The Pairwise Subject Identifier is a long-lived, non-reassignable, uni-directional identifier suitable for use as a unique external person identifier (key). Its value for a given subject depends upon the relying party to whom it is given, thus preventing unrelated systems from using it as a basis for correlation.
Note: While this attribute is supported by SAFIRE’s infrastructure, it is not yet included in the list of officially supported attributes.
Attribute Definition
Friendly Name | pairwise-id |
---|---|
OID | urn:oasis:names:tc:SAML:attribute:pairwise-id |
Description | The Pairwise Subject Identifier is a long-lived, non-reassignable, uni-directional identifier suitable for use as a unique external person identifier (key). Its value for a given subject depends upon the relying party to whom it is given, thus preventing unrelated systems from using it as a basis for correlation. Note: While this attribute is supported by SAFIRE’s infrastructure, it is not yet included in the list of officially supported attributes. |
Format | Single valued, scoped, case-insensitive. Syntax per section 3.4 of the SAML V2.0 Subject Identifier Attributes Profile. The scope portion must match one of the pairwise-id is generated by the Federation Operator if a corresponding subject-id is sent by the home organisation. |
References | |
Example | |
Additional Notes | The pairwise-id consists of two parts in the form In SAFIRE’s case, the uniqueID consists of a SHA256 hash of the supplied |