Seitenhistorie
...
The following attributes will be issued by the OpenIDP to any Service Provider known to it (i.e., all eduID.at Service Providers):
Friendly name | Formal attribute name | Description |
---|---|---|
givenName | urn:oid:2.5.4.42 | First name |
sn | urn:oid:2.5.4.4 | Last name |
displayName | urn:oid:2.16.840.1.113730.3.1.241 | "Firstname Lastname" (without the quotes) |
urn:oid:0.9.2342.19200300.100.1.3 | The email address used for verification emails during account creation | |
eduPersonPrincipalName | urn:oid:1.3.6.1.4.1.5923.1.1.1.6 | Always of the form [a-z0-9]{7}@openidp.aco.net , i.e. seven (random) lower-case characters and/or digits + "@openidp.aco.net ".The string is "random" only during account creation; after that the created eduPersonPrincipalName value will not change for a given registration. Also, eduPersonPrincipalName values will not be re-used or re-assigned from one person to another at the OpenIDP. |
eduPersonEntitlement (only in few cases) | urn:oid:1.3.6.1.4.1.5923.1.1.1.7 | For application owners the OpenIDP allows the provisioning of entitlement values via a proprietary API. E.g. after the u:book support team (see below) has verified someone's identity and eligibility ("studentness") status, they are able to store that fact in an entitlement specific to their services, e.g. |
Services known to accept ACOnet OpenIDP identities
...
These services are known to externalize their guest credentials management to the ACOnet OpenIDP, so they don't have to manage, keep secure and support passwords themselfs:
- USI-Wien Kursanmeldung: The University Sports Institute (USI) at Vienna University implements online registration for its many sports courses via eduID.at. Since not all Austrian institutions whose members are eligible for USI courses currently participate in ACOnet or eduID.at subjects from such institutions can register an account at OpenIDP once, and use that for online registration at USI as long as desired.
- u:book is a federated service by University of Vienna allowing members of participating academic institutions in Austria to buy things and services at participating online stores.
- Training Courses by the Computer Center and Human Resources Development departments at the University of Vienna. Some of these courses are open to the general public and so need a method to authenticate people outside the eduID.at membership (or even outside the ACOnet constituency) in order to register for courses online. Authorization in these cases usually happens by payment of the course fee, so (self-asserted) attributes or identity vetting are not an issue.