...
Friendly name | Attribute name | Definition | Data type | Example |
---|---|---|---|---|
(NameID) | eduPerson (1) | UTF8 string | bd09168cf0c2e675b2def0ade6f50b7d4bb4aae | |
UTF8 string | Vermeegen | |||
Given nameAttributes | UTF8 string | Mërgim Lukáš | ||
Common nameAttributes | UTF8 String | Prof.dr. Mërgim Lukáš Vermeegen | ||
Display nameAttributes | urn:mace:dir:attribute-def:displayName | UTF8 String | Prof.dr. Mërgim L. Vermeegen | |
Email addressAttributes | urn:mace:dir:attribute-def:mail | RFC-5322 address | m.l.vermeegen@university.example.org | |
OrganizationAttributes | urn:mace:terena.org:attribute-def:schacHomeOrganization | RFC-1035 domain string | example.nl | |
Organization TypeAttributes | urn:mace:terena.org:attribute-def:schacHomeOrganizationType | RFC-2141 URN | urn:mace:terena.org:schac:homeOrganizationType:int:university | |
Employee/student numberAttributes | urn:schac:attribute-def:schacPersonalUniqueCode | Schac | RFC-2141 URN | urn:schac:personalUniqueCode:nl:local:example.edu:employeeid:x12-3456 urn:schac:personalUniqueCode:nl:local:example.nl:studentid:s1234567 |
AffiliationAttributes | urn:mace:dir:attribute-def:eduPersonAffiliation | eduPerson (1) | Enum type (UTF8 String) | employee, student, staff, member (alum, affiliate, faculty, library-walk-in are not allowed) |
Scoped affiliationAttributes | urn:mace:dir:attribute-def:eduPersonScopedAffiliation urn:oid:1.3.6.1.4.1.5923.1.1.1.9 | eduPerson (1) | UTF8 String user@domain | student@physics.uniharderwijk.nl |
EntitlementAttributes | urn:mace:dir:attribute-def:eduPersonEntitlement | eduPerson (1) | RFC-2141 URN | to be determined per service (see Standardized values for eduPersonEntitlement) |
PrincipalNameAttributes | urn:mace:dir:attribute-def:eduPersonPrincipalName | eduPerson (1) | UTF8 String | piet.jønsen@example.edu |
isMemberOfAttributes | urn:mace:dir:attribute-def:isMemberOf | RFC-2141 URN | urn:collab:org:surf.nl | |
uidAttributes | urn:mace:dir:attribute-def:uid | UTF8 String | s9603145 | |
preferredLanguageAttributes | urn:mace:dir:attribute-def:preferredLanguage | List of BCP47 language tags | nl | |
ORCID | eduPerson (1) | URL registered with ORCID.org | http://orcid.org/0000-0002-1825-0097 |
...
urn:mace | urn:mace:dir:attribute-def:sn |
urn:oid | urn:oid:2.5.4.4 |
Multiplicity | single-valued |
Data type | UTF8 string (unbounded) |
Description | Surname of a person (including words as "van", "de", "von", etc.) used for personalisation; can be a combination of existing attributes. |
Examples | Vermeegen 孝慈 |
Notes |
|
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:dir:attribute-def:givenName |
urn:oid | urn:oid:2.5.4.42 |
Multiplicity | single-valued |
Data type | UTF8 string (unbounded) |
Description | Given name / "name known by"; combinations of title, initials, and "name known by" are possible. |
Examples | Jan Klaassen |
Notes |
|
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:dir:attribute-def:cn |
urn:oid | urn:oid:2.5.4.3 |
Multiplicity | multi-valued |
Data type | UTF8 string (unbounded) |
Description | Full name. |
Examples | Prof.dr. Mërgim Lukáš Vermeegen 加来 千代, PhD. |
Notes | For example, a typical name of a person in an English-speaking country comprises a personal title (e.g. Mr., Ms., Rd, Professor, Sir, Lord), a first name, middle name(s), last name, generation qualifier (if any, e.g. Jr.) and decorations and awards (if any, e.g. CBE). |
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:dir:attribute-def:displayName |
urn:oid | urn:oid:2.16.840.1.113730.3.1.241 |
Multiplicity | single-valued |
Data type | UTF8 string (unbounded) |
Description | Name as displayed in applications |
Examples | Prof.dr. Mërgim Lukáš Vermeegen 加来 千代, PhD. |
Notes | Can be changed by the end-users themselves and is therefore not suitable for identification. |
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:dir:attribute-def:mail |
urn:oid | urn:oid:0.9.2342.19200300.100.1.3 |
Multiplicity | multi-valued |
Data type | RFC-5322 address (max 256 chars) |
Description | e-mail address; syntax in accordance with RFC 5322 |
Examples | m.l.vermeegen@university.example.org "very.unusual.@.unusual.com"@example.com mlv@[IPv6:2001:db8::1234:4321] |
Notes |
|
...
