Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

CoCo is used in the eduGAIN interfederation to make services available to users of European higher education institutions. The CoCo makes it possible to automatically release mostly harmless attributes to Service Providers which fulfill the EU Data Protection Directive. The expected IdP behaviour is to release the Service Provider required subset of the attributes eptid, eppn, mail, displayName, scoped affiliation and schacHomeOrganization. The required subset of attributes for a specific service is defined in the mandatory Service Provider Privacy Policy. There is furthermore an identity provider entity support category that should be registered for all IdP that supports the R&S Category that can be used for filter purpose in a discovery service.

Expected minimal attribute availability for release (only if required)

Attribute(s)OIDComment
eduPersonTargetedID1.3.6.1.4.1.5923.1.1.1.10Only if required in Service Provider metadata!
eduPersonPrincipalName1.3.6.1.4.1.5923.1.1.1.6Only if required in Service Provider metadata!
mail0.9.2342.19200300.100.1.3Only if required in Service Provider metadata! Can be more than one address released but Identity Providers are recommended to release only one.
displayName and/or cn

2.16.840.1.113730.3.1.241,
2.5.4.3

Only if required in Service Provider metadata! A user's name can be released in different ways and it's recommended that the Service Provider can handle this.
eduPersonScopedAffiliation1.3.6.1.4.1.5923.1.1.1.9Only if required in Service Provider metadata!
schacHomeOrganization1.3.6.1.4.1.25178.1.2.9Only if required in Service Provider metadata!
schacHomeOrganizationType1.3.6.1.4.1.25178.1.2.10Only if required in Service Provider metadata!

...

Examples of services that are viable for this entity category is a course registration self service and a student account creation service, a learning progression registration service and an internship administration self service.

Expected attribute release

AttributeOIDComment
eduPersonTargetedID1.3.6.1.4.1.5923.1.1.1.10 
eduPersonAssurance1.3.6.1.4.1.5923.1.1.1.11One or more Assurance profiles for the user if it is defined, please see "3.3 Configure Shibboleth SP - Check for Identity Assurance" for more information.
norEduPersonNIN1.3.6.1.4.1.2428.90.1.5Swedish goverment Personal Identity Number, Swedish goverment temporary Co-ordination number or Swedish National Admission system interim identity number.

...