Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

A Relying Party that consumes a scoped attribute SHOULD verify that the asserted scope is permitted for the issuing Identity Provider by comparing the scope portion of the attribute value against the <shibmd:Scope> values published in that Identity Provider's metadata. See also section 2.1.4 Scope in SAML 2.0 WebSSO Technology Profile.

Identifier Properties

This section describes identifier properties, including whether they are non-reassignable, opaque, persistent, and unique per relying party.

IdentifierNon-reassignedOpaquePersistentUnique per Relying Party
subject-idcheck mark button check mark buttoncheck mark button(error) 
pairwise-idcheck mark buttoncheck mark buttoncheck mark buttoncheck mark button
personalIdentityNumbercheck mark button(error)(error)(error)

Attribute Definitions

subject-id

...

Namehttps://openfed.se/attributes/pairwise-id
Friendly Namepairwise-id
Data Typexs:string
Multi-valuedNO
ScopedYES
Referenceurn:oasis:names:tc:SAML:attribute:pairwise-id
Example9d666d80-c634-4f12-838b-c667de76762b@example.org

personalIdentityNumber

The subject’s national civic registration number (i.e. the Swedish “personnummer” or “samordningsnummer” as defined in SKV 704 and SKV 707).

The value MUST consist of 12 digits without a hyphen. 

Namehttps://openfed.se/attributes/personalIdentityNumber
Friendly NamepersonalIdentityNumber
Data Typexs:string
Multi-valuedNO
ScopedNO
Referenceurn:oid:1.2.752.29.4.13
Example198611245807

givenName

The given name (first name) of the subject.

...