Requirements and Best Practices

Requirements for Participation in the DFN-AAI

General Requirements

For IdPs and SPs

The following formal, technical and organizational criteria apply equally to Identity Providers (IdP) and Service Providers (SP).

Formal Criteria

Technical and Organizational Criteria

Identity Provider

Service Provider

Why do universities and research institutes require federated Web Single Sign-On?

  • With Web SSO, users only have one user identifier and one password - instead of one per service.
  • After one login with the IdP their browser is logged in to all services for a configurable amount of time.
  • The central login page can be secured with state-of-the-art measures by IdP operators.
  • Passwords are never transmitted to Service Providers.
  • Authorization is granted based on standardized, meaningful attributes (see below). IdP operators can control whether SPs meet the rule of data minimization when they configure attribute release.
  • Users are asked for their consent before attributes are relased to a Service Provider for the first time. The IdP can save this information.

Why do IdP operators talk about local metadata?

Best Practice Recommendations