Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: EWP admin entitlement

...

As specified by the MyAcademicID team the "MyAcademicID IAM Service" requires a specific set of data in order for logins to the services "behind" it to be possible. While it would be pointless to repeat this specification here we can provide guidance to the local eduID.at Austrian academic community by sharing copy/paste-able instructions on how to enable access to the central component and thereby to all the services "behind" it. This assumes use of the Shibboleth Identity Provider software and a configuration that matches our own documentation and deployment recommendations, specifically the attribute resolver and attribute filter documentation.

...

In support of these larger projects the European Student Identifier (ESI) was defined and this too needs to be made available in your IDP and released to the central "MyAcademicID IAM Service". Copy/paste-able examples for its creation are part of our standard set of documentation for the Shibboleth IDP's attribute resolver as well as for its scalable release to eligible services.

Erasmus Without Paper-Admins

Selected individiduals from your institution may need to be provided with a specific eduPersonEntitlement attribute value in order to access certain EWP-specific resources. The section "Attribute release configuration" below illustrates just that, though assigning it to specific people and creating it within your Shibboleth IDP's attribute resolver also needs to happen.

Other common attributes

Make sure to also have the common attributes displayName, mail, eduPersonScopedAffiliation and schacHomeOrganization available and release them to the "MyAcademicID IAM Service", all of which we already provide extensive configuration guidance for.

...