Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

InformationDescriptionExamplestored in/mapped to (internally)
Technical contact
  • authentication issues
  • security issues
  • privacy issues

Can be a list

support@it.geant.orgcontacts['technical']
Support contact

"Generic" support questions for the actual service

  • how does it work

Usually the application administrators or the teams that run it.

Can be a list.

support@it.geant.orgcontacts['support']
Service name

Very short name to be shown in user interfaces.

GÉANT Wikiname
Service description

Longer descriptive text, for instance with details like:

  • intended audience
  • its status (production, testing)
  • when it was set up
  • the software type/version it runs

Can contain URLs

Atlassian Confluence wiki, production instance.description
Service URLThe actual URL to the main servicehttps://wiki.geant.orgurl
MetadataValid SAML2.0 metadata

a URL to the XML metadata (preferred), or an XML metadata file.


Note that a public list of all connected services will be made publicly available. This mean that services can not be "hidden".



Supplied information


The SAML proxy will always provide the following attributes to its downstream services:

...

SAML attributeexample valueremarks
uidfederated-user-1234Unique user ID, always available.
mailuser@domainDefaults to the string 'invalid_email_needs_updating' if none was provided by the upstream IdP
displayNameRobert WagnerDefaults to the string 'first_name last_name' or similar if bit aren't provided by the upstream IdP
isMemberOf
  • GN_Services:GN Project Participants

  • GN4Phase3:WPs:WP9

  • GN4Phase1:SAs:GN4-1_SA3-T4

Multivalued attribute listing the CAMS group memberships.




Service monitoring

At some stage there will be some monitoring set-up, to help ensure the service is conforming to basic requirements. The monitored items are expected to include:


  • Reachability of the Service URL
  • Configuration of the web server's TLS stack, using the SSLlabs test.
  • Clock skew, using HTTP Date header

Any alarms that are generated by these checks will be sent to the technical contact(s) that you configured.