<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
<meta name="Generator" content="Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
span.html-attribute
{mso-style-name:html-attribute;}
span.html-attribute-name
{mso-style-name:html-attribute-name;}
span.html-attribute-value
{mso-style-name:html-attribute-value;}
span.html-tag
{mso-style-name:html-tag;}
span.EmailStyle22
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang="EN-US" link="blue" vlink="purple" style="word-wrap:break-word">
<div class="WordSection1">
<p class="MsoNormal">Yes, Sir, as the metadata states, OpenAthens has permission to assert @alaska.edu to SPs. Thus the importance of getting the display name right in discovery interfaces to (hopefully) prevent people fro possibly getting duplicate identities
in SPs or simply confusing them with two paths into different systems. Usually, though, users won’t be able to log into the same SPs with both OpenAthens and your home IdP. The bigger risk is that they’ll select the wrong IdP and get an error because, say,
OpenAthens isn’t configured to talk to the non-library SP that the user is trying to access incorrectly.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">As for lessons, start simple. Explain IdP discovery and show how the user can get themselves stuck. Also might want to show them how OpenAthens can send users to your IdP, too, instead of acting as its own IdP. That won’t solve the discovery
problem, but it will at least give you a more uniform user experience. In that mode, OpenAthens acts more like a proxy. At least I think it can do that. I try not to be an expert on it.<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<p class="MsoNormal">Keith, happily working at an institution clinging to EZProxy… and amazed that happily and EZProxy can go in the same sentence<o:p></o:p></p>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal"><b>From:</b> users <users-bounces@shibboleth.net> <b>On Behalf Of
</b>IAM David Bantz<br>
<b>Sent:</b> Friday, December 3, 2021 4:36 PM<br>
<b>To:</b> Shib Users <users@shibboleth.net><br>
<b>Subject:</b> RE: OpenAthens doppelgänger ?<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal"><o:p> </o:p></p>
<div>
<p class="MsoNormal">Good perspective (make friends) Keith.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">Aren’t scoped assertions from the OpenAthens IdP going to be “@<a href="https://urldefense.com/v3/__http:/alaska.edu__;!!DZ3fjg!pU5ELXxS5ED2i0rL4VRp8aPSt9bec250bFvipM2ytcupNY405zNBi6-yCQX1B2gJMQ$">alaska.edu</a>”? <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal">They are not, though; they are paying customers of the for profit organization.<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal">What sort of thing would be apprpriate to "teach to" the Library liaison to OpenAthens?<o:p></o:p></p>
</div>
<div>
<p class="MsoNormal"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal" style="margin-bottom:12.0pt">David<o:p></o:p></p>
<div>
<div>
<p class="MsoNormal">On 03Dec2021 at 13:30:33, "Wessel, Keith" <<a href="mailto:kwessel@illinois.edu">kwessel@illinois.edu</a>> wrote:<o:p></o:p></p>
</div>
<blockquote style="border:none;border-left:solid #CCCCCC 1.0pt;padding:0in 0in 0in 6.0pt;margin-left:4.8pt;margin-right:0in">
<div>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Depends on how many of your users are using discovery interfaces that list both as well as what the display name is for the OpenAthens entity. At the least, this sounds like an
opportunity to make a friend at whichever of your campuses’ libraries is the contact for your OpenAthens configuration. It’s definitely a teachable moment.<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Keith<o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<div>
<div style="border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in">
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><b>From:</b> users <<a href="mailto:users-bounces@shibboleth.net">users-bounces@shibboleth.net</a>>
<b>On Behalf Of </b>IAM David Bantz<br>
<b>Sent:</b> Friday, December 3, 2021 4:27 PM<br>
<b>To:</b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<b>Subject:</b> OpenAthens doppelgänger ?<o:p></o:p></p>
</div>
</div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">I haven’t been paying enough attention to OpenAthens. I just realized there is an OpenAthens federated identity provider from a for-profit organization with an entity ID and scope
referring to my institution. That seems to mean that consumers of information from the OpenAthens IdP may conclude, informally from the entity ID, and more correctly based on the scope, that the assertion is about a member of my institution. As I say, I haven’t
