...
Federation operators have rules for entity registration to ensure a good user experience within that federation. These rules are typically published in a Metadata Registration Practice Statement. When we look at a wider ecosystem where multiple federation operators register SPs register SPs and IdPs, we need prioritization and selection rules. The rule that many people know about is about is the metadata combination rule in eduGAIN metadata aggregation, which enforces unique entityIDsunique entityIDs. HoweverHowever, unique entityIDs are not suTicient sufficient to provide a good user experience in an ecosysteman ecosystem. Accurate and complete metadata (such as DisplayName and logos) will help people help people select the appropriate IdP when logging in, although this still requires an individual to make to make the correct choice at login time. What if there was also a mechanism in metadata for an SP an SP to describe which IdPs it would prefer to interoperate with? This Entity Selection Profile aims Profile aims to provide that.
Building on earlier work from SeamlessAccess, we are developing a profile that can allow SPs to identify a set of IdPs, either by entityID or generically by registrationAuthority or entity attribute. They coined the term “trustinfo” although we’re realising it’s actually an entity selection profile. The first step is to define an entity attribute as a container for transporting selection rules and profiles. This step focusses on the current SAML environment.
...