Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.
Comment: SPs may filter out IDPs w/o category support

...

Only by (also) participating in Interfederation (such as eduGAIN) you're will you be able to support your academic constituency in providing them with secured access to the resources they need. For example E.g. E-research cannot happen without international collaboration and shared, properly managed access to scientific tools. Cf. the FIM4R (Federated Identity Management for Research Collaborations) paper.

Metadata

All IDPs in eduID.at should always load SAML Metadata that also includes entities known via Interfederation agreements, such as eduGAIN. This metadata set alone is sufficient for all eduID.at Federation and Interfederation purposes, so can replace any previously used one:

...

Adjust the IDP configuration to lookup and/or generate any missing attributes.

Note
iconfalse

All Every eduID.at-registered IDPsIDP should be able to produce at least the following attributes:

...

If you added support for Service Categories-based attribute release (which is recommended) please also notify ACOnet about which ones you support, so this can be documented in your Identity Provider's SAML Metadata. Signalling the support for a given Service Category allows services relying on attributes defined in such Service Categories to automatically filter which IDPs to make available for login. By only listing IDPs that claim to support a given Service Category chances of successful logins (and hence of a proper user experience) for subjects coming from those Identity Providers are greatly enhanced! Conversely, IDPs not announcing support for any of the popular Service Categories (i.e., those giving the Service Providers no indication that necessary attributes will be released) might find themselfs unable to access fewer services, going forward.