To support the Research and Scholarship Category, an IdP has at least two options:
The Shibboleth IdP software supports the first option out-of-the-box. The second option requires a special plugin at the Shibboleth IdP.
In either case, an IdP leverages entity attributes (instead of entity IDs) to support R&S. Thus the configuration steps documented here require Shibboleth IdP v2.3.4 or later, which fully supports using entity attributes in SP metadata as part of an attribute release filter policy. (No other IdP software is known to support entity attributes at this time.)
Shibboleth IdP v2.3.4 was released on October 27, 2011. For IdPs prior to v2.3.4, InCommon provides an XSLT tool that filters InCommon metadata into an explicit |
To release a fixed subset of the R&S bundle (or the complete R&S bundle itself), configure a new <AttributeFilterPolicy>
element that refers to the R&S entity attribute. The following example releases a subset of the R&S bundle to all R&S SPs:
<AttributeFilterPolicy id="releaseToRandS"> <PolicyRequirementRule xsi:type="saml:AttributeRequesterEntityAttributeExactMatch" attributeName="http://id.incommon.org/attribute/entity/category" attributeValue="http://id.incommon.org/category/research-and-scholarship"/> <AttributeRule attributeID="eduPersonPrincipalName"> <PermitValueRule xsi:type="basic:ANY"/> </AttributeRule> <AttributeRule attributeID="email"> <PermitValueRule xsi:type="basic:ANY"/> </AttributeRule> <AttributeRule attributeID="displayName"> <PermitValueRule xsi:type="basic:ANY"/> </AttributeRule> <AttributeRule attributeID="givenName"> <PermitValueRule xsi:type="basic:ANY"/> </AttributeRule> <AttributeRule attributeID="surName"> <PermitValueRule xsi:type="basic:ANY"/> </AttributeRule> </AttributeFilterPolicy> |
To release some other subset of the R&S bundle, simply customize the above example to match your policy.
To dynamically release a subset of the R&S bundle to each R&S SP on an SP-by-SP basis, configure a new <AttributeFilterPolicy>
element that refers to the R&S entity attribute but limits attribute release to the <md:RequestedAttribute>
elements in SP metadata. This leads to the following two-step configuration process:
<md:RequestedAttribute>
elements in SP metadata.<AttributeFilterPolicy>
element for R&S SPs.These two configuration steps taken together constrain the release of attributes to precisely those attributes requested by R&S SPs (assuming those attributes constitute a subset of the R&S bundle).
The uApprove addon to the Shibboleth IdP includes a plugin that limits attribute release to the <md:RequestedAttribute>
elements in SP metadata.
The uApprove addon is not required to release attributes to R&S SPs. The steps below do not install uApprove but rather a plugin included in the uApprove package. |
To install and configure the plugin, perform the following steps:
<code>$ <b>cp $UAPPROVE_INSTALL$/idp-plugin-2.2.1/lib/* $IDP_INSTALL$/lib/</b></code> |
xmlns:ua="http://www.switch.ch/aai/idp/uApprove/mf"
to the <AttributeFilterPolicy>
element (or better yet, to the parent <AttributeFilterPolicyGroup>
element).The plugin adds a new PermitValueRule
of type ua:AttributeInMetadata
.
The following IdP configuration implicitly releases attributes to any R&S SP. An attribute is released if and only if it is listed in SP metadata.
<AttributeFilterPolicy id="releaseToRandS" xmlns:ua="http://www.switch.ch/aai/idp/uApprove/mf"> <PolicyRequirementRule xsi:type="saml:AttributeRequesterEntityAttributeExactMatch" attributeName="http://id.incommon.org/attribute/entity/category" attributeValue="http://id.incommon.org/category/research-and-scholarship"/> <AttributeRule attributeID="eduPersonPrincipalName"> <PermitValueRule xsi:type="ua:AttributeInMetadata" onlyIfRequired="false"/> </AttributeRule> <AttributeRule attributeID="email"> <PermitValueRule xsi:type="ua:AttributeInMetadata" onlyIfRequired="false"/> </AttributeRule> <AttributeRule attributeID="displayName"> <PermitValueRule xsi:type="ua:AttributeInMetadata" onlyIfRequired="false"/> </AttributeRule> <AttributeRule attributeID="givenName"> <PermitValueRule xsi:type="ua:AttributeInMetadata" onlyIfRequired="false"/> </AttributeRule> <AttributeRule attributeID="surName"> <PermitValueRule xsi:type="ua:AttributeInMetadata" onlyIfRequired="false"/> </AttributeRule> </AttributeFilterPolicy> |