The superior references for the namespace of "urn:mace:surf.nl:" can be found Internet2 MACE registry.


URN2e level3e level4e levelLeverancier / dienstentityID SP
urn:mace:surf.nl:attribute-def:

Door SURF(conext) gedefinieerde attributen

eckid:
ECK iD (Elektronische Content Keten) doorgeven via SURFconext. Voor details zie Attributen in SURFconext (NL).

surf-crm-id:

KlantGUID zoals opgenomen in het SURF CRM. Waarde is een (MS) GUID.

urn:oid:1.3.6.1.4.1.1076.20.100.10.50.2



surf-autorisaties:

Rollen en organisatie-id uit SURF Autorisatie Beheer


urn:mace:surf.nl:
          
sram:


sbs:allow-create-coEntitlement-waarde.  Gebruikes met deze waarde zijn geautoriseerd om een CO aan te maken voor hun instelling.SRAM
scim:extension:*SCIM SRAM schema
group:
*
Values for group memberships expressed as eduPersonEntitlements (as per AARC-G002)
label:
*
Values for collaboration labels expressed as eduPersonEntitlements
sram-acc:
group:
*
Values for group memberships expressed as eduPersonEntitlements (as per AARC-G002)

SRAM-acc

label:
*
Values for collaboration labels expressed as eduPersonEntitlements

sram-test:

group:
*
Values for group memberships expressed as eduPersonEntitlements (as per AARC-G002)

SRAM-test

label:
*
Values for collaboration labels expressed as eduPersonEntitlements
urn:mace:surf.nl:
surfconext.nl:
<Primair_domein_SP>:<Applicatie>:<Applicatie-Attributen>SURFconext
surfconext.nl:
surfsecureid.nl:

2fa:loa1.5
These values can used by an institution in the eduPersonEntitlement attribute of a user to trigger a corresponding SURFconext authorisation rule or Stepup rule to require said SURFsecureID level of assurance for the user.

SURFconext
2fa:loa2
2fa:loa3
nomfa
No MFA needed for the user
urn:mace:surf.nl:invite.surfconext.nl:<guid>
Used by SURFconext Invite for rolesSURFconext Invite
test.invite.surfconext.nl:<guid>
Used by SURFconext Invite for roles
urn:mace:surf.nl:
surfsecureid:
activation:

Limit the token activation methods that the user may choose from to the listed activation methods. 

  • If none of the recognised activation methods are specified, all activation methods are considered.
  • If the restriction would mean that no activation methods are available for a user, the RA method is offered.
SURFsecureID
ra

Allow the user to choose for activation by an RA

self

Allow the user to choose self activation


attribute-def: ssh-key 



urn:mace:surf.nl:stepup:gssp-extensions

XML Schema namespace used for UserAttribute SAML Extension in OpenConext-Stepup.