relying party","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-co-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.cp:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cp","role":"sp","level":"MUST","summary":"Multiple AudienceRestriction elements in a single assertion must each be evaluated independently","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-cp-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.cq:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cq","role":"sp","level":"SHOULD","summary":"An assertion carrying a OneTimeUse condition should be used immediately by the relying party","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-cq-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.cr:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cr","role":"sp","level":"MUST_NOT","summary":"An assertion carrying a OneTimeUse condition must not be retained for future use","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-cr-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.cs:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cs","role":"sp","level":"MUST","summary":"Implementations that choose to retain assertions for future use must observe the OneTimeUse element","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-cs-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ct:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ct","role":"idp","level":"MUST_NOT","summary":"A relying party acting as an asserting party must not issue an assertion that itself violates the restrictions specified in a ProxyRestriction condition","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ct-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cu:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cu","role":"idp","level":"MUST_NOT","summary":"A ProxyRestriction Count value of zero indicates that a relying party must not issue an assertion to another relying party on the basis of this assertion","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cu-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cv:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cv","role":"idp","level":"MUST","summary":"If the ProxyRestriction Count is greater than zero, any assertions so issued must themselves contain a ProxyRestriction element with a Count value of at most one less","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cv-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cw:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cw","role":"idp","level":"MUST","summary":"Otherwise any assertions so issued must contain an AudienceRestriction with at least one of the Audience elements present in the previous ProxyRestriction element","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cw-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cx:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cx","role":"sp","level":"MUST","summary":"An assertion that is malformed with respect to the SAML assertion schema must be rejected by the relying party","condition":null,"testability":"BROWSER","sourceIds":["SAML2-xsd","SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-cx-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.cy:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cy","role":"idp","level":"SHOULD","summary":"The NameQualifier and SPNameQualifier attributes should be omitted unless the element or format explicitly defines their use and semantics","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cy-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.cy:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cy","role":"sp","level":"SHOULD","summary":"The NameQualifier and SPNameQualifier attributes should be omitted unless the element or format explicitly defines their use and semantics","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-cy-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.cz:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.cz","role":"idp","level":"SHOULD_NOT","summary":"A Subject element should not identify more than one principal","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-cz-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.da:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.da","role":"idp","level":"MUST_NOT","summary":"SAML extensions must not add local or SAML-namespace-qualified XML attributes to the SubjectConfirmationDataType complex type","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-da-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.db:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.db","role":"idp","level":"SHOULD","summary":"The time period specified by the NotBefore and NotOnOrAfter attributes of SubjectConfirmationData should fall within the overall assertion validity period","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-db-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dc:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dc","role":"idp","level":"MUST","summary":"If both NotBefore and NotOnOrAfter are present on SubjectConfirmationData, NotBefore must be earlier than NotOnOrAfter","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dc-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dd:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dd","role":"idp","level":"MUST","summary":"Assertions containing AuthnStatement elements must contain a Subject element","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dd-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.de:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.de","role":"idp","level":"SHOULD_NOT","summary":"The SessionIndex value should not be usable to correlate activity by a principal across different session participants","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-de-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.df:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.df","role":"idp","level":"SHOULD","summary":"The SAML authority should choose the range of SessionIndex values such that the cardinality of any one integer is sufficiently high to prevent correlation","condition":{"predicate":"uses_small_integer_sessionindex","predicate_kind":"CAPABILITY_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-df-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dg:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dg","role":"idp","level":"SHOULD","summary":"The SAML authority should choose values for SessionIndex randomly from within the chosen range","condition":{"predicate":"uses_small_integer_sessionindex","predicate_kind":"CAPABILITY_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dg-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dh:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dh","role":"idp","level":"MUST","summary":"Assertions containing AttributeStatement elements must contain a Subject element","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dh-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.di:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.di","role":"idp","level":"MUST_NOT","summary":"SAML extensions must not add local or SAML-namespace-qualified XML attributes to the AttributeType complex type","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-di-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dj:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dj","role":"idp","level":"MUST","summary":"Within an AttributeStatement, if the SAML attribute exists but has no values, then the AttributeValue element must be omitted","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dj-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dk:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dk","role":"idp","level":"MUST","summary":"If a SAML attribute includes an empty value, the corresponding AttributeValue element must be empty","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dk-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dl:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dl","role":"idp","level":"MUST","summary":"If a SAML attribute includes a null value, the corresponding AttributeValue element must be empty and must contain xsi:nil with a value of true or 1","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dl-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dm:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dm","role":"idp","level":"SHOULD","summary":"The Type attribute of an encrypted SAML element should be present","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dm-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dn:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dn","role":"idp","level":"MUST","summary":"If the Type attribute of an encrypted SAML element is present, it must contain the value http://www.w3.org/2001/04/xmlenc#Element","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dn-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.do:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.do","role":"idp","level":"MUST","summary":"The encrypted content must contain an element of the type required for that encrypted SAML element","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-do-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dp:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dp","role":"idp","level":"MUST","summary":"For an encrypted identifier, the ciphertext must be unique to any given encryption operation","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","XMLEnc","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dp-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dq:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dq","role":"idp","level":"SHOULD","summary":"Each wrapped key should include a Recipient attribute that specifies the entity for whom the key has been encrypted, and its value should be the URI identifier of a SAML system entity","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dq-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ds:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ds","role":"idp","level":"SHOULD","summary":"IPv4 addresses should be represented in dotted-decimal format and IPv6 addresses as defined by RFC 3513","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ds-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.du:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.du","role":"idp","level":"RECOMMENDED","summary":"If an attribute contains more than one discrete value, it is recommended that each value appear in its own AttributeValue element","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-du-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dy:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dy","role":"idp","level":"RECOMMENDED","summary":"Two solutions that prevent correlation of SessionIndex values are provided by SAML2Core and are recommended","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dy-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dz:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dz","role":"idp","level":"MUST","summary":"All strings in SAML messages must consist of at least one non-whitespace character","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dz-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dz:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dz","role":"sp","level":"MUST","summary":"All strings in SAML messages must consist of at least one non-whitespace character","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-dz-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ea:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ea","role":"idp","level":"MUST","summary":"All elements of type xs:string or derived from it must be compared using an exact binary comparison","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ea-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ea:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ea","role":"sp","level":"MUST","summary":"All elements of type xs:string or derived from it must be compared using an exact binary comparison","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ea-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.eb:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.eb","role":"idp","level":"MUST_NOT","summary":"SAML implementations and deployments must not depend on case-insensitive string comparisons, normalization or trimming of whitespace, or conversion of locale-specific formats","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-eb-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.eb:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.eb","role":"sp","level":"MUST_NOT","summary":"SAML implementations and deployments must not depend on case-insensitive string comparisons, normalization or trimming of whitespace, or conversion of locale-specific formats","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-eb-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ec:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ec","role":"idp","level":"MUST","summary":"When comparing values represented using different character encodings, the implementation must use a comparison method equivalent to converting both to Unicode Normalization Form C and performing an exact binary comparison","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ec-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ec:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ec","role":"sp","level":"MUST","summary":"When comparing values represented using different character encodings, the implementation must use a comparison method equivalent to converting both to Unicode Normalization Form C and performing an exact binary comparison","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ec-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ed:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ed","role":"idp","level":"MUST","summary":"Applications that compare data received in SAML documents to data from external sources must take into account the normalization rules specified for XML","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ed-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ed:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ed","role":"sp","level":"MUST","summary":"Applications that compare data received in SAML documents to data from external sources must take into account the normalization rules specified for XML","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ed-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ee:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ee","role":"idp","level":"MUST_NOT","summary":"SAML implementations must not depend on specific sorting orders for values","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ee-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ee:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ee","role":"sp","level":"MUST_NOT","summary":"SAML implementations must not depend on specific sorting orders for values","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ee-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ef:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ef","role":"idp","level":"MUST","summary":"All URI reference values used within SAML-defined elements or attributes must consist of at least one non-whitespace character and are required to be absolute","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ef-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ef:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ef","role":"sp","level":"MUST","summary":"All URI reference values used within SAML-defined elements or attributes must consist of at least one non-whitespace character and are required to be absolute","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ef-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.eg:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.eg","role":"idp","level":"MUST","summary":"All SAML time values must be expressed in UTC form, with no time zone component","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-eg-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.eg:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.eg","role":"sp","level":"MUST","summary":"All SAML time values must be expressed in UTC form, with no time zone component","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-eg-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.eh:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.eh","role":"idp","level":"SHOULD_NOT","summary":"SAML system entities should not rely on time resolution finer than milliseconds","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-eh-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.eh:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.eh","role":"sp","level":"SHOULD_NOT","summary":"SAML system entities should not rely on time resolution finer than milliseconds","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-eh-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ei:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ei","role":"idp","level":"MUST_NOT","summary":"Implementations must not generate time instants that specify leap seconds","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ei-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ei:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ei","role":"sp","level":"MUST_NOT","summary":"Implementations must not generate time instants that specify leap seconds","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ei-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ej:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ej","role":"idp","level":"MUST_NOT","summary":"A SAML asserting party must not issue any assertion with an overall Major.Minor assertion version number not supported by the authority","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ej-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ek:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ek","role":"sp","level":"MUST_NOT","summary":"A SAML relying party must not process any assertion with a major assertion version number not supported by the relying party","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ek-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.el:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.el","role":"sp","level":"MUST_NOT","summary":"A SAML requester must not issue a request message with an overall Major.Minor request version number matching a response version number that the requester does not support","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-el-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.em:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.em","role":"idp","level":"MUST","summary":"A SAML responder must reject any request with a major request version number not supported by the responder","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-em-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.en:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.en","role":"idp","level":"MUST_NOT","summary":"A SAML responder must not issue a response message with a response version number higher than the request version number of the corresponding request message","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-en-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.eo:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.eo","role":"idp","level":"MUST_NOT","summary":"A SAML responder must not issue a response message with a major response version number lower than the major request version number of the corresponding request, except to report the error RequestVersionTooHigh","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-eo-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ep:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ep","role":"idp","level":"MUST","summary":"An error response resulting from incompatible SAML protocol versions must report a top-level StatusCode value of VersionMismatch","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ep-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.eq:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.eq","role":"idp","level":"MUST_NOT","summary":"A V1.0 assertion must not appear in a V2.0 response message because they are of different major versions","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-eq-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fg:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fg","role":"sp","level":"SHOULD","summary":"A SAML requester should issue requests with the highest request version supported by both the requester and the responder","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-fg-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.fh:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fh","role":"sp","level":"SHOULD","summary":"If the requester does not know the capabilities of the responder, it should assume that the responder supports requests with the highest request version supported by the requester","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-fh-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.er:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.er","role":"idp","level":"MUST","summary":"SAML assertions and protocol messages must use enveloped signatures","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Bind","SAML2Core","SAML2Prof","XMLEnc","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-er-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.er:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.er","role":"sp","level":"MUST","summary":"SAML assertions and protocol messages must use enveloped signatures","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Bind","SAML2Core","SAML2Prof","XMLEnc","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-er-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.es:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.es","role":"idp","level":"SHOULD","summary":"A SAML assertion obtained by a relying party from an entity other than the asserting party should be signed by the asserting party","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-es-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.et:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.et","role":"idp","level":"SHOULD","summary":"A Response message arriving at a destination from an entity other than the originating sender should be signed by the sender","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-et-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fj:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fj","role":"sp","level":"SHOULD","summary":"An AuthnRequest should be signed or otherwise authenticated and integrity protected by its delivery binding","condition":null,"testability":"BROWSER","sourceIds":["SAML2Bind","SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-fj-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.eu:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.eu","role":"idp","level":"MUST","summary":"SAML assertions and protocol messages must supply a value for the ID attribute on the root element being signed","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-eu-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.eu:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.eu","role":"sp","level":"MUST","summary":"SAML assertions and protocol messages must supply a value for the ID attribute on the root element being signed","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-eu-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ev:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ev","role":"idp","level":"MUST","summary":"Signatures must contain a single ds:Reference containing a same-document reference to the ID attribute value of the root element being signed","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ev-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ev:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ev","role":"sp","level":"MUST","summary":"Signatures must contain a single ds:Reference containing a same-document reference to the ID attribute value of the root element being signed","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ev-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ew:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ew","role":"idp","level":"SHOULD","summary":"SAML implementations should use Exclusive Canonicalization both in the CanonicalizationMethod and as a Transform algorithm","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ew-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ew:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ew","role":"sp","level":"SHOULD","summary":"SAML implementations should use Exclusive Canonicalization both in the CanonicalizationMethod and as a Transform algorithm","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ew-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ex:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ex","role":"idp","level":"SHOULD_NOT","summary":"Signatures in SAML messages should not contain transforms other than the enveloped signature transform or the exclusive canonicalization transforms","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ex-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ex:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ex","role":"sp","level":"SHOULD_NOT","summary":"Signatures in SAML messages should not contain transforms other than the enveloped signature transform or the exclusive canonicalization transforms","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ex-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ey:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ey","role":"sp","level":"MUST","summary":"A service provider that does not reject signatures containing other transform algorithms must ensure that no content of the Response or Assertion is excluded from the signature","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ey-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.fk:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fk","role":"idp","level":"MUST","summary":"An identity provider that does not reject signatures containing other transform algorithms must ensure that no content of the AuthnRequest is excluded from the signature","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-fk-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ez:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ez","role":"idp","level":"MUST","summary":"When an Assertion is encrypted, the encrypted data must replace the plaintext information in the same location within the XML instance","condition":null,"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ez-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fd:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fd","role":"idp","level":"MUST","summary":"When a BaseID or NameID is encrypted, the encrypted data must replace the plaintext information in the same