Search Criteria : 5 assertions found for this search Review filtered assertions

Assertion

Applies to

Applied to
Not applied to

Coverage

Covered by
Not covered by
Id scheme
Assertion id
Status
Testable?
#Coverage
#Applies to
Comment
Predicate
Page
Tags
Last changed
Actions
ITI40ITI40-038reviewedTestable 1 3 The X-Service Provider shall validate the X-User Assertion by processing the Web-Services Security header in accordance with the Web-Services Security Standard, and SAML 2.0 Standard processing rules155Section 3.40.4.1.32/15/17 6:00:11 PM by ceoche
ITI40ITI40-039reviewedTestable 1 3 If the validation of the X-User assertion performed by the X-Service Provider fails, the actor grouped with the X-Service Provider (ie the one performing the underlying web services transaction), shall return with an error code as described in WS-Security core specification Section 12 (Error Handling, using the SOAP Fault mechanism),155Section 3.40.4.1.32/15/17 6:00:11 PM by ceoche
ITI40ITI40-040reviewedTestable 1 3 If the validation of the X-User assertion performed by the X-Service Provider fails, the X-Service Provder shall send an ATNA Audit Message for Authentication Failure.155Section 3.40.4.1.32/15/17 6:00:11 PM by ceoche
ITI40ITI40-049reviewedTestable 3 3 When an ATNA Audit message needs to be generated and the user is authenticated by way of an X-User Assertion, the ATNA Audit message UserNameelement shall record the X-User Assertion using the following encoding: alias"<"user"@"issuer">" where: • alias is the optional string within the SAML Assertion's Subject element SPProvidedID attribute • user is the required content of the SAML Assertion's Subject element156Section 3.40.4.22/15/17 6:00:11 PM by ceoche
ITI40ITI40-050reviewedTestable 3 3 When an ATNA Audit message needs to be generated and the user is authenticated by way of an X-User Assertion, the ATNA Audit message UserNameelement shall record the X-User Assertion using the following encoding: alias"<"user"@"issuer">" where: • alias is the optional string within the SAML Assertion's Subject element SPProvidedID attribute • user is the required content of the SAML Assertion's Subject element • issuer is the X-Assertion Provider entity ID contained with the content of SAML Assertion's Issuer element156Section 3.40.4.22/15/17 6:00:11 PM by ceoche