eduPersonAssurance and postAuthContext principals scripted attribute

Mak, Steve makst at upenn.edu
Thu Jul 30 15:31:57 UTC 2020


Hey list I had a question for implementers.

I'm curious if anyone has built in v4 IdP an eduPersonAssurance attribute. It looks like AWS can't use authnContextClassRef for this type of thing.

I'm currently looking for useful resources for how to build a script for this based on a users authContext principals, or maybe using an activation-condition for it. We don't have any value we can use in our IdP DB.

I was thinking the logic could look like this:

1. At attribute resolve time parse the list of authContext principals.
2. If one of the principals equals 'urn..TimeSyncToken' then set eduPersonAssurance to some MFA-like/Gold/High value.

Thanks,
Steve Mak



More information about the users mailing list