...
Tip | ||
---|---|---|
| ||
The MyAccessID IAM GEANT AAI Service supports the Research and Scholarship (R&S) Entity Category. As such, MyAccessID expects GEANT AAI Service expects to receive the R&S attribute bundle from IdPs in eduGAIN supporting the R&S Entity Category. |
...
Tip | ||
---|---|---|
| ||
As a service that meets the requirements for and supports the entity category of Code of Conduct, the service specifically declares the attributes it requires. |
Attribute Type | Attribute | Requirement | Explanation | |
---|---|---|---|---|
User Identifier |
| Mandatory (at least one) | MyAccessID and GEANT AAI Service and the services connected through MyAccessID GEANT AAI Service require to uniquely identify users. Without a unique identifier, it is not possible to distinguish two different users between each other. As a service that supports Sirtfi, it is required that it is able to uniquely identify users. 1 The i) the IdP supports the R&S Enitity Category, ii) the iii) the federation in which the IdP has registered has a policy that prohibits the reassignment of the value of the | |
| ||||
| ||||
| ||||
| Level of Assurance | eduPersonAssurance | Will become mandatory (date TBD) | |
Name |
| Mandatory (at least one) | MyAccessID GEANT AAI Service and the services connected through MyAccessID GEANT AAI Service expect to receive the name of the user. For example, when a user applies for a new project or for membership membership to an existing project, the managers need to be able to recognise who the applicant is. | |
displayName | ||||
| ||||
| Mandatory | MyAccessIDGEANT AAI Service needs to be able to contact the user regarding the status of their account. In addition, many of the services connected through | MyAccessID GEANT AAI Service expect the email of the user in order to be able contact the user about service related matters. | |
Affiliation |
| Mandatory | Access to many of the services connected through | MyAccessID GEANT AAI Service relies on authorising their member users based on affiliation with their home organisation. |
Organization | schacHomeOrganization | Optional | Access to many of the services connected through | MyAccessID GEANT AAI Service relies on authorising users based on their home organisation. |
Depending on which protocol the IdP is using, SAML or OIDC, attributes need to be released in the following format, respectively:
...