location","condition":null,"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-fd-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fe:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fe","role":"idp","level":"MUST","summary":"When an Attribute is encrypted, the encrypted data must replace the plaintext information in the same location","condition":null,"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-fe-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.dr:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.dr","role":"idp","level":"MUST","summary":"The AuthnRequest that a proxying identity provider generates for the upstream identity provider must follow the SAML identifier uniqueness requirements","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-dr-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.bk:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.bk","role":"idp","level":"MAY","summary":"The identity provider may include a binding-specific RelayState parameter with an unsolicited Response, based on mutual agreement with the service provider","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-bk-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.y2:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.y2","role":"sp","level":"SHOULD","summary":"The service provider should be prepared to handle unsolicited responses by designating a default location to send the user agent subsequent to processing a response successfully","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-y2-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.fl:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fl","role":"sp","level":"SHOULD","summary":"A service provider requester that does not make specific use of AllowCreate should generally set it to true, except when requesting a transient name identifier","condition":{"predicate":"allowcreate_general_interoperability_case","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-fl-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.fm:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fm","role":"idp","level":"SHOULD","summary":"A proxying identity provider requester that does not make specific use of AllowCreate should generally set it to true, except when requesting a transient name identifier","condition":{"predicate":"proxy_allowcreate_general_interoperability_case","predicate_kind":"CLASSIFICATION_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-fm-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fn:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fn","role":"sp","level":"MUST_NOT","summary":"A service provider must not use AllowCreate in a request for a transient name identifier","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-fn-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.fo:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fo","role":"idp","level":"MUST_NOT","summary":"A proxying identity provider must not use AllowCreate in an upstream request for a transient name identifier","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-fo-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fp:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fp","role":"idp","level":"SHOULD","summary":"An identity provider should ignore AllowCreate in conjunction with requests for, or assertions issued with, transient name identifiers","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-fp-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fr:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fr","role":"idp","level":"SHOULD","summary":"If an assertion is issued for use by an entity other than the subject, that entity should be identified in SubjectConfirmation","condition":null,"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-fr-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fs:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fs","role":"idp","level":"SHOULD_NOT","summary":"The ds:Object element should not be present in SAML signatures","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-fs-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fs:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fs","role":"sp","level":"SHOULD_NOT","summary":"The ds:Object element should not be present in SAML signatures","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-fs-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ft:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ft","role":"sp","level":"SHOULD","summary":"A service provider verifier should reject SAML signatures that contain a ds:Object element","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-ft-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.fu:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fu","role":"idp","level":"SHOULD","summary":"An identity provider verifier should reject SAML signatures that contain a ds:Object element","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-fu-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fv:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fv","role":"idp","level":"SHOULD","summary":"If an EncryptedAssertion is present and CBC-mode encryption is used, the Response should be signed","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-fv-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fw:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fw","role":"sp","level":"SHOULD","summary":"Before processing CBC-encrypted assertions or assertions containing CBC-encrypted data, the relying party should require integrity protection","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-fw-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.fx:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fx","role":"idp","level":"SHOULD","summary":"An AuthnRequest issued by a proxying identity provider should be signed or otherwise authenticated and integrity protected by its delivery binding","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-fx-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.fy:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fy","role":"sp","level":"MUST_NOT","summary":"If an assertion signature is invalid, the relying party must not rely on the contents of the assertion","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-fy-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.fz:sp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.fz","role":"sp","level":"SHOULD","summary":"If an assertion signature is valid, the relying party should evaluate it to determine the identity and appropriateness of the issuer","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO01-fz-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO01.ga:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ga","role":"idp","level":"MUST","summary":"If RequestedAuthnContext Comparison is minimum and the identity provider succeeds, the resulting authentication context must be at least as strong as one of the requested contexts","condition":null,"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ga-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.gb:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.gb","role":"idp","level":"MUST","summary":"If RequestedAuthnContext Comparison is better and the identity provider succeeds, the resulting authentication context must be stronger than one of the requested contexts","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-gb-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.gc:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.gc","role":"idp","level":"MUST","summary":"If RequestedAuthnContext Comparison is maximum and the identity provider succeeds, the resulting authentication context must be as strong as possible without exceeding at least one requested context","condition":null,"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-gc-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.gd:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.gd","role":"idp","level":"SHOULD","summary":"If multiple attesting entities are permitted to use a bearer assertion, multiple SubjectConfirmation elements should be included","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-gd-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.ge:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.ge","role":"idp","level":"SHOULD","summary":"A proxying identity provider requester should use the highest request version supported by both it and the upstream responder","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-ge-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.gf:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.gf","role":"idp","level":"SHOULD","summary":"If a proxying identity provider requester does not know the upstream responder's capabilities, it should assume support for its own highest request version","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-gf-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.gg:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.gg","role":"idp","level":"MUST_NOT","summary":"A proxying identity provider requester must not issue a request version corresponding to a response version it does not support","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-gg-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.gh:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.gh","role":"idp","level":"SHOULD","summary":"A proxying identity provider should sign an upstream AuthnRequest when its Consent attribute indicates that principal consent has been obtained","condition":{"predicate":"supports_authnrequest_proxying","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-gh-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.gi:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.gi","role":"idp","level":"MUST_NOT","summary":"If the request ID cannot be determined, the response must not contain InResponseTo","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-gi-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO01.gj:idp","requirement":"IIP-SSO01","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO01","obligation":"IIP-SSO01.gj","role":"idp","level":"MUST","summary":"When ordering is relevant to RequestedAuthnContext evaluation, the supplied references must be evaluated as an ordered set with the first element most preferred","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO01-gj-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO02.a:idp","requirement":"IIP-SSO02","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO02","obligation":"IIP-SSO02.a","role":"idp","level":"MUST","summary":"Support both HTTP-Redirect and HTTP-POST bindings for authentication requests","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO02-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO02.a:sp","requirement":"IIP-SSO02","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO02","obligation":"IIP-SSO02.a","role":"sp","level":"MUST","summary":"Support both HTTP-Redirect and HTTP-POST bindings for authentication requests","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO02-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO03.a:idp","requirement":"IIP-SSO03","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO03","obligation":"IIP-SSO03.a","role":"idp","level":"MUST","summary":"Support the HTTP-POST binding for authentication responses","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO03-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO03.a:sp","requirement":"IIP-SSO03","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO03","obligation":"IIP-SSO03.a","role":"sp","level":"MUST","summary":"Support the HTTP-POST binding for authentication responses","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO03-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO03.b:idp","requirement":"IIP-SSO03","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO03","obligation":"IIP-SSO03.b","role":"idp","level":"MUST","summary":"Support the HTTP-POST binding for error responses","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO03-b-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO03.b:sp","requirement":"IIP-SSO03","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO03","obligation":"IIP-SSO03.b","role":"sp","level":"MUST","summary":"Support the HTTP-POST binding for error responses","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO03-b-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO04.a:idp","requirement":"IIP-SSO04","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO04","obligation":"IIP-SSO04.a","role":"idp","level":"MUST","summary":"Support signing of assertions and responses both together and independently","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO04-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO04.a:sp","requirement":"IIP-SSO04","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO04","obligation":"IIP-SSO04.a","role":"sp","level":"MUST","summary":"Support signing of assertions and responses both together and independently","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO04-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO05.a:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.a","role":"idp","level":"MUST","summary":"Support the persistent name identifier format","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO05-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO05.a:sp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.a","role":"sp","level":"MUST","summary":"Support the persistent name identifier format","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO05-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO05.a1:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.a1","role":"idp","level":"MUST","summary":"Persistent identifiers must be constructed using pseudo-random values with no discernible correspondence with the subject's actual identifier","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO05-a1-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO05.a2:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.a2","role":"idp","level":"MUST_NOT","summary":"Persistent name identifier values must not exceed a length of 256 characters","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO05-a2-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO05.a3:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.a3","role":"idp","level":"MUST","summary":"NameQualifier / SPNameQualifier / SPProvidedID must carry the values defined by SAML2Core 8.3.7 when present","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO05-a3-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO05.a4:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.a4","role":"idp","level":"MUST_NOT","summary":"Persistent identifiers must not be shared in clear text with other providers, and must not appear in log files without appropriate controls","condition":null,"testability":"NOT_OBSERVABLE","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[]},{"id":"IIP-SSO05.a4:sp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.a4","role":"sp","level":"MUST_NOT","summary":"Persistent identifiers must not be shared in clear text with other providers, and must not appear in log files without appropriate controls","condition":null,"testability":"NOT_OBSERVABLE","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[]},{"id":"IIP-SSO05.a5:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.a5","role":"idp","level":"MUST","summary":"SPProvidedID must contain the alternative identifier of the principal most recently set by the service provider or affiliation","condition":{"predicate":"supports_name_identifier_management","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO05-a5-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO05.a6:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.a6","role":"idp","level":"MUST","summary":"When re-issuing an identifier created by another entity, NameQualifier must continue to identify the entity that originally created it","condition":{"predicate":"reissues_foreign_persistent_identifier","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO05-a6-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO05.a7:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.a7","role":"idp","level":"MUST_NOT","summary":"When re-issuing an identifier created by another entity, the NameQualifier attribute must not be omitted","condition":{"predicate":"reissues_foreign_persistent_identifier","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO05-a7-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO05.a8:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.a8","role":"idp","level":"MUST_NOT","summary":"Deployments must not overload the persistent format with persistent but non-opaque values","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO05-a8-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO05.b:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.b","role":"idp","level":"MUST","summary":"Support the transient name identifier format","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO05-b-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO05.b:sp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.b","role":"sp","level":"MUST","summary":"Support the transient name identifier format","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO05-b-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO05.b1:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.b1","role":"idp","level":"MUST_NOT","summary":"Transient name identifier values must not exceed a length of 256 characters","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO05-b1-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO05.b2:idp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.b2","role":"idp","level":"MUST","summary":"Transient identifier values must be generated in accordance with the rules for SAML identifiers (SAML2Core 1.3.4)","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO05-b2-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO05.b3:sp","requirement":"IIP-SSO05","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO05","obligation":"IIP-SSO05.b3","role":"sp","level":"SHOULD","summary":"Relying parties should treat transient identifiers as opaque and temporary values","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO05-b3-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO06.a:idp","requirement":"IIP-SSO06","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO06","obligation":"IIP-SSO06.a","role":"idp","level":"MUST","summary":"Consume peer configuration values from metadata, without additional inputs, for every element identified as MUST or MAY in SAML2Prof 4.1.6 that corresponds to a supported setting","condition":{"predicate":"setting_supported_by_implementation","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2ECP","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO06-a-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO06.a:sp","requirement":"IIP-SSO06","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO06","obligation":"IIP-SSO06.a","role":"sp","level":"MUST","summary":"Consume peer configuration values from metadata, without additional inputs, for every element identified as MUST or MAY in SAML2Prof 4.1.6 that corresponds to a supported setting","condition":{"predicate":"setting_supported_by_implementation","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2ECP","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO06-a-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO07.a:idp","requirement":"IIP-SSO07","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO07","obligation":"IIP-SSO07.a","role":"idp","level":"OPTIONAL","summary":"Including optional elements and attributes in issued messages and assertions is optional","condition":null,"testability":"AUTOMATED","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO07-a-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO07.a:sp","requirement":"IIP-SSO07","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO07","obligation":"IIP-SSO07.a","role":"sp","level":"OPTIONAL","summary":"Including optional elements and attributes in issued messages and assertions is optional","condition":null,"testability":"AUTOMATED","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO07-a-sp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SSO07.b:idp","requirement":"IIP-SSO07","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO07","obligation":"IIP-SSO07.b","role":"idp","level":"REQUIRED","summary":"Successfully process messages and assertions containing unsupported optional content — such content must either result in errors or be ignored, as directed by SAML2Core processing rules for that element","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-SSO07-b-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-SSO07.b:sp","requirement":"IIP-SSO07","section":"2.3","sectionName":"Common / Web Browser SSO","anchor":"#IIP-SSO07","obligation":"IIP-SSO07.b","role":"sp","level":"REQUIRED","summary":"Successfully process messages and assertions containing unsupported optional content — such content must either result in errors or be ignored, as directed by SAML2Core processing rules for that element","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SSO07-b-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-EXT01.a:idp","requirement":"IIP-EXT01","section":"2.4","sectionName":"Common / Extensibility","anchor":"#IIP-EXT01","obligation":"IIP-EXT01.a","role":"idp","level":"MUST","summary":"Successfully consume any and all well-formed extensions","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"],"cases":[{"id":"IIP-EXT01-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"]}]},{"id":"IIP-EXT01.a:sp","requirement":"IIP-EXT01","section":"2.4","sectionName":"Common / Extensibility","anchor":"#IIP-EXT01","obligation":"IIP-EXT01.a","role":"sp","level":"MUST","summary":"Successfully consume any and all well-formed extensions","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp","single_logout_sp"],"cases":[{"id":"IIP-EXT01-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp","metadata_sp","single_logout_sp"]}]},{"id":"IIP-EXT01.b1:idp","requirement":"IIP-EXT01","section":"2.4","sectionName":"Common / Extensibility","anchor":"#IIP-EXT01","obligation":"IIP-EXT01.b1","role":"idp","level":"MAY","summary":"The content of samlp:Extensions, md:Extensions and saml:Advice may be ignored","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"],"cases":[{"id":"IIP-EXT01-b1-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"]}]},{"id":"IIP-EXT01.b1:sp","requirement":"IIP-EXT01","section":"2.4","sectionName":"Common / Extensibility","anchor":"#IIP-EXT01","obligation":"IIP-EXT01.b1","role":"sp","level":"MAY","summary":"The content of samlp:Extensions, md:Extensions and saml:Advice may be ignored","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp","single_logout_sp"],"cases":[{"id":"IIP-EXT01-b1-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp","metadata_sp","single_logout_sp"]}]},{"id":"IIP-EXT01.b:idp","requirement":"IIP-EXT01","section":"2.4","sectionName":"Common / Extensibility","anchor":"#IIP-EXT01","obligation":"IIP-EXT01.b","role":"idp","level":"MUST_NOT","summary":"Content of samlp:Extensions, md:Extensions and saml:Advice may be ignored but must not result in software failures","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"],"cases":[{"id":"IIP-EXT01-b-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"]}]},{"id":"IIP-EXT01.b:sp","requirement":"IIP-EXT01","section":"2.4","sectionName":"Common / Extensibility","anchor":"#IIP-EXT01","obligation":"IIP-EXT01.b","role":"sp","level":"MUST_NOT","summary":"Content of samlp:Extensions, md:Extensions and saml:Advice may be ignored but must not result in software failures","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp","single_logout_sp"],"cases":[{"id":"IIP-EXT01-b-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp","metadata_sp","single_logout_sp"]}]},{"id":"IIP-EXT01.c1:idp","requirement":"IIP-EXT01","section":"2.4","sectionName":"Common / Extensibility","anchor":"#IIP-EXT01","obligation":"IIP-EXT01.c1","role":"idp","level":"MAY","summary":"Undefined attribute content on elements whose type definition contains xsd:anyAttribute may likewise be ignored","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"],"cases":[{"id":"IIP-EXT01-c1-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"]}]},{"id":"IIP-EXT01.c1:sp","requirement":"IIP-EXT01","section":"2.4","sectionName":"Common / Extensibility","anchor":"#IIP-EXT01","obligation":"IIP-EXT01.c1","role":"sp","level":"MAY","summary":"Undefined attribute content on elements whose type definition contains xsd:anyAttribute may likewise be ignored","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp","single_logout_sp"],"cases":[{"id":"IIP-EXT01-c1-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp","metadata_sp","single_logout_sp"]}]},{"id":"IIP-EXT01.c:idp","requirement":"IIP-EXT01","section":"2.4","sectionName":"Common / Extensibility","anchor":"#IIP-EXT01","obligation":"IIP-EXT01.c","role":"idp","level":"MUST_NOT","summary":"Undefined attribute content on elements whose type definition contains xsd:anyAttribute may be ignored but must not result in software failures","condition":null,"testability":"BROWSER","sourceIds":["SAML2-xsd","SAML2MD-xsd","kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"],"cases":[{"id":"IIP-EXT01-c-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"]}]},{"id":"IIP-EXT01.c:sp","requirement":"IIP-EXT01","section":"2.4","sectionName":"Common / Extensibility","anchor":"#IIP-EXT01","obligation":"IIP-EXT01.c","role":"sp","level":"MUST_NOT","summary":"Undefined attribute content on elements whose type definition contains xsd:anyAttribute may be ignored but must not result in software failures","condition":null,"testability":"BROWSER","sourceIds":["SAML2-xsd","SAML2MD-xsd","kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp","single_logout_sp"],"cases":[{"id":"IIP-EXT01-c-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp","metadata_sp","single_logout_sp"]}]},{"id":"IIP-ALG01.a:idp","requirement":"IIP-ALG01","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG01","obligation":"IIP-ALG01.a","role":"idp","level":"MUST","summary":"Support the SHA-256 digest algorithm for creation and verification of XML Signatures","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"],"cases":[{"id":"IIP-ALG01-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"]}]},{"id":"IIP-ALG01.a:sp","requirement":"IIP-ALG01","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG01","obligation":"IIP-ALG01.a","role":"sp","level":"MUST","summary":"Support the SHA-256 digest algorithm for creation and verification of XML Signatures","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp","single_logout_sp"],"cases":[{"id":"IIP-ALG01-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp","metadata_sp","single_logout_sp"]}]},{"id":"IIP-ALG02.a:idp","requirement":"IIP-ALG02","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG02","obligation":"IIP-ALG02.a","role":"idp","level":"MUST","summary":"Support