For many SAML-enabled sites to allow a user to access protected materials, certain information about the user must be provided. Some sites need to know name, e-mail address, or a specific entitlement (Stanford handles entitlement through workgroup memberships). Some others merely want to know whether the user is Stanford faculty, staff, or student, and don’t depend upon the particular identity of the user in question — only that Stanford is willing to vouch for them. For sites using SAML on campus, attribute release policies are commensurate with the policies for sites using Stanford Authentication and Authorization (SAML or WebAuth).
Default Attribute Release
To simplify the attribute release, we have implemented the default attribute release for qualified Service Providers (SPs). The blanket attribute release includes the following attributes:
|Attribute||SAML Name||Description and Example|
|uid||urn:oid:0.9.2342.19200300.100.1.1||SUNet ID, jdoe|
|eduPersonPrincipalName||urn:oid:22.214.171.124.4.1.59126.96.36.199.6||SUNet ID + @stanford.edu , firstname.lastname@example.org|
|givenName||urn:oid:188.8.131.52||first name, ex: john|
|sn||urn:oid:184.108.40.206||surname/last name , ex: doe|
|displayName||urn:oid:2.16.840.1.1137220.127.116.11||Prof. John Doe|
|suAffilliation||suAffiliation||stanford:faculty (but see also the note below)|
|eduPersonEntitlement**||urn:oid:18.104.22.168.4.1.5922.214.171.124.7||stem_x:workgroup_y (see note #6)|
|*WARNING! The mail attribute is not a mandatory attribute at Stanford and might have no value for some users. In particular, if your SP creates an account using one of the attributes as the identifier for that account, do NOT use the mail attribute for that identifier!|
- InCommon Research and Scholarship SPs are included in the above default attribute release.
- Stanford faculty and staff member can request to release the above attributes to InCommon SPs via Help ticket.
- Other attributes that a person has set to "world" visible in StanfordYou may also be released.
- If you need any other attributes, please file a data owner approval request clearly stating your entityID and the desired attributes.
- For SPs that are unable to consume the default attribute release and need the IdP to perform additional transformation for attribute names or format; additional charges may apply.
- To release workgroup information (as eduPersonEntitlement) to specific SPs, please include the stem owner’s/admin’s approval and submit a Help ticket. You do not need to submit data owner approval for workgroup release.
- The suAffilliation attribute is specific to Stanford and will not be recognized by most Service Providers; use eduPersonAffiliation or eduPersonScopedAffiliation instead. See the Directory Service: People Tree page for more detail on the suAffilliation attribute.
- Sample attribute-map.xml .
- The new default attribute release policy automatically applies to “new” SPs that joined the FarmFed Federation on or after Feb. 10, 2017.