[Prev]

2.6 Compliance Requirements for Service Requesters

CR61-DNS

Service Requester MUST use DNS to resolve names. This requirement facilitates configuration and provides a load balancing method (round robin DNS) for the SPs. DNS query results MUST NOT be cached beyond their TTL.

CR65-MDExp

Service Requester MUST implement Well-Known Location (WKL) method of metadata export, see [SAML2meta] section 4.1 "Publication and Resolution via Well-Known Location", p.29, for normative description of this method.

CR66-MDImp

Service Requester MUST implement Well-Known Location (WKL) method of metadata import, see [SAML2meta] section 4.1 "Publication and Resolution via Well-Known Location", p.29, for normative description of this method. The Import MUST NOT unintentionally lead to a trust relationship.

CR67-VfyAn

Service Requester MUST authenticate the Service Provider according to CR216-EntAn.

CR68-An

Service Requester MUST authenticate itself to the Service Provider according to CR216-EntAn.


[Prev | Next]