the RSA-SHA256 signature algorithm for creation and verification of XML Signatures","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"],"cases":[{"id":"IIP-ALG02-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"]}]},{"id":"IIP-ALG02.a:sp","requirement":"IIP-ALG02","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG02","obligation":"IIP-ALG02.a","role":"sp","level":"MUST","summary":"Support the RSA-SHA256 signature algorithm for creation and verification of XML Signatures","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp","single_logout_sp"],"cases":[{"id":"IIP-ALG02-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp","metadata_sp","single_logout_sp"]}]},{"id":"IIP-ALG03.a:idp","requirement":"IIP-ALG03","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG03","obligation":"IIP-ALG03.a","role":"idp","level":"SHOULD","summary":"Should support the ECDSA-SHA256 signature algorithm","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"],"cases":[{"id":"IIP-ALG03-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"]}]},{"id":"IIP-ALG03.a:sp","requirement":"IIP-ALG03","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG03","obligation":"IIP-ALG03.a","role":"sp","level":"SHOULD","summary":"Should support the ECDSA-SHA256 signature algorithm","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp","single_logout_sp"],"cases":[{"id":"IIP-ALG03-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp","metadata_sp","single_logout_sp"]}]},{"id":"IIP-ALG04.a:idp","requirement":"IIP-ALG04","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG04","obligation":"IIP-ALG04.a","role":"idp","level":"MUST","summary":"Support the AES128-GCM block encryption algorithm","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp"],"cases":[{"id":"IIP-ALG04-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp"]}]},{"id":"IIP-ALG04.a:sp","requirement":"IIP-ALG04","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG04","obligation":"IIP-ALG04.a","role":"sp","level":"MUST","summary":"Support the AES128-GCM block encryption algorithm","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-ALG04-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-ALG04.b:idp","requirement":"IIP-ALG04","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG04","obligation":"IIP-ALG04.b","role":"idp","level":"MUST","summary":"Support the AES256-GCM block encryption algorithm","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp"],"cases":[{"id":"IIP-ALG04-b-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp"]}]},{"id":"IIP-ALG04.b:sp","requirement":"IIP-ALG04","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG04","obligation":"IIP-ALG04.b","role":"sp","level":"MUST","summary":"Support the AES256-GCM block encryption algorithm","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-ALG04-b-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-ALG05.a:idp","requirement":"IIP-ALG05","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG05","obligation":"IIP-ALG05.a","role":"idp","level":"MAY","summary":"May support AES-CBC block encryption algorithms for backwards compatibility","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp"],"cases":[{"id":"IIP-ALG05-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp"]}]},{"id":"IIP-ALG05.a:sp","requirement":"IIP-ALG05","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG05","obligation":"IIP-ALG05.a","role":"sp","level":"MAY","summary":"May support AES-CBC block encryption algorithms for backwards compatibility","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-ALG05-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-ALG05.b:idp","requirement":"IIP-ALG05","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG05","obligation":"IIP-ALG05.b","role":"idp","level":"SHOULD","summary":"Implementations supporting AES-CBC should warn on use","condition":{"predicate":"supports_cbc","predicate_kind":"CAPABILITY_BASED"},"testability":"ATTESTED","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp"],"cases":[{"id":"IIP-ALG05-b-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp","ecp_idp"]}]},{"id":"IIP-ALG05.b:sp","requirement":"IIP-ALG05","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG05","obligation":"IIP-ALG05.b","role":"sp","level":"SHOULD","summary":"Implementations supporting AES-CBC should warn on use","condition":{"predicate":"supports_cbc","predicate_kind":"CAPABILITY_BASED"},"testability":"ATTESTED","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-ALG05-b-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-ALG06.a:idp","requirement":"IIP-ALG06","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG06","obligation":"IIP-ALG06.a","role":"idp","level":"MUST","summary":"Support the rsa-oaep-mgf1p key transport algorithm","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp"],"cases":[{"id":"IIP-ALG06-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp"]}]},{"id":"IIP-ALG06.a:sp","requirement":"IIP-ALG06","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG06","obligation":"IIP-ALG06.a","role":"sp","level":"MUST","summary":"Support the rsa-oaep-mgf1p key transport algorithm","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-ALG06-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-ALG06.b:idp","requirement":"IIP-ALG06","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG06","obligation":"IIP-ALG06.b","role":"idp","level":"MUST","summary":"Support the rsa-oaep key transport algorithm","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp"],"cases":[{"id":"IIP-ALG06-b-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp"]}]},{"id":"IIP-ALG06.b:sp","requirement":"IIP-ALG06","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG06","obligation":"IIP-ALG06.b","role":"sp","level":"MUST","summary":"Support the rsa-oaep key transport algorithm","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-ALG06-b-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-ALG06.c:idp","requirement":"IIP-ALG06","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG06","obligation":"IIP-ALG06.c","role":"idp","level":"MUST","summary":"Support DigestMethod sha256 and sha1 for both key transport algorithms","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp"],"cases":[{"id":"IIP-ALG06-c-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp"]}]},{"id":"IIP-ALG06.c:sp","requirement":"IIP-ALG06","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG06","obligation":"IIP-ALG06.c","role":"sp","level":"MUST","summary":"Support DigestMethod sha256 and sha1 for both key transport algorithms","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-ALG06-c-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-ALG06.d:idp","requirement":"IIP-ALG06","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG06","obligation":"IIP-ALG06.d","role":"idp","level":"MUST","summary":"Support the default mask generation function (MGF1 with SHA1) for rsa-oaep","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp"],"cases":[{"id":"IIP-ALG06-d-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp","ecp_idp"]}]},{"id":"IIP-ALG06.d:sp","requirement":"IIP-ALG06","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG06","obligation":"IIP-ALG06.d","role":"sp","level":"MUST","summary":"Support the default mask generation function (MGF1 with SHA1) for rsa-oaep","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-ALG06-d-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-ALG07.a:idp","requirement":"IIP-ALG07","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG07","obligation":"IIP-ALG07.a","role":"idp","level":"RECOMMENDED","summary":"Recommended: consider RFC7457 and current TLS best practice","condition":null,"testability":"ATTESTED","sourceIds":["RFC7457","kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"],"cases":[{"id":"IIP-ALG07-a-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp","ecp_idp","metadata_idp","single_logout_idp"]}]},{"id":"IIP-ALG07.a:sp","requirement":"IIP-ALG07","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG07","obligation":"IIP-ALG07.a","role":"sp","level":"RECOMMENDED","summary":"Recommended: consider RFC7457 and current TLS best practice","condition":null,"testability":"ATTESTED","sourceIds":["RFC7457","kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp","single_logout_sp"],"cases":[{"id":"IIP-ALG07-a-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp","metadata_sp","single_logout_sp"]}]},{"id":"IIP-ALG08.a:idp","requirement":"IIP-ALG08","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG08","obligation":"IIP-ALG08.a","role":"idp","level":"MUST","summary":"Support the ability to prevent the use of particular algorithms so that any attempt to configure or select them fails","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp"],"cases":[{"id":"IIP-ALG08-a-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp","ecp_idp"]}]},{"id":"IIP-ALG08.a:sp","requirement":"IIP-ALG08","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG08","obligation":"IIP-ALG08.a","role":"sp","level":"MUST","summary":"Support the ability to prevent the use of particular algorithms so that any attempt to configure or select them fails","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-ALG08-a-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-ALG08.b:idp","requirement":"IIP-ALG08","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG08","obligation":"IIP-ALG08.b","role":"idp","level":"MUST","summary":"The set of prevented algorithms must be configurable","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp"],"cases":[{"id":"IIP-ALG08-b-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp","ecp_idp"]}]},{"id":"IIP-ALG08.b:sp","requirement":"IIP-ALG08","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG08","obligation":"IIP-ALG08.b","role":"sp","level":"MUST","summary":"The set of prevented algorithms must be configurable","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-ALG08-b-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-ALG08.c:idp","requirement":"IIP-ALG08","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG08","obligation":"IIP-ALG08.c","role":"idp","level":"RECOMMENDED","summary":"Recommended: the default prevented set includes md5, rsa-md5 and rsa-1_5","condition":null,"testability":"ATTESTED","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp","ecp_idp"],"cases":[{"id":"IIP-ALG08-c-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp","ecp_idp"]}]},{"id":"IIP-ALG08.c:sp","requirement":"IIP-ALG08","section":"2.5","sectionName":"Common / Cryptographic Algorithms","anchor":"#IIP-ALG08","obligation":"IIP-ALG08.c","role":"sp","level":"RECOMMENDED","summary":"Recommended: the default prevented set includes md5, rsa-md5 and rsa-1_5","condition":null,"testability":"ATTESTED","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-ALG08-c-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP01.a:sp","requirement":"IIP-SP01","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP01","obligation":"IIP-SP01.a","role":"sp","level":"MUST","summary":"Consume saml:Attribute elements with any arbitrary xs:string Name and any arbitrary xs:anyURI NameFormat","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP01-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP02.a:sp","requirement":"IIP-SP02","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP02","obligation":"IIP-SP02.a","role":"sp","level":"MUST","summary":"Consume saml:AttributeValue elements containing any simple (text-only) element content","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP02-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP02.b:sp","requirement":"IIP-SP02","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP02","obligation":"IIP-SP02.b","role":"sp","level":"MUST_NOT","summary":"Must not require the presence of the xsi:type attribute on AttributeValue","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP02-b-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP02.c:sp","requirement":"IIP-SP02","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP02","obligation":"IIP-SP02.c","role":"sp","level":"OPTIONAL","summary":"Support for complex (mixed/nested) AttributeValue content is optional","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP02-c-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP03.a:sp","requirement":"IIP-SP03","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP03","obligation":"IIP-SP03.a","role":"sp","level":"MUST","summary":"Be capable of generating AuthnRequest messages without a samlp:NameIDPolicy element","condition":null,"testability":"CONFIG","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP03-a-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP03.b:sp","requirement":"IIP-SP03","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP03","obligation":"IIP-SP03.b","role":"sp","level":"MUST","summary":"Be capable of generating AuthnRequest messages with a NameIDPolicy element but no Format attribute","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP03-b-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP04.a:sp","requirement":"IIP-SP04","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP04","obligation":"IIP-SP04.a","role":"sp","level":"MUST","summary":"Support the IdP Discovery redirect protocol end to end as a Service Provider","condition":null,"testability":"BROWSER","sourceIds":["IdPDisco","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP04-a-sp-01","mode":"BROWSER","milestone":"M3","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP04.b:sp","requirement":"IIP-SP04","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP04","obligation":"IIP-SP04.b","role":"sp","level":"MUST","summary":"Initiate the Discovery Protocol by redirecting the user agent to the Discovery Service with HTTP GET","condition":null,"testability":"BROWSER","sourceIds":["IdPDisco","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP04-b-sp-01","mode":"BROWSER","milestone":"M3","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP04.c:sp","requirement":"IIP-SP04","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP04","obligation":"IIP-SP04.c","role":"sp","level":"MUST","summary":"Support at least the single-selection Discovery Service policy value","condition":null,"testability":"BROWSER","sourceIds":["IdPDisco","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP04-c-sp-01","mode":"BROWSER","milestone":"M3","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP04.d:sp","requirement":"IIP-SP04","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP04","obligation":"IIP-SP04.d","role":"sp","level":"MUST","summary":"Include the SP entityID parameter in every Discovery request","condition":null,"testability":"BROWSER","sourceIds":["IdPDisco","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP04-d-sp-01","mode":"BROWSER","milestone":"M3","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP04.e:sp","requirement":"IIP-SP04","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP04","obligation":"IIP-SP04.e","role":"sp","level":"MUST","summary":"URL-encode the entityID parameter in a Discovery request","condition":null,"testability":"BROWSER","sourceIds":["IdPDisco","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP04-e-sp-01","mode":"BROWSER","milestone":"M3","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP04.f:sp","requirement":"IIP-SP04","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP04","obligation":"IIP-SP04.f","role":"sp","level":"MUST_NOT","summary":"Do not place the effective returned-IdP parameter name in the query component of the return URL","condition":null,"testability":"BROWSER","sourceIds":["IdPDisco","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP04-f-sp-01","mode":"BROWSER","milestone":"M3","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP04.g:sp","requirement":"IIP-SP04","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP04","obligation":"IIP-SP04.g","role":"sp","level":"MUST","summary":"For every Discovery request, include return or use a default DiscoveryResponse endpoint from metadata","condition":null,"testability":"BROWSER","sourceIds":["IdPDisco","SAML2Meta","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP04-g-sp-01","mode":"BROWSER","milestone":"M3","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP04.h:sp","requirement":"IIP-SP04","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP04","obligation":"IIP-SP04.h","role":"sp","level":"MUST","summary":"Set DiscoveryResponse/@Binding to the IdP Discovery Protocol URI whenever publishing that metadata extension","condition":null,"testability":"AUTOMATED","sourceIds":["IdPDisco","kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp"],"cases":[{"id":"IIP-SP04-h-sp-01","mode":"AUTOMATED","milestone":"M3","profiles":["browser_sso_sp","metadata_sp"]}]},{"id":"IIP-SP04.i:sp","requirement":"IIP-SP04","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP04","obligation":"IIP-SP04.i","role":"sp","level":"MUST","summary":"Publish each DiscoveryResponse metadata extension with the md:IndexedEndpointType structure defined by IdPDisco","condition":null,"testability":"AUTOMATED","sourceIds":["IdPDisco","SAML2MD-xsd","kantara-fedinterop-impl"],"profiles":["browser_sso_sp","metadata_sp"],"cases":[{"id":"IIP-SP04-i-sp-01","mode":"AUTOMATED","milestone":"M3","profiles":["browser_sso_sp","metadata_sp"]}]},{"id":"IIP-SP05.a:sp","requirement":"IIP-SP05","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP05","obligation":"IIP-SP05.a","role":"sp","level":"MUST","summary":"Process responses from any number of issuing IdPs for any given resource URL","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP05-a-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP05.b:sp","requirement":"IIP-SP05","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP05","obligation":"IIP-SP05.b","role":"sp","level":"MUST_NOT","summary":"It must not be a restriction that multiple IdPs are only supported by requiring distinct resource URLs for each IdP","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP05-b-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP06.a:sp","requirement":"IIP-SP06","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP06","obligation":"IIP-SP06.a","role":"sp","level":"MUST","summary":"Generate AuthnRequest with a RequestedAuthnContext element containing the exact comparison method","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP06-a-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP06.b:sp","requirement":"IIP-SP06","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP06","obligation":"IIP-SP06.b","role":"sp","level":"MUST","summary":"Generate AuthnRequest with any number of AuthnContextClassRef elements","condition":null,"testability":"CONFIG","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP06-b-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP07.a:sp","requirement":"IIP-SP07","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP07","obligation":"IIP-SP07.a","role":"sp","level":"MUST","summary":"Support acceptance or rejection of assertions based on the content of the saml:AuthnContext element","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP07-a-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP08.a:sp","requirement":"IIP-SP08","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP08","obligation":"IIP-SP08.a","role":"sp","level":"MUST","summary":"Support decryption of saml:EncryptedAssertion elements","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP08-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP08.b:sp","requirement":"IIP-SP08","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP08","obligation":"IIP-SP08.b","role":"sp","level":"MUST","summary":"Be configurable with at least two decryption keys","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP08-b-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP08.c:sp","requirement":"IIP-SP08","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP08","obligation":"IIP-SP08.c","role":"sp","level":"MUST","summary":"Attempt each decryption key until the assertion decrypts or keys are exhausted, in which case decryption fails","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP08-c-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP09.a:sp","requirement":"IIP-SP09","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP09","obligation":"IIP-SP09.a","role":"sp","level":"MUST","summary":"Support deep linking and maintain direct addressability of protected resources with Web Browser SSO","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP09-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP09.b:sp","requirement":"IIP-SP09","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP09","obligation":"IIP-SP09.b","role":"sp","level":"RECOMMENDED","summary":"Recommended: preserve POST bodies across a successful SSO exchange, subject to size limits","condition":null,"testability":"ATTESTED","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP09-b-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP10.a:sp","requirement":"IIP-SP10","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP10","obligation":"IIP-SP10.a","role":"sp","level":"MUST_NOT","summary":"Must not fail or reject responses due to unrecognized saml:Attribute elements","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP10-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP11.a:sp","requirement":"IIP-SP11","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP11","obligation":"IIP-SP11.a","role":"sp","level":"MUST_NOT","summary":"Must not treat FriendlyName normatively or make comparisons based on its value","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP11-a-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP12.a:sp","requirement":"IIP-SP12","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP12","obligation":"IIP-SP12.a","role":"sp","level":"MUST_NOT","summary":"Must not require that a persistent name identifier carry semantics or structure beyond what SAML2Core 8.3.7 defines","condition":null,"testability":"CONFIG","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP12-a-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP12.b:sp","requirement":"IIP-SP12","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP12","obligation":"IIP-SP12.b","role":"sp","level":"MUST_NOT","summary":"Must not require, through configuration or deployment documentation, that persistent identifiers carry structure or semantics beyond SAML2Core 8.3.7","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP12-b-sp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP13.a:sp","requirement":"IIP-SP13","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP13","obligation":"IIP-SP13.a","role":"sp","level":"MUST","summary":"Support the ability to reject unsigned samlp:Response elements","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP13-a-sp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP13.b:sp","requirement":"IIP-SP13","section":"3.1","sectionName":"Service Provider / Web Browser SSO","anchor":"#IIP-SP13","obligation":"IIP-SP13.b","role":"sp","level":"SHOULD","summary":"Should reject unsigned samlp:Response elements by default","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_sp"],"cases":[{"id":"IIP-SP13-b-sp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_sp"]}]},{"id":"IIP-SP14.a:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.a","role":"sp","level":"SHOULD","summary":"Should support the SAML V2.0 SingleLogout profile","condition":null,"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-a-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.b:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.b","role":"sp","level":"MUST","summary":"Service Providers claiming support for SLO must be capable of issuing logout requests","condition":{"predicate":"claims_slo_support_sp","predicate_kind":"CLAIM_BASED"},"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-b-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.c:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.c","role":"sp","level":"OPTIONAL","summary":"Consumption of logout requests is optional","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-c-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.c1:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.c1","role":"sp","level":"OPTIONAL","summary":"Consumption of logout responses is optional","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-c1-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.d:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.d","role":"sp","level":"MUST","summary":"When a session involves multiple identity providers, repeat SLO independently for each identity provider","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-d-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.e:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.e","role":"sp","level":"MUST","summary":"Send each participant-initiated LogoutRequest to the corresponding identity provider's SLO request endpoint","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-e-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.f:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.f","role":"sp","level":"MUST","summary":"Include at least one applicable SessionIndex in a participant-issued LogoutRequest","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-f-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.g:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.g","role":"sp","level":"SHOULD","summary":"When the user agent is present, prefer an asynchronous front-channel binding for an SP-initiated LogoutRequest","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-g-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.h:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.h","role":"sp","level":"RECOMMENDED","summary":"Use TLS for the HTTP exchange that sends an SP-initiated LogoutRequest","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-h-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.i:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.i","role":"sp","level":"MUST","summary":"Sign an SP-issued LogoutRequest sent with HTTP POST or Redirect","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-i-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.j:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.j","role":"sp","level":"SHOULD","summary":"Reveal as little information as possible in SLO RelayState when privacy measures are required","condition":{"predicate":"slo_relaystate_privacy_required","predicate_kind":"CLASSIFICATION_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-j-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.k:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.k","role":"sp","level":"MUST","summary":"Authenticate the SP as LogoutRequest requester and protect message integrity","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-k-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.l:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.l","role":"sp","level":"MUST","summary":"Include Issuer in an SP-issued LogoutRequest","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-l-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.m:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.m","role":"sp","level":"MUST","summary":"Use the SP's unique entity identifier as LogoutRequest Issuer","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-m-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.n:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.n","role":"sp","level":"MUST","summary":"Omit LogoutRequest Issuer Format or set it to the SAML entity NameID format","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-n-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.o:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.o","role":"sp","level":"MUST","summary":"Identify the principal in LogoutRequest with an identifier that strongly matches the authentication assertion","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-o-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.p:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.p","role":"sp","level":"MUST","summary":"Invalidate the sessions identified by an authenticated LogoutRequest from the session authority","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-p-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.q:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.q","role":"sp","level":"MUST","summary":"Issue a LogoutResponse with an appropriate status after processing a LogoutRequest or encountering a protocol error","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-q-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.r:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.r","role":"sp","level":"MUST","summary":"Authenticate the SP as responder when returning LogoutResponse over a synchronous binding","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-r-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.s:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.s","role":"sp","level":"RECOMMENDED","summary":"Use TLS for the HTTP exchange that returns LogoutResponse to the identity provider","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-s-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.t:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.t","role":"sp","level":"MUST","summary":"Sign every consumed-flow LogoutResponse sent with HTTP POST or Redirect","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-t-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.u:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.u","role":"sp","level":"MUST","summary":"Include Issuer in an SP-issued LogoutResponse","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-u-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.v:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.v","role":"sp","level":"MUST","summary":"Use the SP's unique entity identifier as LogoutResponse Issuer","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-v-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.w:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.w","role":"sp","level":"MUST","summary":"Omit LogoutResponse Issuer Format or set it to the SAML entity NameID format","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-w-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.x:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.x","role":"sp","level":"MUST","summary":"Authenticate the SP as LogoutResponse responder and protect message integrity","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-x-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.y:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.y","role":"sp","level":"MUST","summary":"Authenticate every consumed LogoutRequest before applying it to local sessions","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-y-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.z:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.z","role":"sp","level":"MUST","summary":"Apply an unexpired LogoutRequest to a matching authentication assertion even when the assertion arrives after the request","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-z-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.aa:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.aa","role":"sp","level":"MUST","summary":"Assign unique SAML identifiers to every LogoutRequest and LogoutResponse the service provider emits","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-aa-sp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.ab:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.ab","role":"sp","level":"MUST","summary":"Set LogoutResponse InResponseTo according to the corresponding LogoutRequest","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-ab-sp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.ac:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.ac","role":"sp","level":"MUST","summary":"If Destination is present on a consumed SLO request or response, compare it with the actual receiving location and discard a mismatch","condition":null,"testability":"BROWSER","sourceIds":["SAML2Bind","SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-ac-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.ad:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.ad","role":"sp","level":"MUST","summary":"Verify every XML signature present on a consumed LogoutRequest or LogoutResponse","condition":null,"testability":"BROWSER","sourceIds":["SAML2Bind","SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-ad-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.ae:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.ae","role":"sp","level":"MUST_NOT","summary":"Do not rely on the contents of a consumed SLO request or response whose XML signature is invalid","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-ae-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.af:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.af","role":"sp","level":"SHOULD","summary":"Treat an invalid XML signature on a consumed SLO request or response as an error","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-af-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.ag:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.ag","role":"sp","level":"SHOULD","summary":"For a valid XML signature on a consumed SLO request or response, evaluate the identity and appropriateness of the signer","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-ag-sp-01","mode":"ATTESTED","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.ah:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.ah","role":"sp","level":"SHOULD","summary":"Sign an emitted SLO request or response when its Consent value indicates that principal consent was obtained","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Bind","SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-ah-sp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.ai:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.ai","role":"sp","level":"MUST","summary":"When responding to a SAML-invalid LogoutRequest, use top-level Requester status","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-ai-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.aj:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.aj","role":"sp","level":"MUST","summary":"Use a permitted top-level StatusCode in every emitted LogoutResponse","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-aj-sp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.ak:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.ak","role":"sp","level":"MUST","summary":"Reject a consumed LogoutRequest whose major request version is unsupported","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-ak-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.al:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.al","role":"sp","level":"MUST_NOT","summary":"Do not emit a LogoutResponse with a version higher than its corresponding LogoutRequest","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-al-sp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.am:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.am","role":"sp","level":"MUST_NOT","summary":"Do not emit a LogoutResponse with a lower major version except to report RequestVersionTooHigh","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-am-sp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.an:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.an","role":"sp","level":"MUST","summary":"If responding to an incompatible SAML protocol version, use top-level VersionMismatch","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-an-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.ao:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.ao","role":"sp","level":"MUST_NOT","summary":"Do not issue a LogoutRequest whose version corresponds to a LogoutResponse version the service provider cannot process","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-ao-sp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.ap:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.ap","role":"sp","level":"SHOULD","summary":"Issue LogoutRequest using the highest request version supported by both requester and responder","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-ap-sp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.aq:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.aq","role":"sp","level":"SHOULD","summary":"When responder capabilities are unknown, assume support for the highest request version supported by the service provider","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"ATTESTED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-aq-sp-01","mode":"ATTESTED","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.ar:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.ar","role":"sp","level":"MUST","summary":"If accepting a SLO XML signature with a non-standard transform, ensure that no message content is excluded from the signature","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-ar-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP14.as:sp","requirement":"IIP-SP14","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP14","obligation":"IIP-SP14.as","role":"sp","level":"MUST","summary":"Make every emitted LogoutRequest and LogoutResponse conform to the SAML protocol schema","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2P-xsd","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP14-as-sp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP15.a:sp","requirement":"IIP-SP15","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP15","obligation":"IIP-SP15.a","role":"sp","level":"MUST","summary":"Support sending SP-initiated LogoutRequest messages with HTTP-Redirect","condition":{"predicate":"supports_slo_initiation_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP15-a-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP15.b:sp","requirement":"IIP-SP15","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP15","obligation":"IIP-SP15.b","role":"sp","level":"MUST","summary":"When consuming LogoutRequest messages, support receiving them with HTTP-Redirect","condition":{"predicate":"supports_slo_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP15-b-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP15.c:sp","requirement":"IIP-SP15","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP15","obligation":"IIP-SP15.c","role":"sp","level":"MUST","summary":"When consuming LogoutRequest messages, support returning LogoutResponse messages with HTTP-Redirect","condition":{"predicate":"supports_slo_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP15-c-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP15.d:sp","requirement":"IIP-SP15","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP15","obligation":"IIP-SP15.d","role":"sp","level":"MUST","summary":"When consuming LogoutResponse messages, support receiving them with HTTP-Redirect","condition":{"predicate":"supports_slo_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP15-d-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP16.a:sp","requirement":"IIP-SP16","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP16","obligation":"IIP-SP16.a","role":"sp","level":"MUST","summary":"SPs supporting SLO must support decryption of saml:EncryptedID in logout requests","condition":{"predicate":"supports_slo_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP16-a-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP16.b:sp","requirement":"IIP-SP16","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP16","obligation":"IIP-SP16.b","role":"sp","level":"MUST","summary":"Be configurable with at least two decryption keys (for encrypted identifiers)","condition":{"predicate":"supports_slo_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP16-b-sp-01","mode":"CONFIG","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP16.c:sp","requirement":"IIP-SP16","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP16","obligation":"IIP-SP16.c","role":"sp","level":"MUST","summary":"Attempt each decryption key until the identifier decrypts or keys are exhausted","condition":{"predicate":"supports_slo_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP16-c-sp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-SP17.a:sp","requirement":"IIP-SP17","section":"3.2","sectionName":"Service Provider / Single Logout","anchor":"#IIP-SP17","obligation":"IIP-SP17.a","role":"sp","level":"MUST","summary":"SPs supporting SLO must consume peer configuration from metadata, without additional inputs, for every element listed in SAML2Prof 4.4.5","condition":{"predicate":"supports_slo_sp","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_sp"],"cases":[{"id":"IIP-SP17-a-sp-01","mode":"CONFIG","milestone":"M3","profiles":["single_logout_sp"]}]},{"id":"IIP-IDP01.a:idp","requirement":"IIP-IDP01","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP01","obligation":"IIP-IDP01.a","role":"idp","level":"MUST","summary":"Generate saml:Attribute elements with any arbitrary xs:string Name and any arbitrary xs:anyURI NameFormat","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP01-a-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP02.a:idp","requirement":"IIP-IDP02","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP02","obligation":"IIP-IDP02.a","role":"idp","level":"MUST","summary":"Determine whether to include specific attributes or values based on the relying party's entityID","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP02-a-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP03.a:idp","requirement":"IIP-IDP03","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP03","obligation":"IIP-IDP03.a","role":"idp","level":"MUST","summary":"Determine whether to include specific attributes or values based on mdattr:EntityAttributes in the relying party's metadata","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP03-a-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP04.a:idp","requirement":"IIP-IDP04","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP04","obligation":"IIP-IDP04.a","role":"idp","level":"MUST","summary":"Determine attribute inclusion based on md:AttributeConsumingService / md:RequestedAttribute in the peer's metadata, including the value of the isRequired attribute","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP04-a-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP04.b:idp","requirement":"IIP-IDP04","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP04","obligation":"IIP-IDP04.b","role":"idp","level":"MUST","summary":"Support the AttributeConsumingServiceIndex attribute in AuthnRequest as the means of selecting the applicable md:AttributeConsumingService","condition":null,"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP04-b-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP05.a:idp","requirement":"IIP-IDP05","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP05","obligation":"IIP-IDP05.a","role":"idp","level":"MUST","summary":"Issue samlp:Response messages with appropriate status codes on error, provided the user agent remains available and an acceptable response location is known","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP05-a-idp-01","mode":"AUTOMATED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP06.a:idp","requirement":"IIP-IDP06","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP06","obligation":"IIP-IDP06.a","role":"idp","level":"MUST","summary":"If ForceAuthn is true, authenticate the presenter directly rather than rely on a previous security context","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP06-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP06.b:idp","requirement":"IIP-IDP06","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP06","obligation":"IIP-IDP06.b","role":"idp","level":"MUST","summary":"Authentication mechanisms within the implementation must have access to the ForceAuthn indicator so their behaviour may be influenced by its value","condition":null,"testability":"ATTESTED","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP06-b-idp-01","mode":"ATTESTED","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP06.c:idp","requirement":"IIP-IDP06","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP06","obligation":"IIP-IDP06.c","role":"idp","level":"MUST_NOT","summary":"If both ForceAuthn and IsPassive are true, must not freshly authenticate the presenter unless the constraints of IsPassive can be met","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP06-c-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP07.a:idp","requirement":"IIP-IDP07","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP07","obligation":"IIP-IDP07.a","role":"idp","level":"MUST_NOT","summary":"If IsPassive is true, the identity provider and the user agent must not visibly take control of the user interface and interact with the presenter in a noticeable fashion","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP07-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP08.a:idp","requirement":"IIP-IDP08","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP08","obligation":"IIP-IDP08.a","role":"idp","level":"MUST","summary":"Support the RequestedAuthnContext exact comparison method in AuthnRequest as defined in SAML2Core","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP08-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP09.a:idp","requirement":"IIP-IDP09","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP09","obligation":"IIP-IDP09.a","role":"idp","level":"MUST","summary":"Support encryption of assertions","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP09-a-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP09.b:idp","requirement":"IIP-IDP09","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP09","obligation":"IIP-IDP09.b","role":"idp","level":"OPTIONAL","summary":"Encryption of identifiers and attributes is optional","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP09-b-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP10.a:idp","requirement":"IIP-IDP10","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP10","obligation":"IIP-IDP10.a","role":"idp","level":"MUST","summary":"Accept and process the samlp:NameIDPolicy element and its Format, SPNameQualifier and AllowCreate attributes","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP10-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP10.b:idp","requirement":"IIP-IDP10","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP10","obligation":"IIP-IDP10.b","role":"idp","level":"MUST","summary":"If the content of NameIDPolicy is not understood or not acceptable, return a Response with an error Status","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP10-b-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP10.c:idp","requirement":"IIP-IDP10","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP10","obligation":"IIP-IDP10.c","role":"idp","level":"MUST","summary":"If Format is the encrypted value, the resulting assertions must contain EncryptedID elements instead of plaintext","condition":{"predicate":"supports_encrypted_nameid","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP10-c-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP10.d:idp","requirement":"IIP-IDP10","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP10","obligation":"IIP-IDP10.d","role":"idp","level":"MUST","summary":"If the NameIDPolicy content is accepted, the returned identifier must conform to it; otherwise an error must be returned","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP10-d-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP11.a:idp","requirement":"IIP-IDP11","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP11","obligation":"IIP-IDP11.a","role":"idp","level":"MUST","summary":"Generate saml:Assertion elements without a saml:NameID in the saml:Subject","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP11-a-idp-01","mode":"CONFIG","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP12.a:idp","requirement":"IIP-IDP12","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP12","obligation":"IIP-IDP12.a","role":"idp","level":"MUST","summary":"Support the AssertionConsumerServiceIndex attribute in AuthnRequest for identifying the response endpoint","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP12-a-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP12.e:idp","requirement":"IIP-IDP12","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP12","obligation":"IIP-IDP12.e","role":"idp","level":"MUST","summary":"Support the AssertionConsumerServiceURL attribute in AuthnRequest for identifying the response endpoint","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP12-e-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP12.f:idp","requirement":"IIP-IDP12","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP12","obligation":"IIP-IDP12.f","role":"idp","level":"MUST","summary":"Support the ProtocolBinding attribute in AuthnRequest for identifying the binding used to return the Response","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP12-f-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP12.b:idp","requirement":"IIP-IDP12","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP12","obligation":"IIP-IDP12.b","role":"idp","level":"MUST","summary":"The responder must ensure that the AssertionConsumerServiceURL value is in fact associated with the requester, and must have a trusted means to map an index to a location associated with the requester","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP12-b-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP12.c:idp","requirement":"IIP-IDP12","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP12","obligation":"IIP-IDP12.c","role":"idp","level":"MUST","summary":"If AssertionConsumerServiceIndex is omitted, return the Response to the default location associated with the requester","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Meta","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP12-c-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP12.d:idp","requirement":"IIP-IDP12","section":"4.1","sectionName":"Identity Provider / Web Browser SSO","anchor":"#IIP-IDP12","obligation":"IIP-IDP12.d","role":"idp","level":"MAY","summary":"If the specified index is invalid, the identity provider may return an error Response or may use the default location","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["browser_sso_idp"],"cases":[{"id":"IIP-IDP12-d-idp-01","mode":"BROWSER","milestone":"M1","profiles":["browser_sso_idp"]}]},{"id":"IIP-IDP13.a:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.a","role":"idp","level":"MUST","summary":"Support the SAML V2.0 Enhanced Client or Proxy Profile Version 2.0","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-a-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.e:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.e","role":"idp","level":"MUST","summary":"Complete the ECP SAML SOAP binding exchange and return a SAML Response or SOAP fault","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-e-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.f:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.f","role":"idp","level":"MUST","summary":"Establish the identity of the principal unless returning an error","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"CONFIG","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-f-idp-01","mode":"CONFIG","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.g:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.g","role":"idp","level":"MUST","summary":"When returning a SAML Response, include an ecp:Response header with the derived response destination","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-g-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.h:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.h","role":"idp","level":"SHOULD","summary":"When a signed AuthnRequest is successfully authenticated, include an ecp:RequestAuthenticated header","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-h-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.i:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.i","role":"idp","level":"MUST","summary":"Set the required SOAP actor and mustUnderstand values on ECP response header blocks","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-i-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.j:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.j","role":"idp","level":"MUST","summary":"Integrity-protect assertions in an ECP Response at the assertion or response level","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-j-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.k:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.k","role":"idp","level":"SHOULD","summary":"Integrity-protect SOAP headers in the ECP exchange","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"ATTESTED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-k-idp-01","mode":"ATTESTED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.l:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.l","role":"idp","level":"MUST","summary":"Securely associate intermediate HTTP exchanges with the original ECP AuthnRequest","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"CONFIG","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-l-idp-01","mode":"CONFIG","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.m:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.m","role":"idp","level":"SHOULD","summary":"Support SOAP- or HTTP-based authentication with no or minimal presentation-oriented interface","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"ATTESTED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-m-idp-01","mode":"ATTESTED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.n:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.n","role":"idp","level":"SHOULD_NOT","summary":"Do not derive an ECP assertion-encryption key merely