<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
Dear Dr Bradlley, thank you very much for the reply and the pointers. I will explore them and also check with my institute if the additional attributes required to be released to access CILogon conform to its policies.</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
<br>
</div>
<div style="font-family: Calibri, Arial, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);">
With regards, Francis.</div>
<div>
<div id="appendonsend"></div>
<div style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:12pt; color:rgb(0,0,0)">
<br>
</div>
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Robert Bradley <robert.bradley@it.ox.ac.uk><br>
<b>Sent:</b> 07 May 2021 20:31<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Subject:</b> Re: Configuring IdP server</font>
<div> </div>
</div>
<div class="BodyFragment"><font size="2"><span style="font-size:11pt">
<div class="PlainText">External Email<br>
<br>
<br>
On 06/05/2021 05:48, Francis Jayakanth, via users, wrote:<br>
><br>
> Hi, In April 2020, our library set up a shibboleth IdP server to<br>
> facilitate federated access to subscribed online resources. Since then,<br>
> the IdP server is serving the purpose very well.<br>
><br>
> Of late, some of our users want to use federated login to access sites<br>
> like the CILogon, <a href="https://www.cilogon.org/home">https://www.cilogon.org/home</a><br>
> <<a href="https://www.cilogon.org/home">https://www.cilogon.org/home</a>> but cannot do so because our IdP server<br>
> is not releasing the attributes expected by the site. Please see the<br>
> enclosed screenshot for your reference.<br>
><br>
> Our IdP is releasing only three attributes to all the publishers to<br>
> access the online resources - eduPersonEntitlement,<br>
> EduPersonScopedAffiliation, and eduPersonTargetedID, and they are<br>
> adequate to access the publishers' online resources.<br>
><br>
> If ​you have configured your IdP server to facilitate federated login to<br>
> sites like CILogon, NIH,  can you please share the configuration details?<br>
><br>
<br>
For CILogon to work, you'll need to update your published metadata to<br>
assert Sirtfi and R&S compliance:<br>
<br>
<a href="https://refeds.org/sirtfi">https://refeds.org/sirtfi</a><br>
<a href="https://refeds.org/research-and-scholarship">https://refeds.org/research-and-scholarship</a><br>
<br>
and then implement the R&S attribute release policy configuration in:<br>
<br>
<a href="https://wiki.refeds.org/display/ENT/Research+and+Scholarship+IdP+Config">https://wiki.refeds.org/display/ENT/Research+and+Scholarship+IdP+Config</a><br>
<br>
Before doing that, you'll want to read all of those links to find out<br>
the full details of what you're asserting, and then find out whether<br>
your organisation can/will agree to implement it.<br>
<br>
For NIH, you can (if I recall correctly) get away with manually<br>
releasing the R&S attribute set (eduPersonPrincipalName, displayName,<br>
givenName, sn, mail, eduPersonScopedAffiliation) without implementing<br>
the R&S specification and metadata announcements.  Again, this assumes<br>
that your organisation is happy to release the attributes in accordance<br>
with its own policies.<br>
<br>
--<br>
Dr Robert Bradley<br>
Identity and Access Management Team, IT Services, University of Oxford<br>
<br>
</div>
</span></font></div>
</div>
</body>
</html>