paid enough attention to OpenAthens, so maybe I need some ’splaining, but this seems to me wrong on many levels. Is it? How concerned should I be?<o:p></o:p></p>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-family:"Courier New";color:#881280"><md:EntityDescriptor <span class="html-attribute">… </span><span class="html-attribute-name">entityID</span><span class="html-attribute">="</span><span class="html-attribute-value"><a href="https://urldefense.com/v3/__https:/idp.alaska.edu/openathens__;!!DZ3fjg!ss-gBE2VLSfEpyRTMYK5VOFdx_pSW4e5k8U7hArZhtkos3tYM5uHlFUeBd-KTek2sw$">https://idp.alaska.edu/openathens</a></span><span class="html-attribute">”</span>></span><o:p></o:p></p>
</div>
<div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span style="font-family:"Courier New";color:#881280">…<</span><span class="html-tag"><span style="font-family:"Courier New"">shibmd:Scope</span></span><span class="html-attribute"><span style="font-family:"Courier New""> </span></span><span class="html-attribute-name"><span style="font-family:"Courier New"">regexp</span></span><span class="html-attribute"><span style="font-family:"Courier New"">=“</span></span><span class="html-attribute-value"><span style="font-family:"Courier New"">false</span></span><span class="html-attribute"><span style="font-family:"Courier New"">"</span></span><span class="html-tag"><span style="font-family:"Courier New"">></span></span><span style="font-family:"Courier New""><a href="https://urldefense.com/v3/__http:/alaska.edu__;!!DZ3fjg!ss-gBE2VLSfEpyRTMYK5VOFdx_pSW4e5k8U7hArZhtkos3tYM5uHlFUeBd8wANqQ8g$">alaska.edu</a><span class="html-tag"></shibmd:Scope></span></span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;margin-bottom:12.0pt"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;margin-bottom:12.0pt"><span class="html-tag"><span style="font-family:"Courier New";color:#881280"><EntityDescriptor</span></span><span class="html-attribute"><span style="font-family:"Courier New";color:#881280"> … </span></span><span class="html-attribute-name"><span style="font-family:"Courier New";color:#881280">entityID</span></span><span class="html-attribute"><span style="font-family:"Courier New";color:#881280">="</span></span><span class="html-attribute-value"><span style="font-family:"Courier New";color:#881280">urn:mace:incommon:<a href="https://urldefense.com/v3/__http:/alaska.edu__;!!DZ3fjg!ss-gBE2VLSfEpyRTMYK5VOFdx_pSW4e5k8U7hArZhtkos3tYM5uHlFUeBd8wANqQ8g$">alaska.edu</a></span></span><span class="html-attribute"><span style="font-family:"Courier New";color:#881280">"</span></span><span class="html-tag"><span style="font-family:"Courier New";color:#881280">></span></span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">… <span class="html-tag"><span style="font-family:"Courier New""><shibmd:Scope</span></span><span class="html-attribute"><span style="font-family:"Courier New""> </span></span><span class="html-attribute-name"><span style="font-family:"Courier New"">regexp</span></span><span class="html-attribute"><span style="font-family:"Courier New"">="</span></span><span class="html-attribute-value"><span style="font-family:"Courier New"">false</span></span><span class="html-attribute"><span style="font-family:"Courier New"">"</span></span><span class="html-tag"><span style="font-family:"Courier New"">></span></span><span style="font-family:"Courier New""><a href="https://urldefense.com/v3/__http:/alaska.edu__;!!DZ3fjg!ss-gBE2VLSfEpyRTMYK5VOFdx_pSW4e5k8U7hArZhtkos3tYM5uHlFUeBd8wANqQ8g$">alaska.edu</a><span class="html-tag"></shibmd:Scope></span></span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;margin-bottom:12.0pt"><o:p> </o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span class="html-tag"><span style="font-family:"Courier New"">David St. Pierre Bantz</span></span><o:p></o:p></p>
</div>
<div>
<p class="MsoNormal" style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span class="html-tag"><span style="font-family:"Courier New"">University of Alaska (<a href="https://urldefense.com/v3/__http:/alaska.edu__;!!DZ3fjg!ss-gBE2VLSfEpyRTMYK5VOFdx_pSW4e5k8U7hArZhtkos3tYM5uHlFUeBd8wANqQ8g$">alaska.edu</a> !)</span></span><o:p></o:p></p>
</div>
</div>
</div>
</div>
</div>
</div>
<div>
<div>
<p class="MsoNormal">-- <br>
For Consortium Member technical support, see <a href="https://urldefense.com/v3/__https:/shibboleth.atlassian.net/wiki/x/ZYEpPw__;!!DZ3fjg!pU5ELXxS5ED2i0rL4VRp8aPSt9bec250bFvipM2ytcupNY405zNBi6-yCQVYq5Ltmg$">
https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><o:p></o:p></p>
</div>
</div>
</blockquote>
</div>
</div>
</div>
</body>
</html>