by probing a service provider TLS endpoint","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"ATTESTED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-n-idp-01","mode":"ATTESTED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.o:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.o","role":"idp","level":"MAY","summary":"An ECP response may include an ecp:RelayState header","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-o-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.p:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.p","role":"idp","level":"MAY","summary":"The identity provider may interpret the delegation audience marker as a request to identify itself in an audience restriction","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-p-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.q:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.q","role":"idp","level":"SHOULD_NOT","summary":"Avoid HTML or other presentation-oriented authentication in the ECP exchange","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"ATTESTED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-q-idp-01","mode":"ATTESTED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.r:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.r","role":"idp","level":"MAY","summary":"The identity provider may use intermediate HTTP presentation exchanges before completing the SAML SOAP exchange","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-r-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.b:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.b","role":"idp","level":"OPTIONAL","summary":"Full conformance to the ECP Profile is optional","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"ATTESTED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-b-idp-01","mode":"ATTESTED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.c:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.c","role":"idp","level":"MUST","summary":"Support Bearer subject confirmation in ECP","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2ECP","SAML2Prof","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-c-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP13.d:idp","requirement":"IIP-IDP13","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP13","obligation":"IIP-IDP13.d","role":"idp","level":"MUST","summary":"Support verification of channel bindings in ECP","condition":{"predicate":"not_token_translation_proxy","predicate_kind":"CLASSIFICATION_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2ECP","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP13-d-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP14.a:idp","requirement":"IIP-IDP14","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP14","obligation":"IIP-IDP14.a","role":"idp","level":"MUST","summary":"Support HTTP Basic Authentication to authenticate the user agent","condition":null,"testability":"AUTOMATED","sourceIds":["kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP14-a-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP14.b:idp","requirement":"IIP-IDP14","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP14","obligation":"IIP-IDP14.b","role":"idp","level":"MAY","summary":"Other forms of authentication may be supported","condition":null,"testability":"ATTESTED","sourceIds":["kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP14-b-idp-01","mode":"ATTESTED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP15.a:idp","requirement":"IIP-IDP15","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP15","obligation":"IIP-IDP15.a","role":"idp","level":"MUST","summary":"Generate and include a random key in accordance with SAML-EC section 5.3.1","condition":null,"testability":"AUTOMATED","sourceIds":["SAML-EC","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP15-a-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP16.a:idp","requirement":"IIP-IDP16","section":"4.2","sectionName":"Identity Provider / Enhanced Client or Proxy","anchor":"#IIP-IDP16","obligation":"IIP-IDP16.a","role":"idp","level":"MUST","summary":"Consume peer configuration from metadata, without additional inputs, for every element listed in SAML2ECP section 2.3.10","condition":null,"testability":"CONFIG","sourceIds":["SAML2ECP","SAML2Prof","kantara-fedinterop-impl"],"profiles":["ecp_idp"],"cases":[{"id":"IIP-IDP16-a-idp-01","mode":"CONFIG","milestone":"M3","profiles":["ecp_idp"]}]},{"id":"IIP-IDP17.a:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.a","role":"idp","level":"MUST","summary":"Support the SAML V2.0 SingleLogout profile","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Errata","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-a-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.b:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.b","role":"idp","level":"MUST","summary":"Support the SAML V2.0 Asynchronous Single Logout Protocol Extension","condition":null,"testability":"BROWSER","sourceIds":["SAML2ASLO","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-b-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.b1:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.b1","role":"idp","level":"MUST_NOT","summary":"For a trusted asynchronous LogoutRequest, do not send a LogoutResponse to its initiator","condition":null,"testability":"BROWSER","sourceIds":["SAML2ASLO","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-b1-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.b2:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.b2","role":"idp","level":"MUST","summary":"Provide all relevant feedback when no LogoutResponse is returned for a trusted asynchronous request","condition":null,"testability":"BROWSER","sourceIds":["SAML2ASLO","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-b2-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.b3:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.b3","role":"idp","level":"MUST","summary":"Place an emitted aslo:Asynchronous element inside samlp:LogoutRequest/samlp:Extensions","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2ASLO","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-b3-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.b4:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.b4","role":"idp","level":"MAY","summary":"Metadata endpoints may advertise support for asynchronous logout requests","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2ASLO","kantara-fedinterop-impl"],"profiles":["metadata_idp","single_logout_idp"],"cases":[{"id":"IIP-IDP17-b4-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["metadata_idp","single_logout_idp"]}]},{"id":"IIP-IDP17.c:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.c","role":"idp","level":"OPTIONAL","summary":"Propagation of logout requests to other session participants is optional","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-c-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.d:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.d","role":"idp","level":"MUST","summary":"Examine the principal identifier and SessionIndex values and determine the exact sessions to terminate","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-d-idp-01","mode":"CONFIG","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.e:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.e","role":"idp","level":"MUST","summary":"For a response-bearing request, if the identity provider successfully terminates its own session, return a LogoutResponse with top-level Success","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-e-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.f:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.f","role":"idp","level":"MUST","summary":"Include Issuer in an IdP-issued LogoutResponse","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-f-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.g:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.g","role":"idp","level":"MUST","summary":"Use the IdP's unique entity identifier as LogoutResponse Issuer","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-g-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.h:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.h","role":"idp","level":"MUST","summary":"Omit LogoutResponse Issuer Format or set it to the SAML entity NameID format","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-h-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.i:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.i","role":"idp","level":"MUST","summary":"Authenticate the IdP as LogoutResponse responder and protect message integrity","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-i-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.j:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.j","role":"idp","level":"MUST","summary":"Include Issuer in any IdP-issued LogoutRequest","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-j-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.k:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.k","role":"idp","level":"MUST","summary":"Use the IdP's unique entity identifier as LogoutRequest Issuer","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-k-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.l:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.l","role":"idp","level":"MUST","summary":"Omit LogoutRequest Issuer Format or set it to the SAML entity NameID format","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-l-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.m:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.m","role":"idp","level":"MUST","summary":"Authenticate the IdP as LogoutRequest requester and protect message integrity","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-m-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.n:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.n","role":"idp","level":"MUST","summary":"Identify the principal in an IdP-issued LogoutRequest with an identifier that strongly matches the authentication assertion","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-n-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.o:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.o","role":"idp","level":"MUST","summary":"For a response-bearing request, if the identity provider cannot terminate its own session, return a LogoutResponse with an error top-level status code","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"CONFIG","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-o-idp-01","mode":"CONFIG","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.p:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.p","role":"idp","level":"MUST","summary":"Authenticate the sender of every received LogoutRequest before applying it to sessions","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-p-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.q:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.q","role":"idp","level":"SHOULD","summary":"When a current-session participant sends LogoutRequest, terminate the identity provider's own matching current session","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-q-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.r:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.r","role":"idp","level":"SHOULD","summary":"When propagation is performed, attempt every applicable participant using any usable protocol binding despite individual failures","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-r-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.s:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.s","role":"idp","level":"MUST","summary":"When attempted propagation does not receive successful responses from every participant, include PartialLogout as a second-level status code","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-s-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.t:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.t","role":"idp","level":"MUST","summary":"Set NotOnOrAfter on every LogoutRequest constructed by the identity provider","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-t-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.u:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.u","role":"idp","level":"SHOULD","summary":"Set LogoutRequest NotOnOrAfter no earlier than the latest assertion NotOnOrAfter for the targeted session","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-u-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.v:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.v","role":"idp","level":"MUST","summary":"Assign unique SAML identifiers to every LogoutRequest and LogoutResponse the identity provider emits","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-v-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.w:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.w","role":"idp","level":"MUST","summary":"Set LogoutResponse InResponseTo according to the corresponding LogoutRequest","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-w-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.x:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.x","role":"idp","level":"MUST","summary":"If Destination is present on a consumed SLO request or response, compare it with the actual receiving location and discard a mismatch","condition":null,"testability":"BROWSER","sourceIds":["SAML2Bind","SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-x-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.y:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.y","role":"idp","level":"MUST","summary":"Verify every XML signature present on a consumed LogoutRequest or LogoutResponse","condition":null,"testability":"BROWSER","sourceIds":["SAML2Bind","SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-y-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.z:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.z","role":"idp","level":"MUST_NOT","summary":"Do not rely on the contents of a consumed SLO request or response whose XML signature is invalid","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-z-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.aa:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.aa","role":"idp","level":"SHOULD","summary":"Treat an invalid XML signature on a consumed SLO request or response as an error","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-aa-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.ab:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.ab","role":"idp","level":"SHOULD","summary":"For a valid XML signature on a consumed SLO request or response, evaluate the identity and appropriateness of the signer","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-ab-idp-01","mode":"ATTESTED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.ac:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.ac","role":"idp","level":"SHOULD","summary":"Sign an emitted SLO request or response when its Consent value indicates that principal consent was obtained","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Bind","SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-ac-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.ad:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.ad","role":"idp","level":"MUST","summary":"When responding to a SAML-invalid LogoutRequest, use top-level Requester status","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-ad-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.ae:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.ae","role":"idp","level":"MUST","summary":"Reject a received LogoutRequest whose major request version is unsupported","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-ae-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.af:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.af","role":"idp","level":"MUST_NOT","summary":"Do not emit a LogoutResponse with a version higher than its corresponding LogoutRequest","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-af-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.ag:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.ag","role":"idp","level":"MUST_NOT","summary":"Do not emit a LogoutResponse with a lower major version except to report RequestVersionTooHigh","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-ag-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.ah:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.ah","role":"idp","level":"MUST","summary":"If responding to an incompatible SAML protocol version, use top-level VersionMismatch","condition":{"predicate":"supports_slo_idp","predicate_kind":"CAPABILITY_BASED"},"testability":"BROWSER","sourceIds":["SAML2Core","SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-ah-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.ai:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.ai","role":"idp","level":"MUST_NOT","summary":"Do not issue a LogoutRequest whose version corresponds to a LogoutResponse version the identity provider cannot process","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-ai-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.aj:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.aj","role":"idp","level":"SHOULD","summary":"Issue LogoutRequest using the highest request version supported by both requester and responder","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-aj-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.ak:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.ak","role":"idp","level":"SHOULD","summary":"When responder capabilities are unknown, assume support for the highest request version supported by the identity provider","condition":null,"testability":"ATTESTED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-ak-idp-01","mode":"ATTESTED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.al:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.al","role":"idp","level":"MUST","summary":"If accepting a SLO XML signature with a non-standard transform, ensure that no message content is excluded from the signature","condition":null,"testability":"BROWSER","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-al-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.am:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.am","role":"idp","level":"MUST","summary":"Make every emitted LogoutRequest and LogoutResponse conform to the SAML protocol schema","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","SAML2P-xsd","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-am-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP17.an:idp","requirement":"IIP-IDP17","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP17","obligation":"IIP-IDP17.an","role":"idp","level":"MUST","summary":"Use a permitted top-level StatusCode in every emitted LogoutResponse","condition":null,"testability":"AUTOMATED","sourceIds":["SAML2Core","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP17-an-idp-01","mode":"AUTOMATED","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP18.a:idp","requirement":"IIP-IDP18","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP18","obligation":"IIP-IDP18.a","role":"idp","level":"MUST","summary":"Support receiving SP-initiated LogoutRequest messages with HTTP-Redirect","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP18-a-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP18.b:idp","requirement":"IIP-IDP18","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP18","obligation":"IIP-IDP18.b","role":"idp","level":"MUST","summary":"Support sending LogoutResponse messages with HTTP-Redirect for SP-initiated logout","condition":null,"testability":"BROWSER","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP18-b-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP18.c:idp","requirement":"IIP-IDP18","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP18","obligation":"IIP-IDP18.c","role":"idp","level":"MUST","summary":"When the IdP emits LogoutRequest messages, support sending them with HTTP-Redirect","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP18-c-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP18.d:idp","requirement":"IIP-IDP18","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP18","obligation":"IIP-IDP18.d","role":"idp","level":"MUST","summary":"For a response-bearing IdP-issued LogoutRequest, support receiving LogoutResponse with HTTP-Redirect","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP18-d-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP19.a:idp","requirement":"IIP-IDP19","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP19","obligation":"IIP-IDP19.a","role":"idp","level":"MUST","summary":"Support decryption of saml:EncryptedID elements in logout requests","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP19-a-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP19.b:idp","requirement":"IIP-IDP19","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP19","obligation":"IIP-IDP19.b","role":"idp","level":"MUST","summary":"Be configurable with at least two decryption keys","condition":null,"testability":"CONFIG","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP19-b-idp-01","mode":"CONFIG","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP19.c:idp","requirement":"IIP-IDP19","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP19","obligation":"IIP-IDP19.c","role":"idp","level":"MUST","summary":"Attempt each decryption key until the identifier decrypts or keys are exhausted, in which case decryption fails","condition":null,"testability":"BROWSER","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP19-c-idp-01","mode":"BROWSER","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP20.a:idp","requirement":"IIP-IDP20","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP20","obligation":"IIP-IDP20.a","role":"idp","level":"MUST","summary":"Consume peer configuration from metadata, without additional inputs, for every element listed in SAML2Prof 4.4.5","condition":null,"testability":"CONFIG","sourceIds":["SAML2Prof","kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP20-a-idp-01","mode":"CONFIG","milestone":"M3","profiles":["single_logout_idp"]}]},{"id":"IIP-IDP21.a:idp","requirement":"IIP-IDP21","section":"4.3","sectionName":"Identity Provider / Single Logout","anchor":"#IIP-IDP21","obligation":"IIP-IDP21.a","role":"idp","level":"MUST","summary":"Generate persistent name identifiers in a manner that allows deployers to avoid assigning identifiers that differ only by case to two different subjects","condition":null,"testability":"ATTESTED","sourceIds":["kantara-fedinterop-impl"],"profiles":["single_logout_idp"],"cases":[{"id":"IIP-IDP21-a-idp-01","mode":"ATTESTED","milestone":"M3","profiles":["single_logout_idp"]}]}],"totals":{"requirements":69,"obligations":544,"cases":732},"attribution":{"scope":"Notices for the specification-derived requirement summaries, profile correspondence and case references represented in this catalog. Measured results are outside this catalog.","transformations":"SAMLscope summarizes and organizes source requirements and adds test instructions and case-level profile mappings; these are not unmodified source documents.","materialIndexPath":"LICENSES/material-index.json","materialIndexSha256":"79f4a504266da21655bb1d66f88336341f354d32c13863d5597760a59fb03697","registryPath":"LICENSES/source-notices.json","registrySha256":"69a33193cc3cbfda9e0e3422ea5cd838a6a4dc6daf27519769c62859fdac8f09","registryProvenance":"The notice registry is identified by its content hash separately from sourceCommit, which identifies the coverage, case and specification catalogs.","sources":[{"id":"IdPDisco","title":"Identity Provider Discovery Service Protocol and Profile","source_url":"http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-idp-discovery-cs-01.pdf","edition":"1.0 (CS)","date":"2008-03-27","catalog_entry":{"version":"1.0 (CS)","date":"2008-03-01","url":"http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-idp-discovery.pdf","source_digest":"sha256:8b631f0fff50d5268872bd59f6bab40f511ae274ea0f3212046cbcacee8dd3fa"},"catalog_correction_pending":true,"raw_pdf_sha256":"8b631f0fff50d5268872bd59f6bab40f511ae274ea0f3212046cbcacee8dd3fa","notice_page":3,"notice_text_sha256":"c094dbec36d615645fbf64b6f528fea6165a3bc6d6f326e21e2dbfef09d623d9","notice_text":"Notices\nCopyright © OASIS Open 2007. All Rights Reserved.\nAll capitalized terms in the following text have the meanings assigned to them in the OASIS Intellectual  \nProperty Rights Policy (the \"OASIS IPR Policy\"). The full Policy may be found at the OASIS website.\nThis document and translations of it may be copied and furnished to others, and derivative works that  \ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published,  \nand distributed, in whole or in part, without restriction of any kind, provided that the above copyright  \nnotice and this section are included on all such copies and derivative works. However, this document  \nitself may not be modified in any way, including by removing the copyright notice or references to OASIS,  \nexcept as needed for the purpose of developing any document or deliverable produced by an OASIS  \nTechnical Committee (in which case the rules applicable to copyrights, as set forth in the OASIS IPR  \nPolicy, must be followed) or as required to translate it into languages other than English.\nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors  \nor assigns.\nThis document and the information contained herein is provided on an \"AS IS\" basis and OASIS  \nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY \nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY \nOWNERSHIP RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A \nPARTICULAR PURPOSE.\nOASIS requests that any OASIS Party or any other party that believes it has patent claims that would  \nnecessarily be infringed by implementations of this OASIS Committee Specification or OASIS Standard,  \nto notify OASIS TC Administrator and provide an indication of its willingness to grant patent licenses to  \nsuch patent claims in a manner consistent with the IPR Mode of the OASIS Technical Committee that  \nproduced this specification.\nOASIS invites any party to contact the OASIS TC Administrator if it is aware of a claim of ownership of  \nany patent claims that would necessarily be infringed by implementations of this specification by a patent  \nholder that is not willing to provide a license to such patent claims in a manner consistent with the IPR  \nMode of the OASIS Technical Committee that produced this specification. OASIS may include such  \nclaims on its website, but disclaims any obligation to do so.