These are the simple steps to join the ACOnet Identity Federation as a member:
- Determine what document needs to be signed in order to become a federation member.
- Submit the completed agreement by (surface-)mail or e-mail to ACOnet.
- Contact the eduID.at operations team, noting the type of service you intend to register and operate with the Federation.
We invite you to also begin technical integration work in parallel with the formal joining process (in order to avoid one delaying the other unduly).
ACOnet participants not yet running a SAML Identity Provider can make use of the extensive documentation on installing and configuring one.
Service Providers
For the registration of a SAML Service Provider (SP) within eduID.at please provide the following information, in addition to a copy of the SAML 2.0 Metadata describing your Service Provider (or the URL to such metadata).
- What attributes the service needs in order to function properly and what they are used for. Additional attributes not strictly needed for the service (but which may provide for a better user experience if available) may be listed separately, clearly indicating their optional status. See What attributes are relevant for a Service Provider for guidance.
- Which of the common Service Categories (REFEDS R&S, GÉANT CoCo v1, REFEDS CoCo v2, etc.) your SP claims to support.
N.B.: SPs without support for any of the (community-)standard Service Categories will experience failed log-in attempts due to IDPs not releasing attributes – unless the SP has leverage to convince IDPs otherwise, e.g. by managing "trust" via contracts anyway or by having special political power or legal standing. - A display name and short (1 paragraph max.) description of the service (in English and/or German)
- A functional/role email address (and optional display name) – not a personal one – for the technical contact to be published with the SAML entity.
- The URL to the Privacy Policy covering this service. See Privacy Notice template document for Service Providers for more.
- An HTTPS URL referencing a logo for the service (in PNG format), between 80 and 250 pixels in size (either dimension).
- How you intend to implement IdP Discovery. While you may use the fallback SAML Discovery Service(s) provided by ACOnet it's preferrable to integrate discovery with your service, in order to provide for a more consistent user experience, cf. the REFEDS Discovery Guide.
- Whether you intend to also participate in Interfederation/eduGAIN (only makes sense if the target audience of the service also includes members of academic institutions outside Austria.)
Identity Providers
For the registration of a SAML Identity Provider (IDP) within eduID.at please provide the following information, in addition to a copy of the SAML 2.0 Metadata describing your Identity Provider (or the URL to such metadata).
- Whether the IDP supports access to services via Service Categories (both REFEDS R&S and GÉANT CoCo strongly recommended)
- The preferred display name for the organisation in German and English language (if differing from what the organisation's web site shows)
- Functional/role email address(es), not personal one(s) – possibly re-using the same address for all roles – and display names for:
- the IDP's technical contact
- the support contact (optional)
- the security contact (if not supplied the technical contact will be re-used)
- HTTPS URLs referencing:
- A logo for the organisation (PNG format), between 80 and 250 pixels in size (either dimension)
- A "favicon"-style icon (16×16 pixel)
- Whether you intend to also participate in Interfederation/eduGAIN (strongly recommended)