ABCDEFGHIJKLMNOPQRSTUVWXYZAA
1
FeatureAcademicIDdidmosRegAppUnity
2
ProtocolsSAML SP/IdPyes/yesyes/yesyes/yesyes/yes
3
OIDC RP/OPyes/yesyes/yesyes/yesyes/yes
4
5
6
Group ManagementVO-based featuresyes, auto/manualyes, e.g. group managementyes, auto/manualyes; manual/semi-automated
7
Dataset-based authorisationyes, e.g. via RBAC and scriptable attributesyes, scriptable
8
External Datasourcesyes (synchronization)yes via synchronizationyes, for attribute import/exportyes for additional attributes
9
Scalabilityyesyeshorizontically, vertically, on-line maintenanceyes
10
Multi-TenancyyesyesFrontend-URL, UI-ThemesFrontend & theme, but not DN
11
12
13
MFAStep-Up/MFA Authenticationyes (PrivacyIDEA)yes (eduMFA)yes (privacyIDEA, LinOTP, eduMFA)yes
14
Pass on MFA upstreamin developmentin development
Request MFA from upstream
15
Pass on MFA downstreamin developmentin development
16
17
18
SystemSystem Requirements"as-a-Service" operations modelDeployment via Docker Containers or "as-a-Service" modelJava 11/17, JDBC-connectable SQL DB, LB ProxyJava, SQL DB
19
20
21
AccountsAutomatic User Deprovisionyes (via IDM Lifecycle processes)yes via didmos Provisioner with connectors to target systemsyes (AQs againt SAML-IdPs)in preparation
22
Account Linkingyesin developmentyesyes
23
Consent/Token Managementyes (user selfservice and administrative UI)Consent: yes via external module, Token Managment: yes, integratedin developmentyes
24
25
26
OIDCPublic Clientyesyesyesyes
27
Dynamic Client Registrationnocan be enabled on requestnono
28
Client Registration Procedureemail/manualemail / manualemail / manualwebpage / automated + approval
29
30
Infrastructure Proxy Funktionialität
yes (many use cases, especially for HPC)
31
G052Proxied Token Introspection
32
G061A specification for IdP hinting (obsoletes AARC-G049)
33
G062A specification for hinting an IdP which discovery service to use
34
G063A specification for providing information about an end service
35
36
Policy SupportPolicyAcademicIDdidmosRegAppUnity
37
Top Level Policyyesyes
38
Security Incident Response Procedureyesyes
39
Policy for the Processing of Private Datayesyesyes
40
Infrastructure Attribute Profileyesyesyesyes
41
Proxy Privacy Policyyesyes
42
Service Access Policy (optional)
43
44
Guideline SupportFeatureAcademicIDdidmosRegAppUnity
45
SirtfiCollect security contacts for every registered serviceyes (can be done in metadata)yesyes
46
G021Exchange of specific assurance information between Infrastructureyesyesyes
47
G025Guidelines for expressing affiliation informationyesyesyes
48
G026Guidelines for expressing community user identifiersyesyesyes
49
G027Specification for expressing resource capabilitiesyesyesyes
50
G031Guidelines for evaluating the combined assurance of linked identitiesno (in development)in developmentno
51
G045AARC Blueprint Architecture 2019yesyesyesyes
52
G057Inferring and constructing voPersonExternalAffiliationyesyesin preparation
53
G061A specification for IdP hinting (obsoletes AARC-G049)no nono
54
G062A specification for hinting an IdP which discovery service to usenonono
55
G063A specification for providing information about an end servicenoyes (but not according to specification)no
56
G069Expressing group and role information (supersedes AARC-G002)yesyesyes
57
G071Guidelines for Secure Operation of Attribute Authoritiesin preparationpartially
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100