SAML IdP Best Current Practice
To register an Identity Provider in SWAMID you need to be a member of the Identity Federation SWAMID. For more information on how to become a member please go to Getting Started with SWAMID.
Most information under this section is in Swedish due to that SWAMID Identity Providers are institutions of the Swedish Higher Educational Sector.
In SWAMID multiple brands of Identity Provider software are used: the two most usual are Shibboleth Identity Provider and Microsoft Active Directory Federation Services (ADFS). On this HowTo page we'll concentrate on these two. For now most of the information will be for Shibboleth, but we'll add more and more information on ADFS.
Metadata and policy considerations
- SWAMID Assurance How-To
- SAML WebSSO Technology Profile
- Entity Category attribute release in SWAMID
- Release of assurance statements in the attribute eduPersonAssurance based on SWAMID Identity Profiles
- SWAMID Identity Provider MDUI requirements
- Säkerhets- och incidenthanteringsprofilen REFEDS SIRTFI med fokus på identitetsfärdare (IdP)
Shibboleth Identity Providers
Base installation
- Shibboleth IdPv5 uppgradering
- Konfigurera metadata i Shibboleth Identity Provider för att använda SWAMID
- Example of a standard attribute resolver for Shibboleth IdP v5 and above
- Example of a standard attribute filter for Shibboleth IdP v5 and above
Extended configuration
- Release of assurance statements in the attribute eduPersonAssurance based on SWAMID Identity Profiles
- Pseudonym identifierare (EPTID)
- SAML f-ticks for Shibboleth
ADFS Identity Provider
Base installation
Extended configuration
Extended configuration of Identity Providers
- Identity Provider Key Rollover
- Rätt semantik för eduPersonScopedAffiliation
- Signalera tillitsprofil genom eduPersonAssurance
- Svenska personnummer: norEduPersonNIN, personalIdentityNumber och schacDateOfBirth
- Rekommenderad release av statisk organisationsinformation
Service Providers that need special integration considerations
- How-To - European Student Identifier (ESI) för European Digital Student Service Infrastructure (EDSSI)
- How-To - Ladok StudentUID vid attributerelease
- How-To - SAML-konfiguration Sunet TCS