Versions Compared


  • This line was added.
  • This line was removed.
  • Formatting was changed.


  1. How to make OpenID Connect work for Higher Education (Roland H)
  2. Provide temporary eduroam to Guests (Paul D)
  3. Token Translation as a Service (Licia)
  4. uApprove Next Generation - Detached from Shibboleth for OAuth, UMA & OpenID Connect (Ken)
  5. Scalable Solution to SAML Attribute Release - Entity Categories, CoC and more... (Olivier)
  6. Structured Attributes
    1. Attribute Aggregation -> Structured (Maarten)
    2. Structured Attributes - More Just Strings (Thomas L)




The scope of the discussion is about SAML attributes and how to transfer more complex attributes. Whether the attributes are transferred from the IdP to the SP or from an AP to an SP is not very relevant.


Several  Several aspects were considered:

  •  the value attached to the attributes a possible architecture to aggregate attributes from different sources
  • a possible architecture to aggregat attributes from different sources

Clearly if attributes become more complex, applications would need to adapt their APIs to process them. Do we have use-cases for more structured attributes? Do SPs need structured attributes?

Olivier mentioned that some use-cases for more structure attributes appeared in the e-Learning sector.

One way would be to provide both the simple value as well as the structured value. Those applications that cannot process the structured value would just ignore it.

We should be careful not to ship too much information for each authN. Maybe AP should be shipping the structured attributes.


It was agreed to decouple the problem in:

  1. Define the structured attribute

     2. Define who wants structured attributes and how to make them consumable for SPs. A couple of use-cases were presented (Roland, Clarin, Olivier).

    3. How do you present the aggregate attributes from different source?


Action: for those attending this section, to provide use-cases that would benefit from structured attributes. Ideally the use-case should be presented with:


 - list potential attributes to support this

 - identify the sources of these attributes