Germany Authentication Methods - RUB-NDS/FutureTrust GitHub Wiki
According to Section 2.2.1 of (BSI TR-03130-1, 2016)[1] every eService must support Online-Authentication based on Extended Access Control 2 (EAC2) as specified in Section 2 of (BSI TR-03124-1, 2015)[2]. EAC2 can be done via SOAP or SAML as described in Germany Overview.
1. ^ BSI TR-03130-1. (2016, November 16). Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI). eID-Server Part 1: Functional Specification. https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/TechnischeRichtlinien/TR03130/TR-03130_TR-eID-Server_Part1.pdf?__blob=publicationFile: Technical Guideline 03130-1, Version 2.0.2.
2. ^ BSI TR-03124-1. (2015, February 24). Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI). eID-Client – Part 1: Specifications. https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/TechnischeRichtlinien/TR03124/TR-03124-1.pdf?__blob=publicationFile&v=1: Technical Guideline 03124-1, Version 1.2.