Skip to content

Commit

Permalink
update 3.6.1 description (OWASP#1053)
Browse files Browse the repository at this point in the history
  • Loading branch information
Elar Lang committed Oct 25, 2021
1 parent a551e0b commit 8b595f1
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion 4.0/en/0x12-V3-Session-management.md
Original file line number Diff line number Diff line change
Expand Up @@ -69,7 +69,7 @@ This section relates to those writing Relying Party (RP) or Credential Service P

| # | Description | L1 | L2 | L3 | CWE | [NIST §](https://pages.nist.gov/800-63-3/sp800-63b.html) |
| :---: | :--- | :---: | :---:| :---: | :---: | :---: |
| **3.6.1** | Verify that relying parties specify the maximum authentication time to Credential Service Providers (CSPs) and that CSPs re-authenticate the subscriber if they haven't used a session within that period. | | || 613 | 7.2.1 |
| **3.6.1** | Verify that Relying Parties (RPs) specify the maximum authentication time to Credential Service Providers (CSPs) and that CSPs re-authenticate the user if they haven't used a session within that period. | | || 613 | 7.2.1 |
| **3.6.2** | Verify that Credential Service Providers (CSPs) inform Relying Parties (RPs) of the last authentication event, to allow RPs to determine if they need to re-authenticate the user. | | || 613| 7.2.1 |

## V3.7 Defenses Against Session Management Exploits
Expand Down

0 comments on commit 8b595f1

Please sign in to comment.