Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Next »

Lehigh's SSO SAML2 Identity Provider (IDP) automatically maps account attributes which are shared with the service provider (SP) when you authenticate and login.  Here are the default mappings and some examples.


Attribute NameEnglish NameExample
urn:oid:0.9.2342.19200300.100.1.1usernamex057
urn:oid:0.9.2342.19200300.100.1.3email addressx057@lehigh.edu
urn:oid:1.3.6.1.4.1.5923.1.1.1.6eppn or eduPersonPrincipalNamex057@lehigh.edu
urn:oid:1.3.6.1.4.1.5923.1.1.1.7eduPersonEntitlementurn:mace:dir:entitlement:common-lib-terms
urn:oid:1.3.6.1.4.1.5923.1.1.1.1eduPersonAffiliationalum, employee, member, staff, faculty, student, affiliate, library-walk-in1
urn:oid:1.3.6.1.4.1.5923.1.1.1.5eduPersonPrimaryAffiliationstaff
urn:oid:2.5.4.3

commonName

Test Account
urn:oid:2.16.840.1.113730.3.1.241displayNameTest Account
urn:oid:2.5.4.4Last Name (sn or surname)Account
urn:oid:2.5.4.42First Name (givenName)Test
urn:oid:1.3.6.1.4.1.5923.1.1.1.10eduPersonTargetedIDdffd47824f4baccd481469fa428231f1f6e04
urn:oid:1.3.6.1.4.1.5923.1.1.1.9eduPersonScopedAffiliationalum@lehigh.edu, staff@lehigh.edu, student@lehigh.edu
1.3.6.1.4.1.5923.1.1.1.16eduPersonOrcidhttp://orcid.org/0000-0002-1825-00972

Notes:

  1. Library-walk-in isn't currently used at Lehigh.
  2. eduPersonOrcid isn't currently included in our attributes.

A good discussion of the attributes and their mapping and usage can be found in the REFEDS eduPerson standard.



  • No labels