Shibboleth Attribute Release policy summary: Difference between revisions

From RavenWiki
Jump to navigationJump to search
(Make clear that misStatus is stored in lookup)
(Summary moved to new, official home)
 
Line 1: Line 1:
{{shib-project}}
See http://www.cam.ac.uk/cs/raven/attribute-summary.html
 
* '''eduPerson Principal Name''' (eduPersonPrincipalName) with the value ''<crsid>@cam.ac.uk'', and an apropriate    '''Anonymous Identifier''' (eduPersonTargetedID), to any SP that requests them on behalf of anyone with a Raven account.
* '''Status''' (eduPersonScopedAffiliation) with the value ''member@cam.ac.uk'' to any SP that requests it on behalf of anyone who appears in lookup.
* '''Entitlement''' (eduPersonEntitlement):
** to '''the EduServ Shibboleth to Athens gateway'''
*** with a value of ''cam#default0'' on behalf of anyone who is not members of lookup group [http://www.lookup.cam.ac.uk/group/100925 100925], and who has a misStatus in lookup of 'staff' or 'student' or who is a member of lookup group [http://www.lookup.cam.ac.uk/group/100926 100926] (this represents the group of people entitled to access Athens-protected electronic resources).
*** with a value of ''cam#aaemo'' on behalf of anyone who is not members of lookup group [http://www.lookup.cam.ac.uk/group/100925 100925] and who is a member of lookup group [http://www.lookup.cam.ac.uk/group/100927 100927] (this represents the collection of people entitled to access 'medically restricted' Athens-protected electronic resources).
** to '''EDINA Film&Sound olnline'''
*** with a value of ''urn:mace:ac.uk:sdss.ac.uk:entitlement:emol.sdss.ac.uk:restricted'' on behalf of anyone who is a member of lookup group [http://www.lookup.cam.ac.uk/group/100927 100927] (this represents the collection of people entitled to access 'medically restricted' material on Film&Sound)
* '''Forename''' (givenName), '''Surname''' (sn), '''Registered Name''' (cn), '''Display Name''' (displayName), '''Institution''' (ou), '''E-mail''' (mail), '''lookup group''' (groupID) with values derived from lookup (subject to each user's choice of suppression) for anyone who appears in lookup
** to '''CS Development server''' https://mnementh.csi.cam.ac.uk/shibboleth

Latest revision as of 08:56, 13 September 2007