Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
en:aai:attributes_best_practice [2021/07/14 15:15] – translated Silke Meyeren:aai:attributes_best_practice [2021/12/14 18:11] (current) Wolfgang Pempe
Line 1: Line 1:
 ====== Recommended Best Practices for the use of attributes in DFN-AAI ====== ====== Recommended Best Practices for the use of attributes in DFN-AAI ======
-(back to [[de:attributes|Übersicht]])+(back to the [[de:attributes|Overview]] (de))
  
 You can find configuration samples for attribute resolver, attribute filter, and relying party configuration [[de:shibidp:config-attributes-aaiplus|on this page]]. You can find configuration samples for attribute resolver, attribute filter, and relying party configuration [[de:shibidp:config-attributes-aaiplus|on this page]].
Line 7: Line 7:
 ^ 1.1 Omni-directional, non-targeted  ^^ ^ 1.1 Omni-directional, non-targeted  ^^
 | ''urn:oasis:names:tc:SAML:attribute:subject-id'' [[de:common_attributes#a16|docs]] (de)| recommended | | ''urn:oasis:names:tc:SAML:attribute:subject-id'' [[de:common_attributes#a16|docs]] (de)| recommended |
-| ''eduPersonUniqueId'' [[de:common_attributes#a12|docs]] (de) | deprecated - the value in front of the scope must be identical to the value of the subject-id |+| ''eduPersonUniqueId'' [[de:common_attributes#a12|docs]] (de) | deprecated - the value in front of the scope should - if ever possible - be identical to the value of the subject-id |
 | <del>''eduPersonPrincipalName''</del> | do not use!  | | <del>''eduPersonPrincipalName''</del> | do not use!  |
 | <del>''mail''</del> | do not use as identifier! | | <del>''mail''</del> | do not use as identifier! |
 ^ 1.2 Pairwise / targeted ^^ ^ 1.2 Pairwise / targeted ^^
 | ''urn:oasis:names:tc:SAML:attribute:pairwise-id'' [[de:common_attributes#a17|docs]] (de) | recommended - stored Id! (plus scope)| | ''urn:oasis:names:tc:SAML:attribute:pairwise-id'' [[de:common_attributes#a17|docs]] (de) | recommended - stored Id! (plus scope)|
-| ''eduPersonTargetedID'' [[de:common_attributes#a11|docs]](de) | deprecated - value must be identical to the pairwise-id (the part in front of the scope) | +| ''eduPersonTargetedID'' [[de:common_attributes#a11|docs]](de) | deprecated - value should - if ever possible - be identical to the pairwise-id (the part in front of the scope) | 
-| ''persistent Id'' (SAML2 Name ID) | deprecated - value must be identical to the pairwise-id (the part in front of the scope) |+| ''persistent Id'' (SAML2 Name ID) | deprecated - value should - if ever possible - be identical to the pairwise-id (the part in front of the scope) |
 ^ 1.3 Others ^^ ^ 1.3 Others ^^
 | ''transient Id'' ( SAML2 Name ID) | recommended (required for Logout) | | ''transient Id'' ( SAML2 Name ID) | recommended (required for Logout) |
Line 23: Line 23:
 | ''schacHomeOrganization'' **and** ''o'' Documentation about [[de:common_attributes#a06|o]] (de) und [[de:common_attributes#a18|schacHomeOrganization]] (de)| recommended | | ''schacHomeOrganization'' **and** ''o'' Documentation about [[de:common_attributes#a06|o]] (de) und [[de:common_attributes#a18|schacHomeOrganization]] (de)| recommended |
 ^ 5. Other attributes that have to be defined (Attribute Resolver) ^^ ^ 5. Other attributes that have to be defined (Attribute Resolver) ^^
-| ''eduPersonAssurance'' [[de:common_attributes#a14|docs]] (de) | see [[https://refeds.org/assurance|REFEDS Assurance Framework]] |+| ''eduPersonAssurance'' [[de:common_attributes#a14|docs]] (de) | see [[https://refeds.org/assurance|REFEDS Assurance Framework]] and [[de:aai:assurance_idp|configuration examples for IdPs]] |
 | ''eduPersonEntitlement'' [[de:common_attributes#a10|docs]] (de) || | ''eduPersonEntitlement'' [[de:common_attributes#a10|docs]] (de) ||
 | ''eduPersonOrcid'' [[de:common_attributes#a13|docs]] (de) | possibly empty | | ''eduPersonOrcid'' [[de:common_attributes#a13|docs]] (de) | possibly empty |
  • Last modified: 3 years ago