\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that  \nmight be claimed to pertain to the implementation or use of the technology described in this document or  \nthe extent to which any license under such rights might or might not be available; neither does it  \nrepresent that it has made any effort to identify any such rights. Information on OASIS' procedures with  \nrespect to rights in any document or deliverable produced by an OASIS Technical Committee can be  \nfound on the OASIS website. Copies of claims of rights made available for publication and any  \nassurances of licenses to be made available, or the result of an attempt made to obtain a general license  \nor permission for the use of such proprietary rights by implementers or users of this OASIS Committee  \nSpecification or OASIS Standard, can be obtained from the OASIS TC Administrator. OASIS makes no  \nrepresentation that any information or list of intellectual property rights will at any time be complete, or  \nthat any claims in such list are, in fact, Essential Claims.\nThe name \"OASIS\" is a trademark of OASIS, the owner and developer of this specification, and should  \nbe used only to refer to the organization and its official outputs. OASIS welcomes reference to, and  \nimplementation and use of, specifications, while reserving the right to enforce its marks against  \nmisleading uses. Please see http://www.oasis-open.org/who/trademark.php for above guidance.\nSstc-saml-idp-discovery-cs-01 27 March 2008\nCopyright © OASIS Open 2007. All Rights Reserved. Page 3 of 13\n47\n48\n49\n50\n51\n52\n53\n54\n55\n56\n57\n58\n59\n60\n61\n62\n63\n64\n65\n66\n67\n68\n69\n70\n71\n72\n73\n74\n75\n76\n77\n78\n79\n80\n81\n82\n83\n84\n85\n86\n87\n88\n89\n90\n5\n6","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"MDQ","title":"Metadata Query Protocol","source_url":"https://www.ietf.org/archive/id/draft-young-md-query-07.txt","edition":"draft-young-md-query-07","date":"2017-07-17","catalog_entry":{"version":"draft-young-md-query-07","date":"2017-07-01","url":"https://www.ietf.org/archive/id/draft-young-md-query-07.txt","source_digest":"sha256:6007463c2733c644c5c8ab4665c09dfd434c68cf9b2eb183c27a76712a96c3f8"},"catalog_correction_pending":true,"raw_source_sha256":"6007463c2733c644c5c8ab4665c09dfd434c68cf9b2eb183c27a76712a96c3f8","notice_location":"Copyright Notice before Table of Contents (page furniture retained)","notice_text":"Copyright Notice\n\n   Copyright (c) 2017 IETF Trust and the persons identified as the\n   document authors.  All rights reserved.\n\n   This document is subject to BCP 78 and the IETF Trust's Legal\n   Provisions Relating to IETF Documents\n   (http://trustee.ietf.org/license-info) in effect on the date of\n   publication of this document.  Please review these documents\n   carefully, as they describe your rights and restrictions with respect\n   to this document.\n\n","notice_text_sha256":"786f67ed0ff74010c43910998af6c97fdb87bac7d75192437f462eccc53781c2","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"REFERENCE_OR_INDEPENDENT_IMPLEMENTATION","terms_review_status":"NO_DOCUMENT_REPRODUCTION_PERMISSION_NEEDED","publication_status":"GREEN","usage_review":"Catalog IDs, technical facts, section selectors and independently written behavior descriptions; no adopted document body is distributed. Embedded library schemas are assessed separately in the dependency inventory.","resolved_by_implementation":false},{"id":"MetaAttr","title":"SAML V2.0 Metadata Extension for Entity Attributes","source_url":"http://docs.oasis-open.org/security/saml/Post2.0/sstc-metadata-attr-cs-01.pdf","edition":"1.0 (cs-01)","date":"2009-08-04","catalog_entry":{"version":"1.0 (cs-01)","date":"2009-08-01","url":"http://docs.oasis-open.org/security/saml/Post2.0/sstc-metadata-attr-cs-01.pdf","source_digest":"sha256:15d332bf01534ab2b577974384f9f87704c8abb9b1717385a6e5bdc00ce933ea"},"catalog_correction_pending":true,"raw_pdf_sha256":"15d332bf01534ab2b577974384f9f87704c8abb9b1717385a6e5bdc00ce933ea","notice_page":3,"notice_text_sha256":"8ac6d20f69890a043905261870e4c5363a081ef2536e599d71af8ef2439bd2a2","notice_text":"Notices\nCopyright © OASIS Open 2009. All Rights Reserved.\nAll capitalized terms in the following text have the meanings assigned to them in the OASIS Intellectual \nProperty Rights Policy (the \"OASIS IPR Policy\"). The full Policy may be found at the OASIS website.\nThis document and translations of it may be copied and furnished to others, and derivative works that \ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published, \nand distributed, in whole or in part, without restriction of any kind, provided that the above copyright notice \nand this section are included on all such copies and derivative works. However, this document itself may \nnot be modified in any way, including by removing the copyright notice or references to OASIS, except as \nneeded for the purpose of developing any document or deliverable produced by an OASIS Technical \nCommittee (in which case the rules applicable to copyrights, as set forth in the OASIS IPR Policy, must be \nfollowed) or as required to translate it into languages other than English.\nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors \nor assigns.\nThis document and the information contained herein is provided on an \"AS IS\" basis and OASIS \nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY \nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY \nOWNERSHIP RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A \nPARTICULAR PURPOSE.\nOASIS requests that any OASIS Party or any other party that believes it has patent claims that would \nnecessarily be infringed by implementations of this OASIS Committee Specification or OASIS Standard, \nto notify OASIS TC Administrator and provide an indication of its willingness to grant patent licenses to \nsuch patent claims in a manner consistent with the IPR Mode of the OASIS Technical Committee that \nproduced this specification.\nOASIS invites any party to contact the OASIS TC Administrator if it is aware of a claim of ownership of \nany patent claims that would necessarily be infringed by implementations of this specification by a patent \nholder that is not willing to provide a license to such patent claims in a manner consistent with the IPR \nMode of the OASIS Technical Committee that produced this specification. OASIS may include such \nclaims on its website, but disclaims any obligation to do so.\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that \nmight be claimed to pertain to the implementation or use of the technology described in this document or \nthe extent to which any license under such rights might or might not be available; neither does it \nrepresent that it has made any effort to identify any such rights. Information on OASIS' procedures with \nrespect to rights in any document or deliverable produced by an OASIS Technical Committee can be \nfound on the OASIS website. Copies of claims of rights made available for publication and any \nassurances of licenses to be made available, or the result of an attempt made to obtain a general license \nor permission for the use of such proprietary rights by implementers or users of this OASIS Committee \nSpecification or OASIS Standard, can be obtained from the OASIS TC Administrator. OASIS makes no \nrepresentation that any information or list of intellectual property rights will at any time be complete, or \nthat any claims in such list are, in fact, Essential Claims.\nThe name \"OASIS\" is a trademark of OASIS, the owner and developer of this specification, and should be \nused only to refer to the organization and its official outputs. OASIS welcomes reference to, and \nimplementation and use of, specifications, while reserving the right to enforce its marks against \nmisleading uses. Please see http://www.oasis-open.org/who/trademark.php for above guidance.\nSstc-metadata-attr-cs-01  4 August 2009\nCopyright © OASIS Open 2009. All Rights Reserved. Page 3 of 11\n44\n45\n46\n47\n48\n49\n50\n51\n52\n53\n54\n55\n56\n57\n58\n59\n60\n61\n62\n63\n64\n65\n66\n67\n68\n69\n70\n71\n72\n73\n74\n75\n76\n77\n78\n79\n80\n81\n82\n83\n84\n85\n86\n87\n5\n6","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"MetaUi","title":"SAML V2.0 Metadata Extensions for Login and Discovery User Interface","source_url":"https://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-metadata-ui/v1.0/os/sstc-saml-metadata-ui-v1.0-os.pdf","edition":"1.0 (OS)","date":"2019-10-24","catalog_entry":{"version":"1.0 (CS)","date":"2012-04-01","url":"http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-metadata-ui/v1.0/sstc-saml-metadata-ui-v1.0.pdf","source_digest":"sha256:e3ded72bc41e11a47e5371219cbcdd5b365e10d399793790ab5350f2b2f30cfc"},"catalog_correction_pending":true,"raw_pdf_sha256":"e3ded72bc41e11a47e5371219cbcdd5b365e10d399793790ab5350f2b2f30cfc","notice_page":3,"notice_text_sha256":"f87244a4f319a6dd6ff2b85d79eba62445b8fa7d414b8d6272c498b03b4c007e","notice_text":"Notices\nCopyright © OASIS Open 2019. All Rights Reserved.\nAll capitalized terms in the following text have the meanings assigned to them in the OASIS Intellectual \nProperty Rights Policy (the \"OASIS IPR Policy\"). The full Policy may be found at the OASIS website.\nThis document and translations of it may be copied and furnished to others, and derivative works that \ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published, \nand distributed, in whole or in part, without restriction of any kind, provided that the above copyright notice \nand this section are included on all such copies and derivative works. However, this document itself may \nnot be modified in any way, including by removing the copyright notice or references to OASIS, except as \nneeded for the purpose of developing any document or deliverable produced by an OASIS Technical \nCommittee (in which case the rules applicable to copyrights, as set forth in the OASIS IPR Policy, must be \nfollowed) or as required to translate it into languages other than English.\nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors \nor assigns.\nThis document and the information contained herein is provided on an \"AS IS\" basis and OASIS \nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY \nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY \nOWNERSHIP RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A \nPARTICULAR PURPOSE.\nOASIS requests that any OASIS Party or any other party that believes it has patent claims that would \nnecessarily be infringed by implementations of this OASIS Committee Specification or OASIS Standard, to \nnotify OASIS TC Administrator and provide an indication of its willingness to grant patent licenses to such \npatent claims in a manner consistent with the IPR Mode of the OASIS Technical Committee that produced \nthis specification.\nOASIS invites any party to contact the OASIS TC Administrator if it is aware of a claim of ownership of any \npatent claims that would necessarily be infringed by implementations of this specification by a patent \nholder that is not willing to provide a license to such patent claims in a manner consistent with the IPR \nMode of the OASIS Technical Committee that produced this specification. OASIS may include such claims \non its website, but disclaims any obligation to do so.\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that \nmight be claimed to pertain to the implementation or use of the technology described in this document or \nthe extent to which any license under such rights might or might not be available; neither does it represent \nthat it has made any effort to identify any such rights. Information on OASIS' procedures with respect to \nrights in any document or deliverable produced by an OASIS Technical Committee can be found on the \nOASIS website. Copies of claims of rights made available for publication and any assurances of licenses \nto be made available, or the result of an attempt made to obtain a general license or permission for the \nuse of such proprietary rights by implementers or users of this OASIS Committee Specification or OASIS \nStandard, can be obtained from the OASIS TC Administrator. OASIS makes no representation that any \ninformation or list of intellectual property rights will at any time be complete, or that any claims in such list \nare, in fact, Essential Claims.\nThe name \"OASIS\" is a trademark of OASIS, the owner and developer of this specification, and should be \nused only to refer to the organization and its official outputs. OASIS welcomes reference to, and \nimplementation and use of, specifications, while reserving the right to enforce its marks against misleading \nuses. Please see https://www.oasis-open.org/policies-guidelines/trademark for above guidance.\nsstc-saml-metadata-ui-v1.0-os 24 October 2019\nStandards Track Work Product Copyright © OASIS Open 2019. All Rights Reserved. Page 3 of 18","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"RFC7457","title":"Summarizing Known Attacks on TLS and DTLS","source_url":"https://www.ietf.org/rfc/rfc7457.txt","edition":"RFC 7457","date":"2015-02","catalog_entry":{"version":"RFC 7457","date":"2015-02-01","url":"https://www.ietf.org/rfc/rfc7457.txt","source_digest":"sha256:f90360738aaa90dc2071e82bc089ffd1169995e7104ae252cd596444da49685f"},"catalog_correction_pending":false,"raw_source_sha256":"f90360738aaa90dc2071e82bc089ffd1169995e7104ae252cd596444da49685f","notice_location":"Copyright Notice before Table of Contents (page furniture retained)","notice_text":"Copyright Notice\n\n   Copyright (c) 2015 IETF Trust and the persons identified as the\n   document authors.  All rights reserved.\n\n   This document is subject to BCP 78 and the IETF Trust's Legal\n   Provisions Relating to IETF Documents\n   (http://trustee.ietf.org/license-info) in effect on the date of\n   publication of this document.  Please review these documents\n   carefully, as they describe your rights and restrictions with respect\n   to this document.  Code Components extracted from this document must\n   include Simplified BSD License text as described in Section 4.e of\n   the Trust Legal Provisions and are provided without warranty as\n   described in the Simplified BSD License.\n\n","notice_text_sha256":"6999576ad028fdda182b907d2ac40f29ad45c3de0e9591caa3511f4ea7f13526","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"REFERENCE_OR_INDEPENDENT_IMPLEMENTATION","terms_review_status":"NO_DOCUMENT_REPRODUCTION_PERMISSION_NEEDED","publication_status":"GREEN","usage_review":"Catalog IDs, technical facts, section selectors and independently written behavior descriptions; no adopted document body is distributed. Embedded library schemas are assessed separately in the dependency inventory.","resolved_by_implementation":false},{"id":"SAML-EC","title":"SAML Enhanced Client SASL and GSS-API Mechanisms","source_url":"https://www.ietf.org/archive/id/draft-ietf-kitten-sasl-saml-ec-16.txt","edition":"draft-ietf-kitten-sasl-saml-ec-16","date":"2017-10-24","catalog_entry":{"version":"draft-ietf-kitten-sasl-saml-ec-16","date":"2017-10-01","url":"https://www.ietf.org/archive/id/draft-ietf-kitten-sasl-saml-ec-16.txt","source_digest":"sha256:7c3266f6e19445e9e5f06d637a73769fcd99dd35865101544be8ec6444d625a6"},"catalog_correction_pending":true,"raw_source_sha256":"7c3266f6e19445e9e5f06d637a73769fcd99dd35865101544be8ec6444d625a6","notice_location":"Copyright Notice before Table of Contents (page furniture retained)","notice_text":"Copyright Notice\n\n   Copyright (c) 2017 IETF Trust and the persons identified as the\n   document authors.  All rights reserved.\n\n   This document is subject to BCP 78 and the IETF Trust's Legal\n   Provisions Relating to IETF Documents\n\n\n\nCantor & Josefsson       Expires April 27, 2018                 [Page 1]\n\f\nInternet-Draft     SAML ECP SASL & GSS-API Mechanisms       October 2017\n\n\n   (https://trustee.ietf.org/license-info) in effect on the date of\n   publication of this document.  Please review these documents\n   carefully, as they describe your rights and restrictions with respect\n   to this document.  Code Components extracted from this document must\n   include Simplified BSD License text as described in Section 4.e of\n   the Trust Legal Provisions and are provided without warranty as\n   described in the Simplified BSD License.\n\n","notice_text_sha256":"5eca85658d48b337fa8687be0a95a901e7b8d41f203b42efc97d42ce5bfa03bc","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"REFERENCE_OR_INDEPENDENT_IMPLEMENTATION","terms_review_status":"NO_DOCUMENT_REPRODUCTION_PERMISSION_NEEDED","publication_status":"GREEN","usage_review":"Catalog IDs, technical facts, section selectors and independently written behavior descriptions; no adopted document body is distributed. Embedded library schemas are assessed separately in the dependency inventory.","resolved_by_implementation":false},{"id":"SAML2-xsd","title":"SAML V2.0 Assertion Schema","source_url":"http://docs.oasis-open.org/security/saml/v2.0/saml-schema-assertion-2.0.xsd","edition":"2.0","date":"2005-03-15","catalog_entry":{"title":"SAML V2.0 Assertion Schema","publisher":"OASIS","version":"2.0","date":"2005-03-15","url":"http://docs.oasis-open.org/security/saml/v2.0/saml-schema-assertion-2.0.xsd","role":"referenced","source_digest":"sha256:006eb7553843cb7baa9b08da2a9d444346c0e982fb9d9293babe08ede680924b"},"raw_source_sha256":"006eb7553843cb7baa9b08da2a9d444346c0e982fb9d9293babe08ede680924b","notice_location":"Catalog reference only; no standalone source file is redistributed.","notice_text":"","notice_text_sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855","notice_status":"REFERENCE_ONLY","publication_status":"GREEN","material_allocation_status":"REFERENCE_OR_INDEPENDENT_IMPLEMENTATION","terms_review_status":"NO_DOCUMENT_REPRODUCTION_PERMISSION_NEEDED","usage_review":"Identifiers, schema element/attribute names and official source references only in catalogs. Schema copies within unmodified dependency JARs are separate inventory items.","catalog_correction_pending":false,"resolved_by_implementation":false},{"id":"SAML2ASLO","title":"SAML V2.0 Asynchronous Single Logout Profile Extension","source_url":"http://docs.oasis-open.org/security/saml/Post2.0/saml-async-slo/v1.0/cs01/saml-async-slo-v1.0-cs01.pdf","edition":"1.0 (cs01)","date":"2012-11-22","catalog_entry":{"version":"1.0 (cs01)","date":"2012-11-01","url":"http://docs.oasis-open.org/security/saml/Post2.0/saml-async-slo/v1.0/cs01/saml-async-slo-v1.0-cs01.pdf","source_digest":"sha256:6b18895c247d2409203c7e17fd680d0e517df05566c85da059cb25a7a35df53c"},"catalog_correction_pending":true,"raw_pdf_sha256":"6b18895c247d2409203c7e17fd680d0e517df05566c85da059cb25a7a35df53c","notice_page":3,"notice_text_sha256":"679c053d0da366ec3047fb4c325197f971fe57a56fb372277316aa9e0693bd28","notice_text":"Notices\nCopyright © OASIS Open 2012. All Rights Reserved.\nAll capitalized terms in the following text have the meanings assigned to them in the OASIS Intellectual \nProperty Rights Policy (the \"OASIS IPR Policy\"). The full Policy may be found at the OASIS website.\nThis document and translations of it may be copied and furnished to others, and derivative works that \ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published, \nand distributed, in whole or in part, without restriction of any kind, provided that the above copyright notice \nand this section are included on all such copies and derivative works. However, this document itself may \nnot be modified in any way, including by removing the copyright notice or references to OASIS, except as \nneeded for the purpose of developing any document or deliverable produced by an OASIS Technical \nCommittee (in which case the rules applicable to copyrights, as set forth in the OASIS IPR Policy, must \nbe followed) or as required to translate it into languages other than English.\nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors \nor assigns.\nThis document and the information contained herein is provided on an \"AS IS\" basis and OASIS \nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY \nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY \nOWNERSHIP RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A \nPARTICULAR PURPOSE.\nOASIS requests that any OASIS Party or any other party that believes it has patent claims that would \nnecessarily be infringed by implementations of this OASIS Committee Specification or OASIS Standard, \nto notify OASIS TC Administrator and provide an indication of its willingness to grant patent licenses to \nsuch patent claims in a manner consistent with the IPR Mode of the OASIS Technical Committee that \nproduced this specification.\nOASIS invites any party to contact the OASIS TC Administrator if it is aware of a claim of ownership of \nany patent claims that would necessarily be infringed by implementations of this specification by a patent \nholder that is not willing to provide a license to such patent claims in a manner consistent with the IPR \nMode of the OASIS Technical Committee that produced this specification. OASIS may include such \nclaims on its website, but disclaims any obligation to do so.\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that \nmight be claimed to pertain to the implementation or use of the technology described in this document or \nthe extent to which any license under such rights might or might not be available; neither does it represent \nthat it has made any effort to identify any such rights. Information on OASIS' procedures with respect to \nrights in any document or deliverable produced by an OASIS Technical Committee can be found on the \nOASIS website. Copies of claims of rights made available for publication and any assurances of licenses \nto be made available, or the result of an attempt made to obtain a general license or permission for the \nuse of such proprietary rights by implementers or users of this OASIS Committee Specification or OASIS \nStandard, can be obtained from the OASIS TC Administrator. OASIS makes no representation that any \ninformation or list of intellectual property rights will at any time be complete, or that any claims in such list \nare, in fact, Essential Claims.\nThe name \"OASIS\" is a trademark of OASIS, the owner and developer of this specification, and should be \nused only to refer to the organization and its official outputs. OASIS welcomes reference to, and \nimplementation and use of, specifications, while reserving the right to enforce its marks against \nmisleading uses. Please see http://www.oasis-open.org/policies-guidelines/trademark for above guidance.\nsaml-async-slo-v1.0-cs01 22 November 2012\nStandards Track Work Product Copyright © OASIS Open 2012. All Rights Reserved. Page 3 of 10","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"SAML2Bind","title":"Bindings for the OASIS SAML V2.0","source_url":"http://docs.oasis-open.org/security/saml/v2.0/saml-bindings-2.0-os.pdf","edition":"2.0 (saml-bindings-2.0-os)","date":"2005-03-15","catalog_entry":{"version":"2.0 (saml-bindings-2.0-os)","date":"2005-03-15","url":"http://docs.oasis-open.org/security/saml/v2.0/saml-bindings-2.0-os.pdf","source_digest":"sha256:80dde7953739eeb306484888ea128dd214e2b4a5dd16fbcbb231ef7ae18fa3f1"},"catalog_correction_pending":false,"raw_pdf_sha256":"80dde7953739eeb306484888ea128dd214e2b4a5dd16fbcbb231ef7ae18fa3f1","notice_page":46,"notice_text_sha256":"6c959fab4f072de6480436a50d741ad8fe7c8b3c29c20abc7ae44b535b54b055","notice_text":"Appendix C. Notices\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that\nmight be claimed to pertain to the implementation or use of the technology described in this document or\nthe extent to which any license under such rights might or might not be available; neither does it represent\nthat it has made any effort to identify any such rights. Information on OASIS's procedures with respect to\nrights in OASIS specifications can be found at the OASIS website. Copies of claims of rights made\navailable for publication and any assurances of licenses to be made available, or the result of an attempt\nmade to obtain a general license or permission for the use of such proprietary rights by implementors or\nusers of this specification, can be obtained from the OASIS Executive Director.\nOASIS invites any interested party to bring to its attention any copyrights, patents or patent applications, or\nother proprietary rights which may cover technology that may be required to implement this specification.\nPlease address the information to the OASIS Executive Director.\nCopyright  © OASIS Open 2005. All Rights Reserved.\nThis document and translations of it may be copied and furnished to others, and derivative works that\ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published and\ndistributed, in whole or in part, without restriction of any kind, provided that the above copyright notice and\nthis paragraph are included on all such copies and derivative works. However, this document itself may\nnot be modified in any way, such as by removing the copyright notice or references to OASIS, except as\nneeded for the purpose of developing OASIS specifications, in which case the procedures for copyrights\ndefined in the OASIS Intellectual Property Rights document must be followed, or as required to translate it\ninto languages other than English.\nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors\nor assigns.\nThis document and the information contained herein is provided on an “AS IS” basis and OASIS\nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY\nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR\nANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.\nsaml-bindings-2.0-os 15 March 2005\nCopyright © OASIS Open 2005. All Rights Reserved. Page 46 of 46\n1725\n1726\n1727\n1728\n1729\n1730\n1731\n1732\n1733\n1734\n1735\n1736\n1737\n1738\n1739\n1740\n1741\n1742\n1743\n1744\n1745\n1746\n1747\n1748\n1749\n1750\n1751","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"SAML2Core","title":"Assertions and Protocols for the OASIS SAML V2.0","source_url":"http://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf","edition":"2.0 (saml-core-2.0-os)","date":"2005-03-15","catalog_entry":{"version":"2.0 (saml-core-2.0-os)","date":"2005-03-15","url":"http://docs.oasis-open.org/security/saml/v2.0/saml-core-2.0-os.pdf","source_digest":"sha256:dc0890f88bfe862c9b39672bed76e2dcb0bedb03491cc41c161aea472b0468ab"},"catalog_correction_pending":false,"raw_pdf_sha256":"dc0890f88bfe862c9b39672bed76e2dcb0bedb03491cc41c161aea472b0468ab","notice_page":86,"notice_text_sha256":"c230ac4b8e676c2c2053346b73cb376dd40d5b7f76aada9921bba55162fc9d56","notice_text":"Appendix B. Notices\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that\nmight be claimed to pertain to the implementation or use of the technology described in this document or\nthe extent to which any license under such rights might or might not be available; neither does it represent\nthat it has made any effort to identify any such rights. Information on OASIS's procedures with respect to\nrights in OASIS specifications can be found at the OASIS website. Copies of claims of rights made\navailable for publication and any assurances of licenses to be made available, or the result of an attempt\nmade to obtain a general license or permission for the use of such proprietary rights by implementors or\nusers of this specification, can be obtained from the OASIS Executive Director.