SAML entities of eduID.cz members provide their metadata conforming to and . In addition, their metadata must fulfill to the requirements specified in this document.
- the root element must contain the attribute
- must be defined as a URL with scheme
- hostname in URL must be a fully qualified domain name (IP address, “localhost” and other reserved domain names according to RFC are not acceptable)
- endpoints
- must be defined as URLs with the scheme
- their hostnames must be provided as fully qualified domain names
- the hostnames must be registered by the organization operating the pertinent Entity
- public keys of Entities
- should be provided as self-signed X.509 certificates (Note: eduID.cz stops publishing an EntityDescriptor as soon as the validity of any of its certificates becomes shorter than 30 days)
- should be RSA public keys with minimal length of 2048 bites
- element
- Every must contain exactly one element
- describes organization operating the Entity, not project names, department names - for those use mdui elements
- must contain element with the official name of the organization operating the Entity in English and in Czech, usage of abreviation is strongly unrecommended
- must contain element with the commonly recognized name of the organization operating the Entity in English and in Czech, usage of abreviation and legal form is strongly unrecommended
- must contain element specifying the location with additional information about the organization operating the Entity in English and in Czech
- every must contain at least one element with “” containing , and refering to a technical contact person with a working email address
- Role Descriptors
- each , , should contain with containing at least the following elements:
- with the display name of the entity in English and in Czech, usage of abreviation and legal form is strongly unrecommended
- with the description name of the entity in English and in Czech
- must contain containing
- the value of must be unique - preferably the main registered DNS domain of the organization operating the pertinent IdP
- at least one
- at least one must be
- at least one should be , it is strogly advised to support persistent NameIDFormat
- must contain with containing
- with the commonly recognized name of the organization operating the Entity in English and in Czech
- usage of abreviation is strongly unrecommended
- usage of legal form is strongly unrecommended
- if there are any organization units, they should be writen from most significant to less significant (ie. CESNET, Department of Standartization)
- with short description of the purpose of IdP in English and in Czech
- with URL holding more informations about the IdP in English and in Czech, not about the organization running the IdP
- with HTTPS (!) URL holding logo of the organization operating the Entity
- English and Czech version of the logo is posible if needed
- there should be at least one version of the logo disignated to operated by eduID.cz with height 40px
- entity requesting to be republished into eduGAIN must provide those elements
- must contain with containing
- with the display name of the entity in English and in Czech, ussage of abreviation and legal form is strongly unrecommended
- with the description of the entity in English and in Czech
- this information might be used at an IdP to inform users about purpose of the SP
- with URL holding more informations about the SP in English and in Czech, not about the organization running the SP
- each should contain that lists all attributes requested by this SP as element with “” for required attributes and “” for just usefull attributes