Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • http://www.swamid.se/policy/assurance/al1
  • http://www.swamid.se/policy/assurance/al2
  • https://refeds.org/assurance
  • https://refeds.org/assurance/profile/cappuccino
  • https://refeds.org/assurance/ID/unique
  • https://refeds.org/assurance/ID/eppn-unique-no-reassign
  • https://refeds.org/assurance/IAP/low
  • https://refeds.org/assurance/IAP/medium
  • https://refeds.org/assurance/IAP/local-enterprise
  • https://refeds.org/assurance/ATP/ePA-1m

SWAMID Identity Assurance Profile 3 without multi-factor authentication

A user that fulfils SWAMID Identity Assurance Level 3 Profile should be signaled as SWAMID Identity Assurance Profile 2 when not performing a multi-factor authentication.

SWAMID Identity Assurance Profile 3 including multi-factor authentication

A user that fulfils SWAMID Identity Assurance Level 3 Profile should get the following values in the attribute eduPersonAssurance:

...

Notice also that this section does not require that the departing user’s account must be removed or disabled; only that the affiliation attribute value as observed by the Service Provider is updated.

Technical implementation

SWAMID has published information in Swedish on how to configure release of assurance via the attribute eduPersonAssurance.