From 1734b9676db5e62faa46f8c77f2b64861b62de27 Mon Sep 17 00:00:00 2001
From: Teun Fransen urn:mace schema: urn:mace:dir:attribute-def:givenName Description: Given name, also known as a first name, forename or Christian name / name known by; combinations of title, initials, and name known by are possible. given_name Description: given name, also known as a first name, forename or Christian name / name known by; combinations of title, initials, and name known by are possible. urn:mace: urn:mace:dir:attribute-def:sn Description: The surname of a person (including any words such as "van", "de", "von" etc.) used for personalization; this can be a combination of existing attributes. family_name Description: The surname of a person (including any words such as "van", "de", "von" etc.) used for personalization; this can be a combination of existing attributes. urn:mace: urn:mace:dir:attribute-def:cn Description: full name. name Description: full name. urn:mace: urn:mace:dir:attribute-def:displayName Description: name as displayed in applications. nickname Description: name as displayed in applications. email Description: e-mail address; syntax in accordance with RFC 5322. email Description: e-mail address; syntax in accordance with RFC 5322. urn:mace: urn:mace:terena.org:attribute-def:schacHomeOrganization Description: the user's organization using the organization's domain name; syntax in accordance with RFC 1035. schac_home_organization Description: the user's organization using the organization's domain name; syntax in accordance with RFC 1035. urn:mace: urn:mace:terena.org:attribute-def:schacHomeOrganizationType Description: designation of the type of organisation as defined on https://wiki.refeds.org/display/STAN/SCHAC+Releases schac_home_organization_type Description: designation of the type of organisation as defined on https://wiki.refeds.org/display/STAN/SCHAC+Releases . urn:mace:dir:attribute-def:ou indicates the department, team, or faculty with which the user is associated within the issuing institution. This attribute is multi-valued, so multiple departments, teams or faculties can be listed For example:
urn:oid schema: urn:oid:2.5.4.42
urn:oid: urn:oid:2.5.4.4
urn:oid: urn:oid:2.5.4.3
urn:oid: urn:oid:2.16.840.1.113730.3.1.241
urn:oid: urn:oid:1.3.6.1.4.1.25178.1.2.9
urn:oid: urn:oid:1.3.6.1.4.1.25178.1.2.10
OrganizationalUnitName
Description: indicates the department, team, or faculty with which the user is associated within the issuing institution. This attribute is multi-valued, so multiple departments, teams or faculties can be listed, for example:
urn:mace: urn:mace:dir:attribute-def:eduPersonAffiliation
urn:oid: urn:oid:1.3.6.1.4.1.5923.1.1.1.1
Description: indicates the relationship between the user and his home organisation. The following values are permitted:
eduperson_affiliation
Description: indicates the relationship between the user and his home organisation. The following values are permitted:
Description: custom URI (URL or URN) that indicates an entitlement to something.
", + "oidcngLabel": "eduperson_entitlement", + "oidcngInfo": "eduperson_entitlement
Description: custom URI (URL or URN) that indicates an entitlement to something.
" } }, "urns": [ @@ -153,10 +153,10 @@ "id": "principleName", "translations" : { "en": { - "saml20Label": "Principle name attribute", - "saml20Info": "Text should be set in web translations", - "oidcngLabel": "Principle name attribute", - "oidcngInfo": "Text should be set in web translations" + "saml20Label": "Principle name attribute (EPPN)", + "saml20Info": "urn:mace: urn:mace:dir:attribute-def:eduPersonPrincipalName
urn:oid: urn:oid:1.3.6.1.4.1.5923.1.1.1.6
Description: unique identifier for a user.
", + "oidcngLabel": "eduperson_principal_name", + "oidcngInfo": "eduperson_principal_name
Description: unique identifier for a user.
" } }, "urns": [ @@ -169,9 +169,9 @@ "translations" : { "en": { "saml20Label": "Uid attribute", - "saml20Info": "Text should be set in web translations", - "oidcngLabel": "Uid attribute", - "oidcngInfo": "Text should be set in web translations" + "saml20Info": "urn:mace: urn:mace:dir:attribute-def:uid
urn:oid: urn:oid:0.9.2342.19200300.100.1.1
Description: the unique code for a person that is used as the login name within the institution.
