...
Attribute Type | Attribute | Requirement | Explanation |
---|---|---|---|
User Identifier |
| Mandatory (at least one) | GEANT AAI Service and the services connected through GEANT AAI Service require to uniquely identify users. Without a unique identifier, it is not possible to distinguish two different users between each other. As a service that supports Sirtfi, it is required that it is able to uniquely identify users. 1 The i) the IdP supports the R&S Enitity Category, ii) the iii) the federation in which the IdP has registered has a policy that prohibits the reassignment of the value of the |
| |||
| |||
| |||
| |||
Name |
| Mandatory (at least one) | GEANT AAI Service and the services connected through GEANT AAI Service expect to receive the name of the user. For example, when a user applies for a new project or for membership membership to an existing project, the managers need to be able to recognise who the applicant is. |
displayName | |||
| |||
| Mandatory | GEANT AAI Service needs to be able to contact the user regarding the status of their account. In addition, many of the services connected through GEANT AAI Service expect the email of the user in order to be able contact the user about service related matters. | |
Affiliation |
| Mandatory | Access to many of the services connected through GEANT AAI Service relies on authorising their member users based on affiliation with their home organisation. |
Organization | schacHomeOrganization | Optional | Access to many of the services connected through GEANT AAI Service relies on authorising users based on their home organisation. |
...
SAML Attribute Name | SAML Attribute Friendly Name |
---|---|
urn:oasis:names:tc:SAML:attribute:subject-id | subject-id |
urn:oasis:names:tc:SAML:attribute:pairwise-id | pairwise-id |
urn:oid:0.9.2342.19200300.100.1.3 | |
urn:oid:1.3.6.1.4.1.25178.1.2.9 | schacHomeOrganization |
urn:oid:1.3.6.1.4.1.5923.1.1.1.6 | eduPersonPrincipalName |
| eduPersonScopedAffiliation |
urn:oid:1.3.6.1.4.1.5923.1.1.1.10 | eduPersonTargetedID |
urn:oid:1.3.6.1.4.1.5923.1.1.1.11 | eduPersonAssurance |
urn:oid:1.3.6.1.4.1.5923.1.1.1.13 | eduPersonUniqueId |
| eduPersonOrcid |
urn:oid:2.5.4.3 | cn |
urn:oid:2.5.4.4 | surname |
urn:oid:2.5.4.42 | givenName |
- OIDC Claims and Scopes
OIDC Claim | Scope |
---|---|
subject-id | openid |
name | profile |
given_name | profile |
family_name | profile |
voperson_id | aarc |
entitlement |
entitlement | |
eduperson_scoped_affiliation | aarc |
eduperson_ |
assurance | aarc |
schac_home_organization | schac_home_organization |