Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

For a suggestion on how to consume and process 4.1 Entity Categories for Service Providers in an Identity Provider look at the page Example of a standard attribute filter for Shibboleth IdP - Deprecated.

All entity categories (as well as other information) on services in SWAMID can be found at 4.1 Entity Categories for Service Providers.

Entity Support Categories

An identity Provider marked with an entity support category for an explicit entity category is signaling that this IdP follows the intended use of the entity category.

REFEDS Research and Scholarship Entity Category Support

entity-support-category URI

http://refeds.org/category/research-and-scholarship

eduGAIN enabledYes

...

Example of services that uses the entity category includes (but are not limited to) collaborative tools and services such as wikis, blogs, project and grant management tools that require some personal information about users to work effectively.  This Entity Category should not be used for access to licensed content such as e-journals.

Process for applying for tagging an identity provider with entity support category for REFEDS Research and Scholarship

For an identity provider to be tagged with R&S it must contact the federation that it has registered with. If the identity provider is registered within the SWAMID federation the identity provider operator sends an e-mail to operations@swamid.se with a formal request. Please note that SWAMID Operations use the results in SWAMID Test utility for verifying your IdPs category compliance for verification. Run the compliance test before you send the request.

...

Upon receiving a request SWAMID operations will respond within two weeks.

GÉANT Dataprotection Code of Conduct Entity Category Support

entity-support-category URI

http://www.geant.net/uri/dataprotection-code-of-conduct/v1

eduGAIN enabledYes

...

CoCo is used in the eduGAIN interfederation to make services available to users of European higher education institutions. The CoCo makes it possible to automatically release mostly harmless attributes to Service Providers which fulfill the EU Data Protection Directive. The expected IdP behaviour is to release the Service Provider required subset of the attributes eptid, eppn, email, displayName, scoped affiliation and schacHomeOrganization. The required subset of attributes for a specific service is defined in the mandatory Service Provider Privacy Policy. There is furthermore an identity provider entity support category that should be registered for all IdP that supports the R&S Category that can be used for filter purpose in a discovery service.

Process for applying for tagging an identity provider with entity support category for GÉANT Dataprotection Code of Conduct

For an identity provider to be tagged with CoCo it must contact the federation that it has registered with. If the identity provider is registered within the SWAMID federation the identity provider operator sends an e-mail to operations@swamid.se with a formal request. Please note that SWAMID Operations use the results in SWAMID Test utility for verifying your IdPs category compliance for verification. Run the compliance test before you send the request.

...

Upon receiving a request SWAMID operations will respond within two weeks.

Other Entity Categories

REFEDS Hide From Discovery

entity-category URI

http://refeds.org/category/hide-from-discovery

eduGAIN enabledYes

...

The Hide from Discovery entity category is used for Identity Providers that should not be shown on discovery interfaces by default. Example of Identity Providers that will use this entity category are new identity providers in pre-production tests. The SWAMID and NORDUnet discovery services support this entity category.

Process for applying for tagging an identity provider with entity category Hide From Discovery

For an identity provider to be tagged with Hide From Discovery it must contact the federation that it has registered with. If the identity provider is registered within the SWAMID federation the identity provider operator sends an e-mail to operations@swamid.se with a formal request.

...