...
which are specified in sections 8.3.7 and 8.3.8 of the SAML2 core specification.
The legacy format has the type urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified
, as defined in the SAML 1.1 specification. Legacy identifiers in SURFconext have the form uid@example.org
. Although these might look like email addresses, they are not, and mail sent to such addresses might not (and mostly will not) be delivered.
By default, SURFconext offers the transient form of the NameId to services. Service providers who have a need for persistent identifiers can negotiate use of the persistent NameId format when their service is connected to SURFconext.
...
By default, the NameId is the only piece of information about the euthenticated authenticated user that SURFconext conveys to SPs. However, in many cases these services require more information about the user, such as a name or an email address.
...
Friendly name | Attribute name | S/M | Definition | Data type | Example | |
---|---|---|---|---|---|---|
ID | (NameId) |
| UTF8 string | bd09168cf0c2e675b2def0ade6f50b7d4bb4aae | ||
Surname |
| UTF8 string | Vermeegen | |||
Given name |
| UTF8 string | Mërgim Lukáš | |||
Common name |
| UTF8 String | Prof.dr. Mërgim Lukáš Vermeegen | |||
Display name | urn:mace:dir:attribute-def:displayName |
| UTF8 String | Prof.dr. Mërgim L. Vermeegen | ||
Email address | urn:mace:dir:attribute-def:mail |
| RFC-5322 address | m.l.vermeegen@university.example.org | ]]></ac:plain-text-body></ac:structured-macro> | |
Organization | urn:mace:terena.org:attribute-def:schacHomeOrganization |
| RFC-1035 domain string | university.example.org | ||
Organization Type | urn:mace:terena.org:attribute-def:schacHomeOrganizationType |
| RFC-2141 URN | urn:mace:terena.org:schac:homeOrganizationType:int:university | ||
Affiliation | urn:mace:dir:attribute-def:eduPersonAffiliation |
| Enum type (UTF8 String) | faculty, student, staff, (alum, member, affiliate, employee, library-walk-in) | ||
Entitlement | urn:mace:dir:attribute-def:eduPersonEntitlement |
| RFC-2141 URN | to be determined per service | ||
PrincipalName | urn:mace:dir:attribute-def:eduPersonPrincipalName |
| UTF8 String | not.a@vålîd.émail.addreß | ||
isMemberOf | urn:mace:dir:attribute-def:isMemberOf |
| RFC-2141 URN | urn:collab:org:surf.nl | ||
uid | urn:mace:dir:attribute-def:uid |
| UTF8 String | s9603145 | ||
preferredLanguage | urn:mace:dir:attribute-def:preferredLanguage |
| List of BCP47 language tags | nl |
...