You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 8 Next »

Users without an institutional account can login via the guest Identity Provider Onegini. To allow for this, your administrative contact person must request SURFconext (support@surfconext.nl) to enable guest access.

By doing so, every Onegini user can potentially login to your service, unless your service contains an authorisation mechanism.

With Onegini users can login with their social account (Facebook, Twitter, LinkedIn or Google). Also a Onegini specific account may be created for users who do not want to use their social account.

Use Onegini to test strong authentication

In the Test, Pilot and Production environments SP's can use Onegini to test strong authentication for their application. The following attributes are available:

Friendly name

Attribute name

Value

SURFconext ID

urn:oid:1.3.6.1.4.1.1076.20.40.40.1urn:collab:person:surfguest.nl:<uid>

uid

urn:mace:dir:attribute-def:uid 
urn:oid:0.9.2342.19200300.100.1.1

Previous SURFguest username when this is a migrated account. Otherwise generated by Onegini.

Surname

urn:mace:dir:attribute-def:sn
urn:oid:2.5.4.4

Registered surname

Given name

urn:mace:dir:attribute-def:givenName
urn:oid:2.5.4.42

Registered first name

Common name

urn:mace:dir:attribute-def:cn
urn:oid:2.5.4.3

Registered common name

Display name

urn:mace:dir:attribute-def:displayName
urn:oid:2.16.840.1.113730.3.1.241

Same as common name

Email address

urn:mace:dir:attribute-def:mail
urn:oid:0.9.2342.19200300.100.1.3

Registered email address
(warning) will only be provided after the user confirmed his email address (via the Onegini website).

Organization

urn:mace:terena.org:attribute-def:schacHomeOrganization 
urn:oid:1.3.6.1.4.1.25178.1.2.9

surfguest.nl

PrincipalName

urn:mace:dir:attribute-def:eduPersonPrincipalName 
urn:oid:1.3.6.1.4.1.5923.1.1.1.6

<uid>@surfguest.nl

There is no attribute that shows which authentication provider (Facebook, Google, LinkedIn, Twitter) the user used.

  • No labels