canada-ca / canada-ca/CATS-STAE
CATSV2 Rel 8.4 - Service Providers SOAP binding for reception of <saml2p:LogoutRequest>
- Dominant language
- Shell
- Stars
- 16
- Forks
- 1
- PR merge metrics
- No merged PRs in 30d
Description
Hi, CATSV2 Rel 8.4, egov 2.8.1.1 requires Service Providers that cannot support the SOAP binding for reception of MUST nevertheless include a for the SOAP binding in their Service Provider metadata AND discuss the resulting implications in a Security Assessment, and Privacy Impact Assessment.
The egov 2.8.1.1 makes an exception for the Sign In Canada Acceptance Platform which MUST only support the HTTP-Redirect binding for the reception of messages.
With the Sign In Canada platform operating as an SP with the existing CSPs on the GCCF Federation, should it not be subject to the same rules?
Not implementing a SOAP binding for reception of the will expose other SPs on the GCCF Federation at risks as they are relying on the CSPs to return a partial global logout response when one of the SP SOAP end point fails to process a logout request.
And would the Sign In Canada acting as an SP on the GCCF Federation not be subject to discuss the resulting implications in a Security Assessment, and Privacy Impact Assessment?
Thanks
Contributor guide
Research direction
Start by reviewing the CATSV2 Rel 8.4 and egov 2.8.1.1 requirements for SAML LogoutRequest bindings, then compare them with Sign In Canada's SP metadata and the existing CSPs on the GCCF Federation. Confirm whether SOAP reception and the Security Assessment and Privacy Impact Assessment implications are required; done means the policy question and resulting implementation scope are documented.
Written by the indexing model from the issue text.
Assessment
- Domain
- authentication, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100