Version 60 (modified by dabantz@…, 12 years ago) (diff) |
---|
University of Alaska
Identity Provider attribute release information &
Privacy Statement regarding your data
One of the most powerful aspects of Shibboleth-based Identity Provider (IdP) is the ability to release selected information about the person to a relying application. A relying application will not see your username and password but instead refer you back to the UA IdP to authenticate ("log in"). If you successfully authenticate ("log in") to the IdP, the IdP asserts a set of attributes about you back to the relying application using a standard protocol (SAML). Different applications can receive different information; in fact, some applications will not receive personally identifiable information about the person that has authenticated. The most current version of this document is actively maintained at https://iam.alaska.edu/trac/wiki/IamUaArp
Permission to release information about you:
If upon review of this information you do not want to release the indicated attributes about you to a service, you should not use (log into) that service.
Re-use or distribution of information about you:
Although the attributes released to a service are deemed necessary to appropriately use that service, that is the only purpose for which they are released. Any subsequent re-use for other purposes is not allowed; if you detect such misuse of your information, contact iam@…
Attributes
The following explains some of terminology related to our attribute release policies. Other attributes based on data in the UA Directory (EDIR) (e.g., major, email addresses, office location, employee type) could be released as and if appropriate for other applications.
Note that only the selected attributes indicated by the name of each service are sent to that service; if an attribute is not listed, it is not sent to that service. For a full list of your University of Alaska attributes as seen by the Identity Provider, click on this link and log in with your UA credentials:
eduPerson attributes - these attributes defined in national standards provide identifiers in specific formats and indications of your relation to the University
eduPersonAffiliation - one or more of the following: Student, Employee, Staff, Faculty, Member, or Affiliate. Member designates a person who is part of the University of Alaska and generally entitled to information services, even if not formally a student or employee; it includes campus-based researchers with external funding, faculty emeriti, and some others. Affiliate designates merely that the person has a record in the UA IdP, but is not automatically eligible for services, and may be used for those with a limited specific affiliation with UA such as short-term guests.
eduPersonEntitlement - permissions or entitlements based on your role(s) at UA; may additionally be scoped to a department or (in the future) course. For example: for a student in Chemistry at UAF-main campus, learner@urn:mace:alaska.edu:itunesu:UAF - Main Campus:Chemistry
eduPersonInstitutionalMail - An email address assigned to the individual in the alaska.edu domain, Distinguished from email by requirement of UA domain ("...@alaska.edu") and from EPPN and eduPersonUnique ID in that it is intended for use by services to send email to users within the domain: delivery (directly, via email routing, or via forward) to a mailbox under control of the user. [in draft awaiting formal approval from standards body]
EPPN (eduPersonPrincipalName) - A unique identifier comprised of your UA username followed by "@alaska.edu"; while it has the look of an email address, it does not signify that this is a valid email address or your preferred email address; example: jpjones3@alaska.edu.
eduPersonTargetedID - An opaque identifier unique to the combination of the authenticated person and the application; because it is different for each application, and does not itself reveal the identity of the user, it enables the application to track preferences or make bookmarks for the user, but does not enable that use information to be correlated with use in other applications or to a real person; example: 84e411ea-7daa-4a57-bbf6-b5cc52981b73
eduPersonUniqueID - A non-changing unique identifier - specifically, not changing upon change of name or role at UA - scoped to alaska.edu; syntax is UA ID#@alaska.edu; example: 30123456@alaska.edu. [in draft awaiting formal approval from standards body; currently relased as uakPersonID]
Group Memberships & Roles
edirRole - roles defined within the UA Enterprise Directory that convey elevated privileges or permissions; examples: DEPTADMIN, SPONSORACCOUNT, HELPDESK
eduIsMemberOf - group membership recorded in the UA Enterprise Directory; often used to express privileges or permissions in other services; example: cn=appusers:onbaseprep:ad_confidential,ou=group,dc=alaska,dc=edu
adIsMemberOf - group membership recorded in the UA Domain (Active Directory), usually assigned programmatically on the basis of UA campus and/or role; example: CN=UAA_Students,OU=UAA,DC=ua,DC=ad,DC=alaska,DC=edu
Names any of the following may be provided, depending on the requirements of the service
common name - usually a combination of given name and surname; may be multi-valued to include preferred first name and middle initial; example: William Smith, William A Smith, Bill Smith
display name - a concatenation of your first and last name; it is based on your legal surname and preferred first name as recorded in UA's Human Resources and/or Student Information Systems (Banner); example: John Doe.
given name - legal individual or first name; example: William
surname - legal family or last name; example: Smith
email - an email address indicated as your preferred email address in the UA Enterprise Directory; it may or may not be an @alaska.edu address; examples: gene.kelly@alaska.edu, peterq@arsc.edu
mailRoutingAddress - the email destination address to which email to other recorded addresses is delivered (routed); for most people, mailRoutingAddress is the email account issued to you by your campus, but users may change this address in the UA Enterprise Directory; unlike the email (mail) attribute, it is always single-valued.
telephone number - phone number as recorded in the UA Enterprise Directory; in international format starting with "+" and country code, no punctuation other than spaces; example: +1 907 474 0123
UA identifiers
UA ID# (released as bannerId)- the unique numeric identifier assigned to all employees and students ("employee ID#", "student ID#") commonly used for UA login and account ids; example: 30123456
UA Username (released as uaSystemID) - the unique name-based identifier commonly used for UA login and account ids; example: jpmorgan
uakPersonID - see eduPersonUniqueID. UA-defined unique identifier using UA ID# parallel to the name-based EPPN, but using the unchanging numeric ID # assigned to all students and employees; intended to substitute for EPPN when the Service Provider needs an unchanging identifier for each user; example: 30123456@alaska.edu
uaSystemLegacyID - usernames based on the prior UA convention that is used in some legacy systems, based on one letter designation of your MAU (a, f, j, s), role (s, f, n, x, h) and initials; examples: asabc2, fxpqr
UDCID (Banner UDC Identifier) - an unchanging, Banner-generated, 32-character, alphanumeric value; it is an opaque (not intended to be human-readable) identifier used in Banner-related applications; example: GXgX9A£4LhGpthOsuyjvu-SKmae2IRzo
UA faculty/staff info
assignmentCount - UA employee's number of current assignments or jobs; value of 1 is typical and indicates an active employee; value of 0 indicates an employee with no current assignment or job, such as an occasional employee, adjunct faculty not currently teaching, faculty on sabbatical or other leave.
