I3:FeatureTest-Selector Support for RequireStrongRecipientIdentity

From OSIS Open Source Identity Systems

Jump to: navigation, search

   list help  copy  as XML  edit
Feature Test   Selector Support for RequireStrongRecipientIdentity
Test Type   Card Usage
Identifier   FTI3-iis-cardusage-m1  
Description   Tests selector's ability to refuse to serve Relying Parties using HTTP when RequireStrongRecipientIdentity is present in the card  
Role tested   Information Card Identity Selector  
Known Successful Reference Solution(s)  
I3:CardSpace .NET Framework 3.5  
Success Criteria   Card usable at an https site but can not be selected to use at an http site  
Failure Criteria   Card not usable at https site or can be used at an http site  

Features Proven

Feature feature_type solution_role
Enforcement of IdP choice to limit use of Card to only sites with SSL Information Card Identity Selector interop
  1. Open the result page for your solution and for this test
  2. Install an HTTPS-only card either by importing the "I3 Echo HTTPS Only" card from the file Image:I3 echo sts cards.crds using the password "i3_echo_sts_cards" or from the drop-down menu at the site https://ipsts.federatedidentity.net/MgmtConsole/TestAccount.aspx?cardType=echoCard .
  3. Visit http://relyingparty.federatedidentity.net/CardSelectorRP/login.aspx and click the icon to submit a card. Verify that the card is not selectable.
  4. Visit https://relyingparty.federatedidentity.net/CardSelectorRP/login.aspx and click the icon to submit a card. Verify that the card is selectable and submit the card using the username "testclient" and password "testpassword".
  5. Set outcome:
    1. If the card was usable at an https site but can not be selected to use at an http site, set the outcome to Works
    2. If the card was not usable at the https site or can be used at an http site, set the outcome to Failed and enter information about the failure in the Notes section.
    3. If other issues occurred set the result to Issues and describe them in the Notes section.
  6. Add either four tilde ~~~~ signs or a text name into the "testedby" parameter
  7. Update the date tested, operating system, and browser lines of the results page