Requirements for SAML2 Identity Providers

This page documents the history of SAFIRE’s Requirements for SAML2 Identity Providers and will display the most recent version. You should always reference this page when linking to the Requirements for SAML2 Identity Providers, unless you intend to link to a specific, versioned document.

Version History

Requirements for SAML2 Identity Providers v20161221 (Draft)

The following describes the technical and administrative checks that will be made before an identity provider is admitted into the SAFIRE federation within the SAML2 Technology Profile. It also serves as a checklist for identity provider operators for assessing their readiness to participate.

Metadata

  • MUST1 have an entityID that is a URL (well-known location). The URL SHOULD use the https scheme and it is RECOMMENDED that valid metadata be available at this URL.
  • MUST use secure (https) end-points for any md:SingleSignOnService or md:SingleLogoutService.
  • MUST contain shibmd:Scope elements detailing every possible scoping value (domain) for eduPersonPrincipalName and mail. These MUST NOT be regular expressions. All scopes MUST be valid DNS domain names and those domains MUST be owned by the organisation (or have written confirmation from the domain owner).
  • MUST contain an md:Organization element, where:
  • MUST contain at least one md:ContactPerson of contactType=“technical” and SHOULD contain one of contactType=“support”. Where md:EmailAddress is given this SHOULD be a role account rather than an individual.
  • SHOULD contain an mdui:UIInfo, with at least the following elements set:
  • It is RECOMMENDED that mdui:PrivacyStatementURL be set and point at the organisation’s privacy policy. This MAY be required in future.
  • It is RECOMMENDED that a mdui:Logo be provided. Any logo MUST be served from a secure (https) server. Logos SHOULD have an aspect ratio as close to 1:1 as possible and SHOULD be at least 100x100 pixels (although 300x300 is RECOMMENDED).
  • SHOULD NOT contain a mdrpi:RegistrationInfo element (any existing one SHALL be removed by the federation aggregator).
  • SAML certificates included in metadata SHOULD be self-signed.
  • Web server certificates used for end-points MUST use PKI that is reasonably likely to be embedded in the browser of all users of the identity provider. Unless an explanation is provided, these SHALL be tested against the root CA lists of common browsers.

Language and Localisation

The SAML metadata specification allows display elements such as md:OrganizationName to be localised by using the xml:lang attribute to specify a BCP 47 language code. In common with other federations worldwide, English (xml:lang=“en”) MUST always be included and will be used as the default when no localised version is available.

It is strongly RECOMMENDED that official translations of organisation, display, or service names be included in metadata. In particular, major South African languages such as isiZulu (zu), isiXhosa (xh) and/or Afrikaans (af) are encouraged.

Attributes

  • The minimum attributes MUST be provided for all users; the Federation hub will generate an error should these not be provided for a particular user.
  • Identity providers that wish to participate in inter-federation SHOULD provide all the recommended attributes.
  • It is strongly RECOMMENDED that identity providers provide as many attributes as they are able.
  • The eduPersonPrincipal name attribute supplied by the identity provider is used to generate a persistent NameID. For this reason,  in addtion to the eduPerson schema requirements, the eduPersonPrincipalName provided to the Federation MUST NOT be reassigned.

Technical

  • Clocks MUST must be synchronised via the Network Time Protocol (NTP; SNTP) or equivalent such that they ultimately derive their time from the South African master clock maintained by National Metrology Institute of South Africa or an acceptable alternative (e.g. za.pool.ntp.org).
  • Logs of successful authentications MUST be retained for at least 184 days.
  • Federation metadata SHOULD be refreshed at least once per day and MUST be refreshed at least once per cacheDuration.

Administrative

  • Participants that are not already signatories of the REN Service Agreement MUST provide documentary proof of legal name, by means of one of the following:
    • CIPC registration certificate;
    • Trust deed;
    • SARS tax clearance certificate;
    • NPO registration; OR
    • Any other mutually acceptable means.
  • Participants MUST have signed a Participation Agreement.
  • Written permission MUST be provided for the use domains in shibmd:Scope if not verifiable by whois.
  • Each entity must be accompanied by a separate registration request form, including:
  • Only one md:IDPSSODescriptor per juristic person will be registered.

  1. The key words “MUST”, “MUST NOT”, “REQUIRED”, “SHALL”, “SHALL NOT”, “SHOULD”, “SHOULD NOT”, “RECOMMENDED”, “MAY”, and “OPTIONAL” in this document are to be interpreted as described in RFC 2119. [return]

South African Identity Federation