| Description | Specifies the person's affiliation within a particular security domain in broad categories such as student, faculty, staff, alum, etc. |
|---|---|
| Format | The attribute is structured as a scoped attribute, with the form affiliation@security-domain, where affiliation is one of a number of prescribed categories of user.
Only these values are allowed to the left of the "@" sign: faculty, student, staff, employee, member, affiliate, alum, library walk-in. These are defined below. The values to the right of the "@" sign should indicate a security domain.
|
| Classification | Personal characteristics |
| Origin/ObjectClass | eduPerson |
| OID | 1.3.6.1.4.1.5923.1.1.1.9 |
| SAML attribute name | urn:mace:dir:attribute-def:eduPersonScopedAffiliation [Legacy Name and Syntax using the Structured Encoding rules] urn:oid:1.3.6.1.4.1.5923.1.1.1.9 [Uses Simple Encoding rules that are more compatible with vendor products] |
| LDAP syntax | directoryString [1.3.6.1.4.1.1466.115.121.1.15] |
| Number of values | Multiple |
| Example values | eduPersonScopedAffiliation: faculty@cs.berkeley.edu |
| Notes on usage | This attribute enables an organisation to assert its relationship with the user. This addresses the common case where a resource is provided on a site licence basis, and the only access requirement is that the user is a bona fide member of the organisation, or a specific school or faculty within it.
This attribute may appear suitable for controlling access to, for example, an academic licensed commercial software package. However, this is usually not the case; such licenses have greater constraints than just eduPersonAffiliation=faculty. In most cases an academic user must also agree to use the application for only academic purposes and perhaps accept obligations such as acknowledging the owners or reporting results in a particular way. |
| Notes on privacy | See privacy notes for eduPersonAffiliation. |
| Available | |
| Source | Static (see note) |
| Only "member" attribute value. UniSA doesn't currently support the full range of values available via this attribute. Currently only:
is supported. |
