In order for SWAMID to work as effectively as possible for students and employees as well as for service providers and identity providers, SWAMID recommends that service providers use entity categories to get the attributes that they require.
In order for services within the SWAMID federation to work as effectively as possible, SWAMID recommends the use of entity categories. Entity categories benefits not only students and employees but also administrators of relying and identity providers by providing a stable framework for the release of attributes.
During autumn 2019, SWAMID has updated its entity category recommendations and these will be implemented in our production environment during 2020.
This service is designed to help administrators of identity providers verify that their IdP follows the new recommendations.
SWAMID’s current recommendations for attribute release are available at https://wiki.sunet.se/display/SWAMID/SAML+WebSSO+Service+Provider+Best+Current+Practice.
Example configuration for Shibboleth can be found in the section entitled “Example of metadata configuration, attribute resolvers and attribute filters” on the following wiki page https://wiki.sunet.se/display/SWAMID/SAML+WebSSO+Identity+Provider+Best+Current+Practice.
A new version of the ADFSToolkit will be released which will help ADFS IdPs to follow the new recommendations.
The SWAMID best practice attribute release check consists of the following tests: