Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Attribute release

Adjust the IDP configuration Extend your existing IDP configuration to scalably release selected needed attributes to appropriate SPsappropriate Service Providers.

Info
iconfalse

The currently best option we have for this are Entity Categories which allow to group Service Providers by common criteria and release certain attributes to whole categories of SPs. This is a risk-based approach, enabling low-risk transactions with high benefit services.

Useful categories are (more to come):

TODO: Detailed technical information to follow!

The use of the provided Service Categories to automate attribute release as much as possible is strongly recommended for all IDPs participating in Interfederation.

Notify ACOnet

To make your Identity Provider usable with services from registered in other interfederated institutions federations contact ACOnet in order for your entity to become visible to eduGAIN (and from there to other eduGAIN-participating federations).those interfederation services.

If you added support for Service Categories-based attribute release (which is strongly recommended!) please also notify ACOnet about which ones you support, so this can be documented in your Identity Provider's SAML Metadata. Signalling the support for a given Service Category allows services relying on attributes defined in such Service Categories to automatically filter which IDPs they make available for login. By only listing IDPs who claim to support a given Service Category chances of successful logins (and hence of a proper user experience) for subjects coming from those Identity Providers are greatly enhanced!