", + "oidcngLabel": "uids", + "oidcngInfo": "uids
Description: the unique code within the institution for a person that is used as the login name.
" } }, "urns": [ @@ -184,9 +184,9 @@ "translations" : { "en": { "saml20Label": "Preferred language attribute", - "saml20Info": "Text should be set in web translations", - "oidcngLabel": "Preferred language attribute", - "oidcngInfo": "Text should be set in web translations" + "saml20Info": "urn:mace: urn:mace:dir:attribute-def:preferredLanguage
urn:oid: urn:oid:2.16.840.1.113730.3.1.39
Description: a two-letter abbreviation for the preferred language according to the ISO 639 language abbreviation code table; no subcodes
", + "oidcngLabel": "locale", + "oidcngInfo": "locale
Description: a two-letter abbreviation for the preferred language according to the ISO 639 language abbreviation code table; no subcodes.
" } }, "urns": [ @@ -198,10 +198,10 @@ "id": "personalCode", "translations" : { "en": { - "saml20Label": "Personal code attribute", - "saml20Info": "Text should be set in web translations", - "oidcngLabel": "Personal code attribute", - "oidcngInfo": "Text should be set in web translations" + "saml20Label": "Employee-student number attribute", + "saml20Info": "urn:mace: urn:schac:attribute-def:schacPersonalUniqueCode
urn:oid: urn:oid:1.3.6.1.4.1.25178.1.2.14
Description: The user's student, employee, and/or member id as used in the institution's internal systems. More information: https://wiki.surfnet.nl/pages/viewpage.action?pageId=11207351
", + "oidcngLabel": "schac_personal_unique_code", + "oidcngInfo": "schac_personal_unique_code
Description: The user's student, employee, and/or member id as used in the institution's internal systems. More information: https://wiki.surfnet.nl/pages/viewpage.action?pageId=11207351
" } }, "urns": [ @@ -214,9 +214,9 @@ "translations" : { "en": { "saml20Label": "Scoped affiliation attribute", - "saml20Info": "Text should be set in web translations", - "oidcngLabel": "Scoped affiliation attribute", - "oidcngInfo": "Text should be set in web translations" + "saml20Info": "urn:mace: urn:mace:dir:attribute-def:eduPersonScopedAffiliation
urn:oid: urn:oid:1.3.6.1.4.1.5923.1.1.1.9
Description: Indicates the relationship between the user and a specific (security) domain with his home organisation. The following values are permitted:
eduperson_scoped_affiliation
Description: Indicates the relationship between the user and a specific (security) domain with his home organisation. The following values are permitted:
urn:mace:dir:attribute-def:eduPersonTargetedID
urn:oid:1.3.6.1.4.1.5923.1.1.1.10
This attribute is created because the Subject NameID itself is not part of the SAML v2.0 response and therefore only is available for application if the local SAML implementation explicitly support this. Within SURFconext the Subject 'NameID' is explicitly copied into the eduPersonTargetedID attribute, in order for the identifier to be used like any other attribute.
", + "oidcngLabel": "not used in OIDC", + "oidcngInfo": "not used in OIDC" } }, "urns": [ "urn:mace:dir:attribute-def:eduPersonTargetedID", "urn:oid:1.3.6.1.4.1.5923.1.1.1.10" ] - }, - { - "id": "contactPersonID", - "translations" : { - "en": { - "saml20Label": "Saml20 Contact Person target ID attribute", - "saml20Info": "Saml20 Text should be set in web translations", - "oidcngLabel": "Oidcng Contact Person target ID attribute", - "oidcngInfo": "Oidcng Text should be set in web translations" - } - }, - "urns": [ - "urn:mace:dir:attribute-def:contactPersonIDID", - "urn:oid:1.3.6.1.4.1.5923.1.1.1.100" - ] } ]