dlevel - code from Banner HR indicating an employee's home department; examples: D8ARCH, D1ASHE. More human-friendly attributes are uakEmployeeDepartment, uakEmployeeAffiliation
employee type - indication of employment category from HR record, examples: Exempt Staff - Regular or Faculty - Regular - <12 month
title - working or informal title at UA; examples: Professor of Biology or Instructional Designer
TKL - "Time Keeping Location" from employees' HR record; example: T801; deprecated for non-HR use or authorization because it has no firm connection to the employee's department, work location, or role, but rather indicates one of the locations at which time cards were historically collected and paychecks distributed.
uakEmployeeDept - department name of an employee's home department from personnel record in Banner HR; example: CLA Philosophy & Humanities
uakEmployeeCampus - campus to which the employee's home department belongs; example: UAF Main, UAA Kenai Peninsula College
uakEmployeeAffiliation
uakEmployeeFacultyAffiliation - academic program(s) in which a faculty member is currently an instructor of record; note that program names are not identical to department names; examples: UAF - eLearning & Distance Ed|Philosophy, UAF - Fairbanks Campus|Biology & Wildlife
UA student info
creditHoursCurrent - current student enrollment in credit hours; some services may require a minimum number of credit hours
uakStudentCampus - campus(es) providing courses in which a student is currently enrolled or has a major declared; note that these campus names from Banner SIS are not identical to the names from Banner HR for employee campus; examples: UAF - Fairbanks Campus , UAA - Kenai Peninsula Campus
uakStudentDept - academic program(s) in which a student is currently enrolled or has declared a major
Applications
The following applications rely on the UA IdP for authentication and receive the information (attributes) indicated upon successful authentication (login).
ARSC - EPPN
AskUA, aka Right Answers (Help Desk Knowledgebase Portal): UA Username, group membership, eduPersonAffiliation
Atomic Learning (instructional videos) : surname, given name, UA ID#, EPPN, email, eduPersonAffiliation, and "AtomicLearningCampus" (combined set of values of uakStudentCampus and uakEmployeeCampus)
Blackboard Connect (Emergency Communications) EPPN, UA ID#, givenName, surname [released under specific attribute names required by this vendor: BBConnectFedID, ContactRefCode, FirstName, LastName]
CTSI (Clinical and Translational Sciences) - see IndianaCTSI
Data Cookbook (Data analysis, limited to licensed users) - bannerID
DigitalMeasures? (Faculty activity reporting) - EPPN
DocuSign (electronic signatures) - EPPN (in test)
Dreamspark (Microsoft's full suite of software development tools): (none!)
EDUCAUSE (EDUCAUSE Portal): eduPersonTargetedID (PersistentID), EPPN, surname, givenName, email, eduPersonScopedAffiliation (affiliation@alaska.edu)
eduroam (roaming wireless network access) Attributes released by UA IdP: EPPN
EZProxy (access to UAF Rasmuson Library licensed scholarly databases): EPPN, eduPersonEntitlement and standard values of eduPersonAffiliation
Faculty180 (Faculty Activity Reporting) UA ID#, common name, givenName, surname, email
GINA EPPN
Google (Google Apps for Higher Ed, including email, calendar, docs; currently only in proof-of-concept): UA Username
IAM @ UA - this IAM wiki - EPPN
IndianaCTSI (research, research grant, and collaboration tools): EPPN (researchers will be promoted to provide name and email to the service)
Internet2 mailing lists eduPersonAffiliation, email
iTunesU (University of Alaska section for podcasts in Apple's iTunes): EPPN, Transient ID, eduPersonTargetedID (old format), eduPersonEntitlement
InfoEd (research administration): EPPN, UA ID#
Intellex (Environmental Health & Safety training): UA Username, UA ID#, email
Kuali Ready (Disaster Recovery Planning) UA ID# scoped, displayName, given name, surname, email, telephone number
NSF (National Science Foundation, including FastLane for PIs): EPPN, given name, surname, common name, email
NIH (National Institutes of Health resources; services tbd): given name, surname, email
Parking @ UAF : EPPN, UA ID#
People.alaska.edu - web gateway for UA Enterprise Directory: uaUsername
Shibboleth.net (wiki and issues tracking for Shibboleth project) - EPPN, givenName, sn, cn,
Spaces (Internet2 wiki at spaces.internet2.edu): EPPN, eduPersonEntitlement and standard values of eduPersonAffiliation
Staff Council @ UAF : EPPN, UA ID#, given name, surname, email, telephone number, employee type, TKL, title, employee affiliation
Study Abroad @ UAF : UA ID#, given name, surname, email,
TAB @ UAF : UA ID#, EPPN, display name, email, telephone number, employee affiliation, eduPersonAffiliation
Trac (wiki, technical documentation and internal tracking for IAM-related projects): EPPN
UAA Tickets : cn (common name), displayName, eduPersonAffiliation, mail, uakStudentCampus, creditHoursCurrent
UAlaska network (authenticated access to UA wired network): EPPN
Win for Alaska (Wellness programs for UA Employees): EPPN