I4:FeatureTest-Selector Differentiates between Extended Validation Certificates and Regular SSL Certificates for IdPs

From OSIS Open Source Identity Systems

Jump to: navigation, search

   list help  copy  as XML  edit
Feature Test   Selector Differentiates between Extended Validation Certificates and Regular SSL Certificates for IdPs
Test Type   Site Information
Identifier   FTR-iis-cardusage-9  
Description   Selector provides a noticable difference between IdPs using EV and regular SSL certificates  
Role tested   Information Card Identity Selector  
Known Successful Reference Solution(s)  
I4:CardSpace .NET Framework 3.5 SP1  
Success Criteria   Selector informs user whether an EV or regular SSL certificate is being used  
Failure Criteria   Selector makes no distinction between EV and regular SSL certificates  

Features Proven

Feature feature_type solution_role
Differentiate Extended Validation Certificates from Regular SSL Certificates for IdPs Information Card Identity Selector usability

Instructions

  1. Open the result page for the solution for this test.
  2. Visit an Identity Provider employing an EV SSL certificate, such as I4:VeriSign PIP and obtain an Information Card from the site.
  3. Note what information is shown about the site's certificate as the user is being asked to make a trust decision about the site and the card issued by it.
  4. Now visit an Identity Provider employing a regular SSL certificate for the first time, such as I4:Bandit Cards and obtain a card from the site.
  5. Note what information is shown about the site's certificate as the user is being asked to make a trust decision about the site and the card issued by it.
  6. If successful, the trust information displayed for the card at the site using an EV certificate will be substantially different and inspire more confidence than the information displayed for the card at the site using only a regular certificate.
  7. Set outcome:
    1. If the success criteria was met, set the outcome to "Works".
    2. If the test failed, set the outcome to "Failed" and enter information about the failure in the Notes section.
    3. If other issues occurred set the result to "Issues" and describe them in the Notes section.
  8. Add either four tilde ~~~~ signs or a text name into the "Tested by" parameter.
  9. Update the Date Tested, Browser, and Operating System lines of the results page.