UPDATE ......From Tuesday 8 April 2025 we have changed the way that Single Sign-on works on this wiki. Please see here for more information:
Update
...
- Entity Category: Grouping of entities is typically done via a:
- Trust Anchor or an Intermediate. All entities with similar behavious are members of the same intermediate (or trust anchor)
- Trust Mark could also be used. A trust mark is created by a trust mark owner ( .
- The trustmark owner must be trusted and listed as such by the federation TA
- A Trust Mark may be self issued.
- Entity Attribute Signalling assurance certifications is done using so called Trust Marks.
- Profiles, signalling certain behaviour as part of a transaction is generally covered in the underlying standards like OpenID Connect and OAuth2OAuth 2.0. The capablity for signalling is often available, however the semantics may need to be adopted
- Metadata Extension, provide an extention to existing metadata profiles is allowed in the OpenID Federation specification. For broad acceptance and implementation of an extention it may be needed to engage with the OpenID Foundation, e.g. via de RandE working group
- Frameworks, are currenlty basically assurance frameworks, which provide a structured means of describing or defining the main sources of assurance provided within the federation by the member entities or the federation itself.
Wallets
WIP
Overview of findings
specification name | type | Applies to entity | Asserted by | Attribute profile | Entity behavioural rules | Attribute requirements | In scope for OpenIDFed | In scope for wallets | SAML Specific Protocol requirements |
---|---|---|---|---|---|---|---|---|---|
Research and Scholarship (R&S) v1.3 | Entity Category | SP | Registrar |
|
|
| |||
Research and Scholarship (R&S) v1.3 | Entity Category | IdP | IdP |
|
| ^^^ | |||
Hide From Discovery v.1 | Entity Category | IdP | IdP |
| |||||
Anonymous Access v.2 | Entity Category | SP | Registrar |
|
|
| |||
Anonymous Access v.2 | Entity Category | IdP | IdP |
|
| ^^^ | |||
Pseudonymous Access v.2 | Entity Category | SP | Registrar |
| |||||
Pseudonymous Access v.2 | Entity Category | IdP | IdP |
| ^^^ | ||||
Personalized Access v.2 | Entity Category | IdP | Registrar |
| |||||
Personalized Access v.2 | Entity Category | SP | Registrar | ^^^ | |||||
Code of Conduct v.2 | Entity Category and Best Practice | ||||||||
Sirtfi v1 & v2 | Entity Attribute | SP | SP |
...