I haven’t been paying enough attention to OpenAthens. I just realized there
is an OpenAthens federated identity provider from a for-profit organization
with an entity ID and scope referring to my institution. That seems to mean
that consumers of information from the OpenAthens IdP may conclude,
informally from the entity ID, and more correctly based on the scope, that
the assertion is about a member of my institution. As I say, I haven’t paid
enough attention to OpenAthens, so maybe I need some ’splaining, but this
seems to me wrong on many levels. Is it? How concerned should I be?

<md:EntityDescriptor … entityID="”>
…<shibmd:Scope regexp=“false"></shibmd:Scope>

<EntityDescriptor … entityID="">
… <shibmd:Scope regexp="false"></shibmd:Scope>

