...
The R&S attribute bundle consists of the following attributes:
refedsNonPrivateUserID
: a non-private user identifierrefedsPersonName
: a person namerefedsEmailAddress
: an email address
These attributes are "above-the-wire" attributes intended solely to facilitate attribute release. See: REFEDS Attribute Registrywhere non-private user identifier is a persistent, non-reassigned, non-targeted identifier defined to be any one of the following:
eduPersonPrincipalName
(if non-reassigned)eduPersonPrincipalName
+eduPersonTargetedID
and where person name is defined to be any one of the following:
displayName
givenName
+sn
(surname)
and where email address is defined to be the mail
attribute.
6. Attribute Request
If a Service Provider requests an R&S attribute, the Identity Provider is REQUIRED to release it. Thus one or more R&S attributes MUST be listed in Service Provider metadata, otherwise the Identity Provider may release nothing at all.
...