\nOASIS invites any interested party to bring to its attention any copyrights, patents or patent applications, or\nother proprietary rights which may cover technology that may be required to implement this specification.\nPlease address the information to the OASIS Executive Director.\nCopyright © OASIS Open 2005. All Rights Reserved.\nThis document and translations of it may be copied and furnished to others, and derivative works that\ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published and\ndistributed, in whole or in part, without restriction of any kind, provided that the above copyright notice and\nthis paragraph are included on all such copies and derivative works. However, this document itself may\nnot be modified in any way, such as by removing the copyright notice or references to OASIS, except as\nneeded for the purpose of developing OASIS specifications, in which case the procedures for copyrights\ndefined in the OASIS Intellectual Property Rights document must be followed, or as required to translate it\ninto languages other than English.\nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors\nor assigns.\nThis document and the information contained herein is provided on an “AS IS” basis and OASIS\nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY\nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR\nANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.\nsaml-core-2.0-os 15 March 2005\nCopyright © OASIS Open 2005. All Rights Reserved. Page 86 of 86\n3569\n3570\n3571\n3572\n3573\n3574\n3575\n3576\n3577\n3578\n3579\n3580\n3581\n3582\n3583\n3584\n3585\n3586\n3587\n3588\n3589\n3590\n3591\n3592\n3593\n3594\n3595\n171\n172","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"SAML2ECP","title":"SAML V2.0 Enhanced Client or Proxy Profile","source_url":"http://docs.oasis-open.org/security/saml/Post2.0/saml-ecp/v2.0/cs01/saml-ecp-v2.0-cs01.pdf","edition":"2.0 (cs01)","date":"2013-08-26","catalog_entry":{"version":"2.0 (cs01)","date":"2013-08-01","url":"http://docs.oasis-open.org/security/saml/Post2.0/saml-ecp/v2.0/cs01/saml-ecp-v2.0-cs01.pdf","source_digest":"sha256:9195b6bb98b3fe8f4dd532fa967e49c29c81ba519421afbfc6b85bbfd17f576a"},"catalog_correction_pending":true,"raw_pdf_sha256":"9195b6bb98b3fe8f4dd532fa967e49c29c81ba519421afbfc6b85bbfd17f576a","notice_page":3,"notice_text_sha256":"0b656585a813d3594c435e26487f43ff49156a85ce5fa8e7d0170db17e642afb","notice_text":"Notices\nCopyright © OASIS Open 2013. All Rights Reserved.\nAll capitalized terms in the following text have the meanings assigned to them in the OASIS Intellectual \nProperty Rights Policy (the \"OASIS IPR Policy\"). The full Policy may be found at the OASIS website.\nThis document and translations of it may be copied and furnished to others, and derivative works that \ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published, \nand distributed, in whole or in part, without restriction of any kind, provided that the above copyright notice \nand this section are included on all such copies and derivative works. However, this document itself may \nnot be modified in any way, including by removing the copyright notice or references to OASIS, except as \nneeded for the purpose of developing any document or deliverable produced by an OASIS Technical \nCommittee (in which case the rules applicable to copyrights, as set forth in the OASIS IPR Policy, must \nbe followed) or as required to translate it into languages other than English.\nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors \nor assigns.\nThis document and the information contained herein is provided on an \"AS IS\" basis and OASIS \nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY \nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY \nOWNERSHIP RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A \nPARTICULAR PURPOSE.\nOASIS requests that any OASIS Party or any other party that believes it has patent claims that would \nnecessarily be infringed by implementations of this OASIS Committee Specification or OASIS Standard, \nto notify OASIS TC Administrator and provide an indication of its willingness to grant patent licenses to \nsuch patent claims in a manner consistent with the IPR Mode of the OASIS Technical Committee that \nproduced this specification.\nOASIS invites any party to contact the OASIS TC Administrator if it is aware of a claim of ownership of \nany patent claims that would necessarily be infringed by implementations of this specification by a patent \nholder that is not willing to provide a license to such patent claims in a manner consistent with the IPR \nMode of the OASIS Technical Committee that produced this specification. OASIS may include such \nclaims on its website, but disclaims any obligation to do so.\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that \nmight be claimed to pertain to the implementation or use of the technology described in this document or \nthe extent to which any license under such rights might or might not be available; neither does it represent \nthat it has made any effort to identify any such rights. Information on OASIS' procedures with respect to \nrights in any document or deliverable produced by an OASIS Technical Committee can be found on the \nOASIS website. Copies of claims of rights made available for publication and any assurances of licenses \nto be made available, or the result of an attempt made to obtain a general license or permission for the \nuse of such proprietary rights by implementers or users of this OASIS Committee Specification or OASIS \nStandard, can be obtained from the OASIS TC Administrator. OASIS makes no representation that any \ninformation or list of intellectual property rights will at any time be complete, or that any claims in such list \nare, in fact, Essential Claims.\nThe name \"OASIS\" is a trademark of OASIS, the owner and developer of this specification, and should be \nused only to refer to the organization and its official outputs. OASIS welcomes reference to, and \nimplementation and use of, specifications, while reserving the right to enforce its marks against \nmisleading uses. Please see http://www.oasis-open.org/policies-guidelines/trademark for above guidance.\nsaml-ecp-v2.0-cs01 26 August 2013\nStandards Track Work Product Copyright © OASIS Open 2013. All Rights Reserved. Page 3 of 24","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"SAML2Errata","title":"SAML Version 2.0 Errata 05","source_url":"https://docs.oasis-open.org/security/saml/v2.0/errata05/os/saml-v2.0-errata05-os.pdf","edition":"Errata 05","date":"2012-05-01","catalog_entry":{"version":"Errata 05","date":"2012-05-01","url":"https://docs.oasis-open.org/security/saml/v2.0/errata05/os/saml-v2.0-errata05-os.pdf","source_digest":"sha256:c9f6d7c4d6b147066a24715076ac8b62269429fae8e27d53a03cf0d73651ace3"},"catalog_correction_pending":false,"raw_pdf_sha256":"c9f6d7c4d6b147066a24715076ac8b62269429fae8e27d53a03cf0d73651ace3","notice_page":3,"notice_text_sha256":"cb2a6bc2e2a3c28442b5a3bacb0678765bba8c52832983a8f65a7fd9a084b128","notice_text":"Notices\nCopyright © OASIS Open 2012. All Rights Reserved.\nAll capitalized terms in the following text have the meanings assigned to them in the OASIS Intellectual \nProperty Rights Policy (the \"OASIS IPR Policy\"). The full Policy may be found at the OASIS website.\nThis document and translations of it may be copied and furnished to others, and derivative works that \ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published, \nand distributed, in whole or in part, without restriction of any kind, provided that the above copyright notice \nand this section are included on all such copies and derivative works. However, this document itself may \nnot be modified in any way, including by removing the copyright notice or references to OASIS, except as \nneeded for the purpose of developing any document or deliverable produced by an OASIS Technical \nCommittee (in which case the rules applicable to copyrights, as set forth in the OASIS IPR Policy, must \nbe followed) or as required to translate it into languages other than English.\nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors \nor assigns.\nThis document and the information contained herein is provided on an \"AS IS\" basis and OASIS \nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY \nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY \nOWNERSHIP RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A \nPARTICULAR PURPOSE.\nOASIS requests that any OASIS Party or any other party that believes it has patent claims that would \nnecessarily be infringed by implementations of this OASIS Committee Specification or OASIS Standard, \nto notify OASIS TC Administrator and provide an indication of its willingness to grant patent licenses to \nsuch patent claims in a manner consistent with the IPR Mode of the OASIS Technical Committee that \nproduced this specification.\nOASIS invites any party to contact the OASIS TC Administrator if it is aware of a claim of ownership of \nany patent claims that would necessarily be infringed by implementations of this specification by a patent \nholder that is not willing to provide a license to such patent claims in a manner consistent with the IPR \nMode of the OASIS Technical Committee that produced this specification. OASIS may include such \nclaims on its website, but disclaims any obligation to do so.\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that \nmight be claimed to pertain to the implementation or use of the technology described in this document or \nthe extent to which any license under such rights might or might not be available; neither does it represent \nthat it has made any effort to identify any such rights. Information on OASIS' procedures with respect to \nrights in any document or deliverable produced by an OASIS Technical Committee can be found on the \nOASIS website. Copies of claims of rights made available for publication and any assurances of licenses \nto be made available, or the result of an attempt made to obtain a general license or permission for the \nuse of such proprietary rights by implementers or users of this OASIS Committee Specification or OASIS \nStandard, can be obtained from the OASIS TC Administrator. OASIS makes no representation that any \ninformation or list of intellectual property rights will at any time be complete, or that any claims in such list \nare, in fact, Essential Claims.\nThe name \"OASIS\" is a trademark of OASIS, the owner and developer of this specification, and should be \nused only to refer to the organization and its official outputs. OASIS welcomes reference to, and \nimplementation and use of, specifications, while reserving the right to enforce its marks against \nmisleading uses. Please see http://www.oasis-open.org/who/trademark.php for above guidance.\nsaml-v2.0-errata05-os 01 May 2012\nStandards Track Work Product Copyright © OASIS Open 2012. All Rights Reserved. Page 3 of 44","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"SAML2MD-xsd","title":"SAML V2.0 Metadata Schema","source_url":"http://docs.oasis-open.org/security/saml/v2.0/saml-schema-metadata-2.0.xsd","edition":"2.0","date":"2005-03-15","catalog_entry":{"title":"SAML V2.0 Metadata Schema","publisher":"OASIS","version":"2.0","date":"2005-03-15","url":"http://docs.oasis-open.org/security/saml/v2.0/saml-schema-metadata-2.0.xsd","role":"referenced","source_digest":"sha256:204bc7991055dbb889307abbd2ff58022753897dd7064a4d1ca13eb737d2617a"},"raw_source_sha256":"204bc7991055dbb889307abbd2ff58022753897dd7064a4d1ca13eb737d2617a","notice_location":"Catalog reference only; no standalone source file is redistributed.","notice_text":"","notice_text_sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855","notice_status":"REFERENCE_ONLY","publication_status":"GREEN","material_allocation_status":"REFERENCE_OR_INDEPENDENT_IMPLEMENTATION","terms_review_status":"NO_DOCUMENT_REPRODUCTION_PERMISSION_NEEDED","usage_review":"Identifiers, schema element/attribute names and official source references only in catalogs. Schema copies within unmodified dependency JARs are separate inventory items.","catalog_correction_pending":false,"resolved_by_implementation":false},{"id":"SAML2MDIOP","title":"SAML V2.0 Metadata Interoperability Profile","source_url":"https://docs.oasis-open.org/security/saml/Post2.0/sstc-metadata-iop-os.pdf","edition":"1.0 (OS)","date":"2019-10-24","catalog_entry":{"version":"1.0 (CS)","date":"2009-08-01","url":"http://docs.oasis-open.org/security/saml/Post2.0/sstc-metadata-iop.pdf","source_digest":"sha256:66a6f838429feb8fc96bf2d2d2741554bc030107aeb5ea4661d4881538dfe496"},"catalog_correction_pending":true,"raw_pdf_sha256":"66a6f838429feb8fc96bf2d2d2741554bc030107aeb5ea4661d4881538dfe496","notice_page":3,"notice_text_sha256":"4f201d95ba81a6880039f45f13bb92142e319e91cf76ca76ff8e4ad3daf716b2","notice_text":"Notices\nCopyright © OASIS Open 2019. All Rights Reserved.\nAll capitalized terms in the following text have the meanings assigned to them in the OASIS Intellectual \nProperty Rights Policy (the \"OASIS IPR Policy\"). The full Policy may be found at the OASIS website.\nThis document and translations of it may be copied and furnished to others, and derivative works that \ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published, \nand distributed, in whole or in part, without restriction of any kind, provided that the above copyright notice \nand this section are included on all such copies and derivative works. However, this document itself may \nnot be modified in any way, including by removing the copyright notice or references to OASIS, except as \nneeded for the purpose of developing any document or deliverable produced by an OASIS Technical \nCommittee (in which case the rules applicable to copyrights, as set forth in the OASIS IPR Policy, must \nbe followed) or as required to translate it into languages other than English.\nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors \nor assigns.\nThis document and the information contained herein is provided on an \"AS IS\" basis and OASIS \nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY \nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY \nOWNERSHIP RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A \nPARTICULAR PURPOSE.\nOASIS requests that any OASIS Party or any other party that believes it has patent claims that would \nnecessarily be infringed by implementations of this OASIS Committee Specification or OASIS Standard, \nto notify OASIS TC Administrator and provide an indication of its willingness to grant patent licenses to \nsuch patent claims in a manner consistent with the IPR Mode of the OASIS Technical Committee that \nproduced this specification.\nOASIS invites any party to contact the OASIS TC Administrator if it is aware of a claim of ownership of \nany patent claims that would necessarily be infringed by implementations of this specification by a patent \nholder that is not willing to provide a license to such patent claims in a manner consistent with the IPR \nMode of the OASIS Technical Committee that produced this specification. OASIS may include such \nclaims on its website, but disclaims any obligation to do so.\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that \nmight be claimed to pertain to the implementation or use of the technology described in this document or \nthe extent to which any license under such rights might or might not be available; neither does it represent \nthat it has made any effort to identify any such rights. Information on OASIS' procedures with respect to \nrights in any document or deliverable produced by an OASIS Technical Committee can be found on the \nOASIS website. Copies of claims of rights made available for publication and any assurances of licenses \nto be made available, or the result of an attempt made to obtain a general license or permission for the \nuse of such proprietary rights by implementers or users of this OASIS Committee Specification or OASIS \nStandard, can be obtained from the OASIS TC Administrator. OASIS makes no representation that any \ninformation or list of intellectual property rights will at any time be complete, or that any claims in such list \nare, in fact, Essential Claims.\nThe name \"OASIS\" is a trademark of OASIS, the owner and developer of this specification, and should be \nused only to refer to the organization and its official outputs. OASIS welcomes reference to, and \nimplementation and use of, specifications, while reserving the right to enforce its marks against \nmisleading uses. Please see https://www.oasis-open.org/policies-guidelines/trademark for above \nguidance.\nsstc-metadata-iop-os 24 October 2019\nStandards Track Work Product Copyright © OASIS Open 2019. All Rights Reserved. Page 3 of 14","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"SAML2Meta","title":"Metadata for the OASIS SAML V2.0","source_url":"http://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf","edition":"2.0 (saml-metadata-2.0-os)","date":"2005-03-15","catalog_entry":{"version":"2.0 (saml-metadata-2.0-os)","date":"2005-03-15","url":"http://docs.oasis-open.org/security/saml/v2.0/saml-metadata-2.0-os.pdf","source_digest":"sha256:48656c21cc0cf26873ebec6792299de4f71c46ce5df73c707653b4c0b12117ae"},"catalog_correction_pending":false,"raw_pdf_sha256":"48656c21cc0cf26873ebec6792299de4f71c46ce5df73c707653b4c0b12117ae","notice_page":43,"notice_text_sha256":"2877f3d3b6b0146a19c86e77a63ef44ebd324bc98ce62492d5577115bb478bb5","notice_text":"Appendix C. Notices\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that\nmight be claimed to pertain to the implementation or use of the technology described in this document or\nthe extent to which any license under such rights might or might not be available; neither does it represent\nthat it has made any effort to identify any such rights. Information on OASIS's procedures with respect to\nrights in OASIS specifications can be found at the OASIS website. Copies of claims of rights made\navailable for publication and any assurances of licenses to be made available, or the result of an attempt\nmade to obtain a general license or permission for the use of such proprietary rights by implementors or\nusers of this specification, can be obtained from the OASIS Executive Director.\nOASIS invites any interested party to bring to its attention any copyrights, patents or patent applications, or\nother proprietary rights which may cover technology that may be required to implement this specification.\nPlease address the information to the OASIS Executive Director.\nCopyright © OASIS Open 2005. All Rights Reserved.\nThis document and translations of it may be copied and furnished to others, and derivative works that\ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published and\ndistributed, in whole or in part, without restriction of any kind, provided that the above copyright notice and\nthis paragraph are included on all such copies and derivative works. However, this document itself may\nnot be modified in any way, such as by removing the copyright notice or references to OASIS, except as\nneeded for the purpose of developing OASIS specifications, in which case the procedures for copyrights\ndefined in the OASIS Intellectual Property Rights document must be followed, or as required to translate it\ninto languages other than English.\nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors\nor assigns.\nThis document and the information contained herein is provided on an “AS IS” basis and OASIS\nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY\nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR\nANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.\nsaml-metadata-2.0-os 15 March 2005\nCopyright © OASIS Open 2005 All Rights Reserved. Page 43 of 43\n1712\n1713\n1714\n1715\n1716\n1717\n1718\n1719\n1720\n1721\n1722\n1723\n1724\n1725\n1726\n1727\n1728\n1729\n1730\n1731\n1732\n1733\n1734\n1735\n1736\n1737\n1738","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"SAML2MetaAlgSup","title":"SAML V2.0 Metadata Profile for Algorithm Support","source_url":"http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-metadata-algsupport-v1.0-cs01.pdf","edition":"1.0 (cs01)","date":"2011-02-21","catalog_entry":{"version":"1.0 (cs01)","date":"2011-02-01","url":"http://docs.oasis-open.org/security/saml/Post2.0/sstc-saml-metadata-algsupport-v1.0-cs01.pdf","source_digest":"sha256:5f21e73e5d8fb2841a759905468cb27bbdb4637521ecdcb46c0744b1efb76245"},"catalog_correction_pending":true,"raw_pdf_sha256":"5f21e73e5d8fb2841a759905468cb27bbdb4637521ecdcb46c0744b1efb76245","notice_page":3,"notice_text_sha256":"e299218412e4dd2d121d239b3d6a9842422f79699515c9d9bdffd4afc357e12b","notice_text":"Notices\nCopyright © OASIS Open 2011. All Rights Reserved.\nAll capitalized terms in the following text have the meanings assigned to them in the OASIS Intellectual  \nProperty Rights Policy (the \"OASIS IPR Policy\"). The full Policy may be found at the OASIS website.\nThis document and translations of it may be copied and furnished to others, and derivative works that  \ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published,  \nand distributed, in whole or in part, without restriction of any kind, provided that the above copyright  \nnotice and this section are included on all such copies and derivative works. However, this document  \nitself may not be modified in any way, including by removing the copyright notice or references to  \nOASIS, except as needed for the purpose of developing any document or deliverable produced by an  \nOASIS Technical Committee (in which case the rules applicable to copyrights, as set forth in the OASIS  \nIPR Policy, must be followed) or as required to translate it into languages other than English. \nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors  \nor assigns. \nThis document and the information contained herein is provided on an \"AS IS\" basis and OASIS  \nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY  \nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY  \nOWNERSHIP RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR  \nA PARTICULAR PURPOSE. \nOASIS requests that any OASIS Party or any other party that believes it has patent claims that would  \nnecessarily be infringed by implementations of this OASIS Committee Specification or OASIS Standard,  \nto notify OASIS TC Administrator and provide an indication of its willingness to grant patent licenses to  \nsuch patent claims in a manner consistent with the IPR Mode of the OASIS Technical Committee that  \nproduced this specification.\nOASIS invites any party to contact the OASIS TC Administrator if it is aware of a claim of ownership of  \nany patent claims that would necessarily be infringed by implementations of this specification by a patent  \nholder that is not willing to provide a license to such patent claims in a manner consistent with the IPR  \nMode of the OASIS Technical Committee that produced this specification. OASIS may include such  \nclaims on its website, but disclaims any obligation to do so.\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that  \nmight be claimed to pertain to the implementation or use of the technology described in this document or  \nthe extent to which any license under such rights might or might not be available; neither does it  \nrepresent that it has made any effort to identify any such rights. Information on OASIS' procedures with  \nrespect to rights in any document or deliverable produced by an OASIS Technical Committee can be  \nfound on the OASIS website. Copies of claims of rights made available for publication and any  \nassurances of licenses to be made available, or the result of an attempt made to obtain a general license  \nor permission for the use of such proprietary rights by implementers or users of this OASIS Committee  \nSpecification or OASIS Standard, can be obtained from the OASIS TC Administrator. OASIS makes no  \nrepresentation that any information or list of intellectual property rights will at any time be complete, or  \nthat any claims in such list are, in fact, Essential Claims. \nThe names \"OASIS\" and “SAML” are trademarks of OASIS, the owner and developer of this \nspecification, and should be used only to refer to the organization and its official outputs. OASIS  \nwelcomes reference to, and implementation and use of, specifications, while reserving the right to  \nenforce its marks against misleading uses. Please see http://www.oasis-open.org/who/trademark.php for \nabove guidance.\nsstc-saml-metadata-algsupport-v1.0-cs01 21 February 2011\nCopyright © OASIS Open 2011. All Rights Reserved.           Standards Track Work Product Page 3 of 13","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"SAML2P-xsd","title":"SAML V2.0 Protocol Schema","source_url":"http://docs.oasis-open.org/security/saml/v2.0/saml-schema-protocol-2.0.xsd","edition":"2.0","date":"2005-03-15","catalog_entry":{"title":"SAML V2.0 Protocol Schema","publisher":"OASIS","version":"2.0","date":"2005-03-15","url":"http://docs.oasis-open.org/security/saml/v2.0/saml-schema-protocol-2.0.xsd","role":"referenced","source_digest":"sha256:554250583cd5eacc6ce5f094f6ff50fc2547972c436dc96e2e7eb41abf2c817e"},"raw_source_sha256":"554250583cd5eacc6ce5f094f6ff50fc2547972c436dc96e2e7eb41abf2c817e","notice_location":"Catalog reference only; no standalone source file is redistributed.","notice_text":"","notice_text_sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855","notice_status":"REFERENCE_ONLY","publication_status":"GREEN","material_allocation_status":"REFERENCE_OR_INDEPENDENT_IMPLEMENTATION","terms_review_status":"NO_DOCUMENT_REPRODUCTION_PERMISSION_NEEDED","usage_review":"Identifiers, schema element/attribute names and official source references only in catalogs. Schema copies within unmodified dependency JARs are separate inventory items.","catalog_correction_pending":false,"resolved_by_implementation":false},{"id":"SAML2Prof","title":"Profiles for the OASIS SAML V2.0","source_url":"http://docs.oasis-open.org/security/saml/v2.0/saml-profiles-2.0-os.pdf","edition":"2.0 (saml-profiles-2.0-os)","date":"2005-03-15","catalog_entry":{"version":"2.0 (saml-profiles-2.0-os)","date":"2005-03-15","url":"http://docs.oasis-open.org/security/saml/v2.0/saml-profiles-2.0-os.pdf","source_digest":"sha256:5df9b874551941c7f03cb9270e67ea44f426b44a8fa642b8cf261064cc6f7de2"},"catalog_correction_pending":false,"raw_pdf_sha256":"5df9b874551941c7f03cb9270e67ea44f426b44a8fa642b8cf261064cc6f7de2","notice_page":66,"notice_text_sha256":"e81957d493498e87e435e63a30cdd6d0fecf1261385eadcad8553824c7cef0ad","notice_text":"Appendix B. Notices\nOASIS takes no position regarding the validity or scope of any intellectual property or other rights that\nmight be claimed to pertain to the implementation or use of the technology described in this document or\nthe extent to which any license under such rights might or might not be available; neither does it represent\nthat it has made any effort to identify any such rights. Information on OASIS's procedures with respect to\nrights in OASIS specifications can be found at the OASIS website. Copies of claims of rights made\navailable for publication and any assurances of licenses to be made available, or the result of an attempt\nmade to obtain a general license or permission for the use of such proprietary rights by implementors or\nusers of this specification, can be obtained from the OASIS Executive Director.\nOASIS invites any interested party to bring to its attention any copyrights, patents or patent applications, or\nother proprietary rights which may cover technology that may be required to implement this specification.\nPlease address the information to the OASIS Executive Director.\nCopyright © OASIS Open 2005. All Rights Reserved.\nThis document and translations of it may be copied and furnished to others, and derivative works that\ncomment on or otherwise explain it or assist in its implementation may be prepared, copied, published and\ndistributed, in whole or in part, without restriction of any kind, provided that the above copyright notice and\nthis paragraph are included on all such copies and derivative works. However, this document itself may\nnot be modified in any way, such as by removing the copyright notice or references to OASIS, except as\nneeded for the purpose of developing OASIS specifications, in which case the procedures for copyrights\ndefined in the OASIS Intellectual Property Rights document must be followed, or as required to translate it\ninto languages other than English.\nThe limited permissions granted above are perpetual and will not be revoked by OASIS or its successors\nor assigns.\nThis document and the information contained herein is provided on an “AS IS” basis and OASIS\nDISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY\nWARRANTY THAT THE USE OF THE INFORMATION HEREIN WILL NOT INFRINGE ANY RIGHTS OR\nANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.\nsaml-profiles-2.0-os 15 March 2005\nCopyright © OASIS Open 2005. All Rights Reserved. Page 66 of 66\n2291\n2292\n2293\n2294\n2295\n2296\n2297\n2298\n2299\n2300\n2301\n2302\n2303\n2304\n2305\n2306\n2307\n2308\n2309\n2310\n2311\n2312\n2313\n2314\n2315\n2316\n2317","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","resolved_by_implementation":false,"rights_holder":"OASIS and the document contributors"},{"id":"XMLEnc","title":"XML Encryption Syntax and Processing 1.1","source_url":"https://www.w3.org/TR/xmlenc-core1/","edition":"1.1","date":"2013-04-11","catalog_entry":{"version":"1.1","date":"2013-04-11","url":"https://www.w3.org/TR/xmlenc-core1/","source_digest":"sha256:40e83298cc2e53c565bebf8b8345c14edabea77d56a3a3698ca438730afec1ce"},"catalog_correction_pending":false,"raw_source_sha256":"40e83298cc2e53c565bebf8b8345c14edabea77d56a3a3698ca438730afec1ce","notice_location":"Copyright paragraph (HTML markup removed; linked document-use URL retained)","notice_text":"Copyright © 2013 W3C® (MIT, ERCIM, Keio, Beihang), All Rights Reserved. W3C liability, trademark and document use rules apply.\nDocument use rules linked by the adopted document: https://www.w3.org/Consortium/Legal/copyright-documents\n","notice_text_sha256":"892f4a259781bfb5a05d886d4d7bab5aee419995d54e907511680f1de467a4ca","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"REFERENCE_OR_INDEPENDENT_IMPLEMENTATION","terms_review_status":"NO_DOCUMENT_REPRODUCTION_PERMISSION_NEEDED","publication_status":"GREEN","usage_review":"Catalog IDs, technical facts, section selectors and independently written behavior descriptions; no adopted document body is distributed. Embedded library schemas are assessed separately in the dependency inventory.","resolved_by_implementation":false},{"id":"kantara-fedinterop-impl","title":"SAML V2.0 Implementation Profile for Federation Interoperability","source_url":"https://kantarainitiative.github.io/SAMLprofiles/fedinterop.html","edition":"1.1","date":"2019-12-18","catalog_entry":{"version":"1.1","date":"2019-12-18","url":"https://kantarainitiative.github.io/SAMLprofiles/fedinterop.html","source_digest":"sha256:6cbc97a652651d6a5cff26a41c51195b8b914ed59dc63ed1d6ce254e88edd13d"},"catalog_correction_pending":false,"raw_source_sha256":"6cbc97a652651d6a5cff26a41c51195b8b914ed59dc63ed1d6ce254e88edd13d","notice_location":"Copyright Notice and License sections","notice_text_sha256":"a11cf99bc4101872fd02a53d617fc64c576b64d40362a3c8d8aee596aa4e7d6b","notice_text":"SAML v2.0 Implementation Profile for Federation Interoperability ©2017 Internet2 and/or the respective contributors, used under license.  All rights reserved.\n\nThis work is licensed under the Creative Commons Attribution-ShareAlike 3.0 United States License.\nhttps://creativecommons.org/licenses/by-sa/3.0/us/\n\nContributors credited by the original document: Walter Hoehn (editor), Scott Cantor, Rainer Hörbe, Tom Scavo, Eric Goodman, Brett Bieber, Nick Roy, Barry Ribbeck, Judith E. Bush, Mike Grady.\nSAMLscope adapts and organizes the requirements; this is not an unmodified specification.\n","license_url":"https://creativecommons.org/licenses/by-sa/3.0/us/","notice_status":"RETAINED_SOURCE_TEXT","material_allocation_status":"QUOTATION_OR_IMPLEMENTATION_COMMENTARY","publication_status":"YELLOW","terms_review_status":"APPLICABLE_DOCUMENT_PERMISSION_CONFIRMED","usage_review":"Requirement summaries, test instructions and source-comparison explanations incorporate source expression. Retain this document-specific notice, source/title/version and modification attribution in redistributable copies.","adaptation_license":"CC-BY-SA-4.0 (CC BY-SA 3.0 US section 4(b) permits a later same-elements license; original source stays CC BY-SA 3.0 US)","contributors":["Walter Hoehn (editor)","Scott Cantor","Rainer Hörbe","Tom Scavo","Eric Goodman","Brett Bieber","Nick Roy","Barry Ribbeck","Judith E. Bush","Mike Grady"],"extraction_note":"Original copyright/license notice plus the original contributor credits and a clearly identified SAMLscope modification statement.","resolved_by_implementation":true,"rights_holder":"Internet2 and named contributors"}],"unresolvedSources":[],"originalContentLicense":"CC-BY-SA-4.0 (SAMLscope-owned contributions only)","originalContentAttribution":"SAMLscope contributors; https://github.com/sgrastar/SAMLscope; identify your changes","originalContentLicenseText":"Attribution-ShareAlike 4.0 International\n\n=======================================================================\n\nCreative Commons Corporation (\"Creative Commons\") is not a law firm and\ndoes not provide legal services or legal advice. Distribution of\nCreative Commons public licenses does not create a lawyer-client or\nother relationship. Creative Commons makes its licenses and related\ninformation available on an \"as-is\" basis. Creative Commons gives no\nwarranties regarding its licenses, any material licensed under their\nterms and conditions, or any related information. Creative Commons\ndisclaims all liability for damages resulting from their use to the\nfullest extent possible.\n\nUsing Creative Commons Public Licenses\n\nCreative Commons public licenses provide a standard set of terms and\nconditions that creators and other rights holders may use to share\noriginal works of authorship and other material subject to copyright\nand certain other rights specified in the public license below. The\nfollowing considerations are for informational purposes only, are not\nexhaustive, and do not form part of our licenses.\n\n     Considerations for licensors: Our public licenses are\n     intended for use by those authorized to give the public\n     permission to use material in ways otherwise restricted by\n     copyright and certain other rights. Our licenses are\n     irrevocable. Licensors should read and understand the terms\n     and conditions of the license they choose before applying it.\n     Licensors should also secure all rights necessary before\n     applying our licenses so that the public can reuse the\n     material as expected. Licensors should clearly mark any\n     material not subject to the license. This includes other CC-\n     licensed material, or material used under an exception or\n     limitation to copyright. More considerations for licensors:\n    wiki.creativecommons.org/Considerations_for_licensors\n\n     Considerations for the public: By using one of our public\n     licenses, a licensor grants the public permission to use the\n     licensed material under specified terms and conditions. If\n     the licensor's permission is not necessary for any reason--for\n     example, because of any applicable exception or limitation to\n     copyright--then that use is not regulated by the license. Our\n     licenses grant only permissions under copyright and certain\n     other rights that a licensor has authority to grant. Use of\n     the licensed material may still be restricted for other\n     reasons, including because others have copyright or other\n     rights in the material. A licensor may make special requests,\n     such as asking that all changes be marked or described.\n     Although not required by our licenses, you are encouraged to\n     respect those requests where reasonable. More considerations\n     for the public:\n    wiki.creativecommons.org/Considerations_for_licensees\n\n=======================================================================\n\nCreative Commons Attribution-ShareAlike 4.0 International Public\nLicense\n\nBy exercising the Licensed Rights (defined below), You accept and agree\nto be bound by the terms and conditions of this Creative Commons\nAttribution-ShareAlike 4.0 International Public License (\"Public\nLicense\"). To the extent this Public License may be interpreted as a\ncontract, You are granted the Licensed Rights in consideration of Your\nacceptance of these terms and conditions, and the Licensor grants You\nsuch rights in consideration of benefits the Licensor receives from\nmaking the Licensed Material available under these terms and\nconditions.\n\n\nSection 1 -- Definitions.\n\n  a. Adapted Material means material subject to Copyright and Similar\n     Rights that is derived from or based upon the Licensed Material\n     and in which the Licensed Material is translated, altered,\n     arranged, transformed, or otherwise modified in a manner requiring\n     permission under the Copyright and Similar Rights held by the\n     Licensor. For purposes of this Public License, where the Licensed\n     Material is a musical work, performance, or sound recording,\n     Adapted Material is always produced where the Licensed Material is\n     synched in timed relation with a moving image.\n\n  b. Adapter's License means the license You apply to Your Copyright\n     and Similar Rights in Your contributions to Adapted Material in\n     accordance with the terms and conditions of this Public License.\n\n  c. BY-SA Compatible License means a license listed at\n     creativecommons.org/compatiblelicenses, approved by Creative\n     Commons as essentially the equivalent of this Public License.\n\n  d. Copyright and Similar Rights means copyright and/or similar rights\n     closely related to copyright including, without limitation,\n     performance, broadcast, sound recording, and Sui Generis Database\n     Rights, without regard to how the rights are labeled or\n     categorized. For purposes of this Public License, the rights\n     specified in Section 2(b)(1)-(2) are not Copyright and Similar\n     Rights.\n\n  e. Effective Technological Measures means those measures that, in the\n     absence of proper authority, may not be circumvented under laws\n     fulfilling obligations under Article 11 of the WIPO Copyright\n     Treaty adopted on December 20, 1996, and/or similar international\n     agreements.\n\n  f. Exceptions and Limitations means fair use, fair dealing, and/or\n     any other exception or limitation to Copyright and Similar Rights\n     that applies to Your use of the Licensed Material.\n\n  g. License Elements means the license attributes listed in the name\n     of a Creative Commons Public License. The License Elements of this\n     Public License are Attribution and ShareAlike.\n\n  h. Licensed Material means the artistic or literary work, database,\n     or other material to which the Licensor applied this Public\n     License.\n\n  i. Licensed Rights means the rights granted to You subject to the\n     terms and conditions of this Public License, which are limited to\n     all Copyright and Similar Rights that apply to Your use of the\n     Licensed Material and that the Licensor has authority to license.\n\n  j. Licensor means the individual(s) or entity(ies) granting rights\n     under this Public License.\n\n  k. Share means to provide material to the public by any means or\n     process that requires permission under the Licensed Rights, such\n     as reproduction, public display, public performance, distribution,\n     dissemination, communication, or importation, and to make material\n     available to the public including in ways that members of the\n     public may access the material from a place and at a time\n     individually chosen by them.\n\n  l. Sui Generis Database Rights means rights other than copyright\n     resulting from Directive 96/9/EC of the European Parliament and of\n     the Council of 11 March 1996 on the legal protection of databases,\n     as amended and/or succeeded, as well as other essentially\n     equivalent rights anywhere in the world.\n\n  m. You means the individual or entity exercising the Licensed Rights\n     under this Public License. Your has a corresponding meaning.\n\n\nSection 2 -- Scope.\n\n  a. License grant.\n\n       1. Subject to the terms and conditions of this Public License,\n          the Licensor hereby grants You a worldwide, royalty-free,\n          non-sublicensable, non-exclusive, irrevocable license to\n          exercise the Licensed Rights in the Licensed Material to:\n\n            a. reproduce and Share the Licensed Material, in whole or\n               in part; and\n\n            b. produce, reproduce, and Share Adapted Material.\n\n       2. Exceptions and Limitations. For the avoidance of doubt, where\n          Exceptions and Limitations apply to Your use, this Public\n          License does not apply, and You do not need to comply with\n          its terms and conditions.\n\n       3. Term. The term of this Public License is specified in Section\n          6(a).\n\n       4. Media and formats; technical modifications allowed. The\n          Licensor authorizes You to exercise the Licensed Rights in\n          all media and formats whether now known or hereafter created,\n          and to make technical modifications necessary to do so. The\n          Licensor waives and/or agrees not to assert any right or\n          authority to forbid You from making technical modifications\n          necessary to exercise the Licensed Rights, including\n          technical modifications necessary to circumvent Effective\n          Technological Measures. For purposes of this Public License,\n          simply making modifications authorized by this Section 2(a)\n          (4) never produces Adapted Material.\n\n       5. Downstream recipients.\n\n            a. Offer from the Licensor -- Licensed Material. Every\n               recipient of the Licensed Material automatically\n               receives an offer from the Licensor to exercise the\n               Licensed Rights under the terms and conditions of this\n               Public License.\n\n            b. Additional offer from the Licensor -- Adapted Material.\n               Every recipient of Adapted Material from You\n               automatically receives an offer from the Licensor to\n               exercise the Licensed Rights in the Adapted Material\n               under the conditions of the Adapter's License You apply.\n\n            c. No downstream restrictions. You may not offer or impose\n               any additional or different terms or conditions on, or\n               apply any Effective Technological Measures to, the\n               Licensed Material if doing so restricts exercise of the\n               Licensed Rights by any recipient of the Licensed\n               Material.\n\n       6. No endorsement. Nothing in this Public License constitutes or\n          may be construed as permission to assert or imply that You\n          are, or that Your use of the Licensed Material is, connected\n          with, or sponsored, endorsed, or granted official status by,\n          the Licensor or others designated to receive attribution as\n          provided in Section 3(a)(1)(A)(i).\n\n  b. Other rights.\n\n       1. Moral rights, such as the right of integrity, are not\n          licensed under this Public License, nor are publicity,\n          privacy, and/or other similar personality rights; however, to\n          the extent possible, the Licensor waives and/or agrees not to\n          assert any such rights held by the Licensor to the limited\n          extent necessary to allow You to exercise the Licensed\n          Rights, but not otherwise.\n\n       2. Patent and trademark rights are not licensed under this\n          Public License.\n\n       3. To the extent possible, the Licensor waives any right to\n          collect royalties from You for the exercise of the Licensed\n          Rights, whether directly or through a collecting society\n          under any voluntary or waivable statutory or compulsory\n          licensing scheme. In all other cases the Licensor expressly\n          reserves any right to collect such royalties.\n\n\nSection 3 -- License Conditions.\n\nYour exercise of the Licensed Rights is expressly made subject to the\nfollowing conditions.\n\n  a. Attribution.\n\n       1. If You Share the Licensed Material (including in modified\n          form), You must:\n\n            a. retain the following if it is supplied by the Licensor\n               with the Licensed Material:\n\n                 i. identification of the creator(s) of the Licensed\n                    Material and any others designated to receive\n                    attribution, in any reasonable manner requested by\n                    the Licensor (including by pseudonym if\n                    designated);\n\n                ii. a copyright notice;\n\n               iii. a notice that refers to this Public License;\n\n                iv. a notice that refers to the disclaimer of\n                    warranties;\n\n                 v. a URI or hyperlink to the Licensed Material to the\n                    extent reasonably practicable;\n\n            b. indicate if You modified the Licensed Material and\n               retain an indication of any previous modifications; and\n\n            c. indicate the Licensed Material is licensed under this\n               Public License, and include the text of, or the URI or\n               hyperlink to, this Public License.\n\n       2. You may satisfy the conditions in Section 3(a)(1) in any\n          reasonable manner based on the medium, means, and context in\n          which You Share the Licensed Material. For example, it may be\n          reasonable to satisfy the conditions by providing a URI or\n          hyperlink to a resource that includes the required\n          information.\n\n       3. If requested by the Licensor, You must remove any of the\n          information required by Section 3(a)(1)(A) to the extent\n          reasonably practicable.\n\n  b. ShareAlike.\n\n     In addition to the conditions in Section 3(a), if You Share\n     Adapted Material You produce, the following conditions also apply.\n\n       1. The Adapter's License You apply must be a Creative Commons\n          license with the same License Elements, this version or\n          later, or a BY-SA Compatible License.\n\n       2. You must include the text of, or the URI or hyperlink to, the\n          Adapter's License You apply. You may satisfy this condition\n          in any reasonable manner based on the medium, means, and\n          context in which You Share Adapted Material.\n\n       3. You may not offer or impose any additional or different terms\n          or conditions on, or apply any Effective Technological\n          Measures to, Adapted Material that restrict exercise of the\n          rights granted under the Adapter's License You apply.\n\n\nSection 4 -- Sui Generis Database Rights.\n\nWhere the Licensed Rights include Sui Generis Database Rights that\napply to Your use of the Licensed Material:\n\n  a. for the avoidance of doubt, Section 2(a)(1) grants You the right\n     to extract, reuse, reproduce, and Share all or a substantial\n     portion of the contents of the database;\n\n  b. if You include all or a substantial portion of the database\n     contents in a database in which You have Sui Generis Database\n     Rights, then the database in which You have Sui Generis Database\n     Rights (but not its individual contents) is Adapted Material,\n     including for purposes of Section 3(b); and\n\n  c. You must comply with the conditions in Section 3(a) if You Share\n     all or a substantial portion of the contents of the database.\n\nFor the avoidance of doubt, this Section 4 supplements and does not\nreplace Your obligations under this Public License where the Licensed\nRights include other Copyright and Similar Rights.\n\n\nSection 5 -- Disclaimer of Warranties and Limitation of Liability.\n\n  a. UNLESS OTHERWISE SEPARATELY UNDERTAKEN BY THE LICENSOR, TO THE\n     EXTENT POSSIBLE, THE LICENSOR OFFERS THE LICENSED MATERIAL AS-IS\n     AND AS-AVAILABLE, AND MAKES NO REPRESENTATIONS OR WARRANTIES OF\n     ANY KIND CONCERNING THE LICENSED MATERIAL, WHETHER EXPRESS,\n     IMPLIED, STATUTORY, OR OTHER. THIS INCLUDES, WITHOUT LIMITATION,\n     WARRANTIES OF TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR\n     PURPOSE, NON-INFRINGEMENT, ABSENCE OF LATENT OR OTHER DEFECTS,\n     ACCURACY, OR THE PRESENCE OR ABSENCE OF ERRORS, WHETHER OR NOT\n     KNOWN OR DISCOVERABLE. WHERE DISCLAIMERS OF WARRANTIES ARE NOT\n     ALLOWED IN FULL OR IN PART, THIS DISCLAIMER MAY NOT APPLY TO YOU.\n\n  b. TO THE EXTENT POSSIBLE, IN NO EVENT WILL THE LICENSOR BE LIABLE\n     TO YOU ON ANY LEGAL THEORY (INCLUDING, WITHOUT LIMITATION,\n     NEGLIGENCE) OR OTHERWISE FOR ANY DIRECT, SPECIAL, INDIRECT,\n     INCIDENTAL, CONSEQUENTIAL, PUNITIVE, EXEMPLARY, OR OTHER LOSSES,\n     COSTS, EXPENSES, OR DAMAGES ARISING OUT OF THIS PUBLIC LICENSE OR\n     USE OF THE LICENSED MATERIAL, EVEN IF THE LICENSOR HAS BEEN\n     ADVISED OF THE POSSIBILITY OF SUCH LOSSES, COSTS, EXPENSES, OR\n     DAMAGES. WHERE A LIMITATION OF LIABILITY IS NOT ALLOWED IN FULL OR\n     IN PART, THIS LIMITATION MAY NOT APPLY TO YOU.\n\n  c. The disclaimer of warranties and limitation of liability provided\n     above shall be interpreted in a manner that, to the extent\n     possible, most closely approximates an absolute disclaimer and\n     waiver of all liability.\n\n\nSection 6 -- Term and Termination.\n\n  a. This Public License applies for the term of the Copyright and\n     Similar Rights licensed here. However, if You fail to comply with\n     this Public License, then Your rights under this Public License\n     terminate automatically.\n\n  b. Where Your right to use the Licensed Material has terminated under\n     Section 6(a), it reinstates:\n\n       1. automatically as of the date the violation is cured, provided\n          it is cured within 30 days of Your discovery of the\n          violation; or\n\n       2. upon express reinstatement by the Licensor.\n\n     For the avoidance of doubt, this Section 6(b) does not affect any\n     right the Licensor may have to seek remedies for Your violations\n     of this Public License.\n\n  c. For the avoidance of doubt, the Licensor may also offer the\n     Licensed Material under separate terms or conditions or stop\n     distributing the Licensed Material at any time; however, doing so\n     will not terminate this Public License.\n\n  d. Sections 1, 5, 6, 7, and 8 survive termination of this Public\n     License.\n\n\nSection 7 -- Other Terms and Conditions.\n\n  a. The Licensor shall not be bound by any additional or different\n     terms or conditions communicated by You unless expressly agreed.\n\n  b. Any arrangements, understandings, or agreements regarding the\n     Licensed Material not stated herein are separate from and\n     independent of the terms and conditions of this Public License.\n\n\nSection 8 -- Interpretation.\n\n  a. For the avoidance of doubt, this Public License does not, and\n     shall not be interpreted to, reduce, limit, restrict, or impose\n     conditions on any use of the Licensed Material that could lawfully\n     be made without permission under this Public License.\n\n  b. To the extent possible, if any provision of this Public License is\n     deemed unenforceable, it shall be automatically reformed to the\n     minimum extent necessary to make it enforceable. If the provision\n     cannot be reformed, it shall be severed from this Public License\n     without affecting the enforceability of the remaining terms and\n     conditions.\n\n  c. No term or condition of this Public License will be waived and no\n     failure to comply consented to unless expressly agreed to by the\n     Licensor.\n\n  d. Nothing in this Public License constitutes or may be interpreted\n     as a limitation upon, or waiver of, any privileges and immunities\n     that apply to the Licensor or You, including from the legal\n     processes of any jurisdiction or authority.\n\n\n=======================================================================\n\nCreative Commons is not a party to its public\nlicenses. Notwithstanding, Creative Commons may elect to apply one of\nits public licenses to material it publishes and in those instances\nwill be considered the “Licensor.” The text of the Creative Commons\npublic licenses is dedicated to the public domain under the CC0 Public\nDomain Dedication. Except for the limited purpose of indicating that\nmaterial is shared under a Creative Commons public license or as\notherwise permitted by the Creative Commons policies published at\ncreativecommons.org/policies, Creative Commons does not authorize the\nuse of the trademark \"Creative Commons\" or any other trademark or logo\nof Creative Commons without its prior written consent including,\nwithout limitation, in connection with any unauthorized modifications\nto any of its public licenses or any other arrangements,\nunderstandings, or agreements concerning use of licensed material. For\nthe avoidance of doubt, this paragraph does not form part of the\npublic licenses.\n\nCreative Commons may be contacted at creativecommons.org.\n\n","reviewStatus":"Source notices and modification credits are retained for incorporated material. Reference-only sources do not require document reproduction permission."}}
