diff --git a/ELN-0602 - Deployment Profile for the Swedish eID Framework.md b/ELN-0602 - Deployment Profile for the Swedish eID Framework.md index a3fe85b..b03a11f 100644 --- a/ELN-0602 - Deployment Profile for the Swedish eID Framework.md +++ b/ELN-0602 - Deployment Profile for the Swedish eID Framework.md @@ -2,7 +2,7 @@ # Deployment Profile for the Swedish eID Framework -### Version 1.4 - 2017-02-13 +### Version 1.4 - 2017-03-13 #### *Draft version* *ELN-0602-v1.4* @@ -742,16 +742,28 @@ placed under the `` element as the value of an ``` - ` + http://id.elegnamnden.se/loa/1.0/loa3 ... - ` -` + + ``` *Example of how an Authentication Context URI identifier representing a Level of Assurance is included in an authentication statement.* +An Identity Provider that acts as a proxy for other Identity Providers SHOULD include the `` element under the `` element. This element will contain the entityID of the Identity Provider that was involved in authenticating the principal. + +``` + + + ... + http://idp.company.com/auth + + +``` +*Example of how the entityID of an Identity Provider that provided the authentication for the principal is included in an authentication statement.* + #### 6.2.1. Attribute Release Rules @@ -1237,6 +1249,8 @@ response with the status code - A clarification to section 5.2 was made stating that conformant Identity Providers MUST support the HTTP-POST binding. + +- Section 6.2 was updated with requirements for proxy-IdP:s that are expected to include the `` element holding the entityID of the Identity Provider that provided the authentication of the principal. **Changes between version 1.2 and version 1.3:** diff --git a/ELN-0604 - Attribute Specification for the Swedish eID Framework.md b/ELN-0604 - Attribute Specification for the Swedish eID Framework.md index 63e2e4f..bbca4eb 100644 --- a/ELN-0604 - Attribute Specification for the Swedish eID Framework.md +++ b/ELN-0604 - Attribute Specification for the Swedish eID Framework.md @@ -2,7 +2,7 @@ # Attribute Specification for the Swedish eID Framework -### Version 1.4 - 2017-02-13 +### Version 1.4 - 2017-03-13 #### *Draft version* *ELN-0604-v1.4* @@ -220,7 +220,7 @@ Framework. | Attribute requirement | Attributes | | :--- | :--- | -| **REQUIRED**2 | `prid` (Provisional ID)
`pridPersistence` (Provisional ID persistence indicator)
`eidasPersonIdentifier` (Mapping of the eIDAS PersonIdentifier attribute)
`dateOfBirth` (Date of birth)
`sn` (Surname)
`givenName` (Given name) | +| **REQUIRED**2 | `prid` (Provisional ID)
`pridPersistence` (Provisional ID persistence indicator)
`eidasPersonIdentifier` (Mapping of the eIDAS PersonIdentifier attribute)
`dateOfBirth` (Date of birth)
`sn` (Surname)
`givenName` (Given name)
`transactionIdentifier` (ID of assertion issued by the member state node)4 | | **REQUIRED**
(if available)3 | `birthName` (Birth name)
`placeOfBirth` (Place of birth)
`eidasNaturalPersonAddress` (Address for natural person)
`gender` (Gender) | | **RECOMMENDED** | `personalIdentityNumber` (National civic registration number)
`personalIdentityNumberBinding` (National civic registration number Binding URI) | **Typical use**: In an attribute release policy implemented by an eIDAS @@ -236,7 +236,7 @@ between eIDAS attributes and an Swedish identity number (see [section The eIDAS attribute set comprises of “added” and “converted” attributes. **Added attributes**: Attributes that are not provided by the member -state node, but added by the\ +state node, but added by the Swedish eIDAS node in order to provide additional information about the authenticated subject obtained from relevant domestic attribute sources. The `prid`, `pridPersistence` and `personalIdentityNumber` @@ -259,6 +259,8 @@ examples of “converted attributes”. > \[3\]: Converted attributes for the optional attributes of the eIDAS minimum data set for natural persons. +> \[4\]: The transaction identifier attribute will contain the unique ID of the assertion that was issued by the member state node. This information together with the entityID of the member state node (found in the `` element of an assertion) give a reference to the original assertion and authentication process. + ### 2.6. eIDAS Legal Person Attribute Set