SAML entities of eduID.cz members provide their metadata conforming to and . In addition, their metadata must fulfill to the requirements specified in this document.
Prefix
Namespace URL
the root element must contain the attribute
must be defined as a URL with scheme
hostname in URL must be a fully qualified domain name (IP address, „localhost“ and other reserved domain names according to RFC are not acceptable)
endpoints
must be defined as URLs with the scheme
their hostnames must be provided as fully qualified domain names
the hostnames must be registered by the organization operating the pertinent Entity
public keys of Entities
should be provided as self-signed X.509 certificates (Note: eduID.cz stops publishing an EntityDescriptor as soon as the validity of any of its certificates becomes shorter than 30 days)
should be RSA public keys with minimal length of 2048 bites
element
Every must contain exactly one element
describes organization operating the Entity, not project names, department names - for those use mdui elements
must contain element with the official name of the organization operating the Entity in English and in Czech, usage of abreviation is strongly unrecommended
must contain element with the commonly recognized name of the organization operating the Entity in English and in Czech, usage of abreviation and legal form is strongly unrecommended
must contain element specifying the location with additional information about the organization operating the Entity in English and in Czech
every must contain at least one element with „“ containing , and refering to a technical contact person with a working email address
Role Descriptors
each , , should contain with containing at least the following elements:
with the display name of the entity in English and in Czech, usage of abreviation and legal form is strongly unrecommended
with the description name of the entity in English and in Czech
must contain containing
the value of must be unique - preferably the main registered DNS domain of the organization operating the pertinent IdP
at least one
at least one must be
at least one should be , it is strogly advised to support persistent NameIDFormat
must contain with containing
with the commonly recognized name of the organization operating the Entity in English and in Czech
usage of abreviation is strongly unrecommended
usage of legal form is strongly unrecommended
if there are any organization units, they should be writen from most significant to less significant (ie. CESNET, Department of Standartization)
with short description of the purpose of IdP in English and in Czech
with URL holding more informations about the IdP in English and in Czech, not about the organization running the IdP
with HTTPS (!) URL holding logo of the organization operating the Entity
English and Czech version of the logo is posible if needed
there should be at least one version of the logo disignated to operated by eduID.cz with height 40px
entity requesting to be republished into eduGAIN must provide those elements
must contain with containing
with the display name of the entity in English and in Czech, ussage of abreviation and legal form is strongly unrecommended
with the description of the entity in English and in Czech
this information might be used at an IdP to inform users about purpose of the SP
with URL holding more informations about the SP in English and in Czech, not about the organization running the SP
each should contain that lists all attributes requested by this SP as element with „“ for required attributes and „“ for just usefull attributes