Admin/policy question - Shibboleth users with multiple affiliations

Peter Schober peter.schober at univie.ac.at
Fri Sep 20 03:28:31 EDT 2013


Ken,

More of a topic for the REFEDS mailing list (Research and
Education Federations coordination) but anyway:

* Ken Weiss <ken.weiss at ucop.edu> [2013-09-19 20:19]:
> It would come down to the IDPs agreeing on a common opaque unique
> identifier, with infrastructure to manage that across multiple
> institutions. That's why I called this an admin/policy question. I was
> just hoping someone had already grappled with this and come up with a
> framework.

If you incude Author Identifiers (mainly from the e-resource publisher
world) there are several (ORCID being one of them), with difering
ideas about assignment, registration, claiming, etc.

More to your question and from the Identity Federation world:
The AAF http://www.aaf.edu.au/ has done exactly this with their
"auEduPersonSharedToken" attribute (one of their "core attributes"
every IdP implements), cf.
http://wiki.aaf.edu.au/tech-info/attributes/auedupersonsharedtoken

>From what I've heard in presentations and in conversation with the
friendly folks at AAF, the process of "moving" your
auEduPersonSharedToken from one institution to another is manual,
though, and AFAIU involves the subject "telling" the new institution
his/her old value (which has security implications). But this may be
based on incomplete understanding on my side, of course.

Getting a globally scalable and secure version of such a process in
place is quite the challenge, I would imagine.
-peter


More information about the users mailing list