Skip to content

FAL2 - Section 4.7 requires the use of the auth_time claim #89

@deansaxe

Description

@deansaxe

Section 4.7 in SP800-63C Rev4 draft states:

The IdP SHALL communicate to the RP any information the IdP has regarding the time of the subscriber’s latest authentication event at the IdP, and the RP MAY use this information in making authorization and access decisions.

IPSIE SL1 should make the auth_time claim required in the id token to resolve this gap.

Metadata

Metadata

Assignees

Labels

FAL2Issues related to FAL2 compliancesl1

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions