The Incommon Federation wiki has moved.

Please visit the new InCommon Federation Library wiki for updated content. Remember to update your bookmarks.

Click in the link above if you are not automatically redirected in 15 seconds.



You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Next »

Migrating to REFEDS R&S Phase II

Report on Phase I

As of Feb 16, all but five (5) R&S SPs have been migrated to REFEDS R&S; that is, 27 of 32 R&S SPs now have a multivalued R&S entity attribute in metadata. I believe two of the remaining five are at risk:

  1. GPN/UM Dropoff Services

  2. Narada Metrics

I believe the other three (Indiana CTSI Hub, nanoHUB.org, and Penn State WikiSpaces) will successfully migrate by the end of February.

Outline of Phase II

Basic message: If you are an IdP operator that supports R&S, migrate to REFEDS R&S now! (reference needed)

Recommended migration process:

  1. An R&S IdP migrates to REFEDS R&S by changing its config from this:

    The configuration of an IdP that has NOT migrated to REFEDS R&S
    <afp:AttributeFilterPolicy id="releaseFullBundleToRandS">
    
      <afp:PolicyRequirementRule xsi:type="saml:AttributeRequesterEntityAttributeExactMatch"
          attributeName="http://macedir.org/entity-category"
          attributeValue="http://id.incommon.org/category/research-and-scholarship"/>
    
      <!-- attribute rules here -->
    
    </afp:AttributeFilterPolicy>
    

    to this:

    The configuration of an IdP that has migrated to REFEDS R&S
    <afp:AttributeFilterPolicy id="releaseFullBundleToRandS">
    
      <afp:PolicyRequirementRule xsi:type="saml:AttributeRequesterEntityAttributeExactMatch"
          attributeName="http://macedir.org/entity-category"
          attributeValue="http://refeds.org/category/research-and-scholarship"/>
    
      <!-- attribute rules here -->
    
    </afp:AttributeFilterPolicy>
  2. When an R&S IdP migrates to REFEDS R&S (as above), the entity attribute in IdP metadata is changed from this:

    The InCommon R&S Entity Attribute for IdPs
    <mdattr:EntityAttributes
        xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
      <!-- the InCommon entity attribute value for R&amp;S IdPs -->
      <saml:Attribute
          xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
          NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
          Name="http://macedir.org/entity-category-support">
        <saml:AttributeValue>
          http://id.incommon.org/category/research-and-scholarship
        </saml:AttributeValue>
      </saml:Attribute>
    </mdattr:EntityAttributes>

    to this:

    The REFEDS R&S Entity Attribute for IdPs
    <mdattr:EntityAttributes
        xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
      <!-- the REFEDS entity attribute value for R&amp;S IdPs -->
      <saml:Attribute
          xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"
          NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"
          Name="http://macedir.org/entity-category-support">
        <saml:AttributeValue>
          http://refeds.org/category/research-and-scholarship
        </saml:AttributeValue>
      </saml:Attribute>
    </mdattr:EntityAttributes>
  3. The InCommon R&S entity attribute value is not exported to eduGAIN. That is, only the REFEDS R&S entity attribute value is exported to eduGAIN (whereas the InCommon R&S entity attribute value is filtered at the border of the InCommon Federation).

  4. R&S IdPs that migrate to REFEDS R&S will be automatically exported to eduGAIN once global R&S SPs have been imported into InCommon metadata.

 


 

Once Phase II begins, the following wiki pages will need to be edited:

https://spaces.at.internet2.edu/x/-oKVAQ

https://spaces.at.internet2.edu/x/eQTvAQ

https://spaces.at.internet2.edu/x/aAbvAQ

https://spaces.at.internet2.edu/x/BoOVAQ

#trackbackRdf ($trackbackUtils.getContentIdentifier($page) $page.title $trackbackUtils.getPingUrl($page))
  • No labels