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:terena.org:attribute-def:schacHomeOrganization |
urn:oid | urn:oid:1.3.6.1.4.1.25178.1.2.9 |
Multiplicity | single-valued |
Data type | RFC-1035 domain string. Must be a secondary-level domain under control by the institution. Preferably use the institutions main domain name. |
Description | Domain name of the users organisation; syntax conform RFC 1035. |
Examples | uniharderwijk.nl |
Notes |
|
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:terena.org:attribute-def:schacHomeOrganizationType |
urn:oid | urn:oid:1.3.6.1.4.1.25178.1.2.10 |
Multiplicity | single-value |
Data type | RFC-2141 URN (see Schac standard) |
Description | Organisation type as defined by Terena. |
Examples | urn:mace:terena.org:schac:homeOrganizationType:int:university urn:mace:terena.org:schac:homeOrganizationType:es:opi |
Notes | In practice this attribute is almost not used by IdPs or SPs; contact support@surfconext.nl if you would like to use it. |
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:schac:attribute-def:schacPersonalUniqueCode |
urn:oid | urn:oid:1.3.6.1.4.1.25178.1.2.14 |
Multiplicity | multi-value |
Data type | RFC-2141 URN (see SURFnet registry). |
Description | The id used in the university's internal systems. |
Examples | urn:schac:personalUniqueCode:nl:local:example.edu:employeeid:x12-3456 urn:schac:personalUniqueCode:nl:local:example.nl:studentid:s1234567 |
Notes |
|
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:dir:attribute-def:eduPersonAffiliation |
urn:oid | urn:oid:1.3.6.1.4.1.5923.1.1.1.1 |
Multiplicity | multi-valued |
Data type | UTF8 String (only the values below are allowed). |
Description | Relationship between user and his home organisation:
|
Examples | see above |
Notes |
|
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:dir:attribute-def:eduPersonScopedAffiliation |
urn:oid | urn:oid:1.3.6.1.4.1.5923.1.1.1.9 |
Multiplicity | multi-valued |
Data type | UTF8 String of the form affiliation@subdomain. |
Description | Indicates the relationship between the user and a specific (security) domain with his home organisation in a fine-grained way. For example, it can specify that a user is a student in the Physics department or a secretary working in a specific department.The value consists of an affiliation-part and a domain-part, i.e. <affiliation>@<sub.domain.nl>.
|
Examples | student@physics.uniharderwijk.nl |
Notes |
|
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:dir:attribute-def:eduPersonEntitlement |
urn:oid | urn:oid:1.3.6.1.4.1.5923.1.1.1.7 |
Multiplicity | multi-value |
Data type | RFC-2141 URN |
Description | Custom URI (URL or URN) indicating an entitlement to something. |
Examples | urn:mace:terena.org:tcs:personal-admin |
Notes |
|
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:dir:attribute-def:eduPersonPrincipalName |
urn:oid | urn:oid:1.3.6.1.4.1.5923.1.1.1.6 |
Multiplicity | single-valued |
Data type | UTF8 String of the form user@domain . Domain must be equal to or a subdomain of schacHomeOrganization. |
Description | Unique identifier for a user. |
Examples | piet.jønsen@example.edu not.a@vålîd.émail.addreß |
Notes |
|
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:dir:attribute-def:isMemberOf |
urn:oid | urn:oid:1.3.6.1.4.1.5923.1.5.1.1 |
Multiplicity | multi-valued |
Data type | RFC-2141 URN |
Description | Organisations the user is member of. |
Examples | urn:collab:org:surf.nl |
Notes |
|
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:dir:attribute-def:uid |
urn:oid | urn:oid:0.9.2342.19200300.100.1.1 |
Multiplicity | multi-valued |
Data type | UTF8 string (max 256 chars); do not use space or @ -sign. |
Description | Code for a person, used as login name within his institution. |
Examples | s9603145 |
Notes |
|
Anchor | ||||
---|---|---|---|---|
|
urn:mace | urn:mace:dir:attribute-def:preferredLanguage |
urn:oid | urn:oid:2.16.840.1.113730.3.1.39 |
Multiplicity | single-valued |
Data type | RFC2798 BCP47 |
Description | two-letter abbreviation for the preferred language, conform ISO 639. |
Examples | nl |
Notes | Can be useful for international correspondence or human-computer interaction. Values MUST conform to the definition of the Accept-Language header field defined in RFC 2068, only " |
...
urn:mace:dir:attribute-def:eduPersonTargetedID | |
urn:oid:1.3.6.1.4.1.5923.1.1.1.10 | |
Multiplicity | single-valued |
Data type | UTF8 string (unbounded) |
Description | EduPersonTargetedID is a copy of the Subject -> NameID generated by SURFconext. When an IdP provides the eduPersonTargetedID itself, it is always overwritten by SURFconext. |
Example | bd09168cf0c2e675b2def0ade6f50b7d4bb4aae |
Note | This attribute is created because the Subject -> NameID itself is not part of the SAML v2.0 response and therefore only available for the application if the local SAML implementation explicitly support this. |
Anchor | ||||
---|---|---|---|---|
|
urn:mace:dir:attribute-def:eduPersonOrcid | |
urn:oid:1.3.6.1.4.1.5923.1.1.1.16 | |
Multiplicity | multi-valued |
Data type | URL, registered with ORCID.org |
Description | ORCID is a persistent digital identifier distinguishing the account holder from other researchers. EduPersonOrcid supports automated linkages between the account holder and his professional activities, ensuring that his work is recognized. Must be valid ORCID identifier in the ORCID-preferred URL representation, i.e. http://orcid.org/0000-0002-1825-0097. |
Example | http://orcid.org/0000-0002-1825-0097 |
Note | For more information: https://www.surf.nl/en/news/2016/02/global-author-identifier-service-orcid-now-available-through-surfconext-and-edugain.html. |
...