eduPersonTargetedID
A persistent, service-specific pseudonym that opaquely but uniquely identifies the subject.
Note: While still in widespread use, this attribute is deprecated in favour of the newer (and better defined) pairwise-id.
Attribute Definition
| Friendly Name | eduPersonTargetedID |
|---|---|
| OID | urn:oid:1.3.6.1.4.1.5923.1.1.1.10 |
| Description | A persistent, service-specific pseudonym that opaquely but uniquely identifies the subject. Note: While still in widespread use, this attribute is deprecated in favour of the newer (and better defined) pairwise-id. |
| Format | Single valued, guaranteed unique for a specific service provider. Not transferable between different service providers. The name identifier value will not be longer than 256 characters in length, but the exact presentation (and thus length) of this attribute is defined by the service provider. eduPersonTargetedId is generated by the Federation Operator as a hash based on the home institution of the user, their incoming eduPersonPrincipalName, the entity ID of the service, and a secret value. Institutions or services that are in production and change one of these variables will cause a eduPersonTargetedID to be generated. This can cause users to lose access to their profiles, and is strongly discouraged. |
| References | |
| Example | |
| Additional Notes | eduPersonTargetedID is an abstracted version of the SAML V2.0 Name Identifier format of “urn:oasis:names:tc:SAML:2.0:nameid-format:persistent”. In SAML, this is an XML construct consisting of a string value inside a In SAFIRE’s case, the attribute consists of a While eduPersonTargetedID is transmitted as a |