SAML
Metadata registration
SAML authentication relies on the use of metadata. Both parties (you as a SP and the LifeScience IdP) need to exchange metadata in order to know and trust each other. The metadata include information such as the location of the service endpoints that need to be invoked, as well as the certificates that will be used to sign SAML messages. The format of the exchanged metadata should be based on the XML-based SAML 2.0 specification. Usually, you will not need to manually create such an XML document, as this is automatically generated by all major SAML 2.0 SP software solutions (e.g., Shibboleth, SimpleSAMLphp, and mod_auth_mellon). It is important that you serve your metadata over HTTPS using a browser-friendly SSL certificate, i.e. issued by a trusted certificate authority.
You can get the metadata of the LifeScience IdP on a dedicated URL that depends on the integration environment being used:
Development environment | Production environment |
---|---|
https://saml.pilot.lifescienceid.org/proxy/saml2/idp/metadata.php | TBD |
Attributes
The LifeScience IdP is guaranteed to release a minimal subset of the REFEDS Research & Scholarship attribute bundle to connected Service Providers. A more extensive list of all the attributes that may be made available to Service Providers is included in the following table:
Attribute Description | Attribute Friendly Name | Attribute OID | Attribute Example Value |
---|---|---|---|
Persistent, non-reassigned, non-targeted identifier; this is always scoped @lifescienceid.org | eduPersonUniqueId | urn:oid:1.3.6.1.4.1.5923.1.1.1.13 |
|
Email address | mail | urn:oid:0.9.2342.19200300.100.1.3 | john.doe@example.org |
Display name | displayName | urn:oid:2.16.840.1.113730.3.1.241 | John Doe |
First name | givenName | urn:oid:2.5.4.42 | John |
Family name | sn | urn:oid:2.5.4.4 | Doe |
Assurance information | eduPersonAssurance | urn:oid:1.3.6.1.4.1.5923.1.1.1.11 | TBD |
TBD | eduPersonScopedAffiliation | urn:oid:1.3.6.1.4.1.5923.1.1.1.9 | TBD |
One or more URIs (either URNs or URLs) that indicate rights to specific resources; URN values expressing group membership and role information use the urn:geant:lifescienceid.org:group namespace (see also AARC-JRA1.1A) | eduPersonEntitlement | urn:oid:1.3.6.1.4.1.5923.1.1.1.7 |
|
One or more ORCID researcher identifiers | eduPersonOrcid | urn:oid:1.3.6.1.4.1.5923.1.1.1.16 | http://orcid.org/0000-0002-1825-0097 |