The Keystone connections page configures how OpenAthens products like Keystone work in multiple federations. SAML applications such as Shibboleth don't have a separate connection here because their appearance in other federations isn't managed by us.
Connection details
Existing Keystone connections are displayed in a list. Each connection is shown as a “card” including key details, such as the entityID of the connection, the number of applications linked to the connection, and the federations or 1:1 (bilateral) connections to which it provides access. There are also options to edit or delete the connection.
Sort connections
You can sort the list of connections either alphabetically by name or alphabetically by entityID. Sorting by name is the default.
-
Open the Sort by drop-down menu above the list of connections.
-
Choose whether to sort by Name or by entityID.
The list automatically updates to show your chosen sort order.
Edit a connection
To configure a connection, click on its name in the list. You are taken to a page that shows the details of the connection.
You can change the following settings:
Application
The application record(s) using this connection.
Rules (OpenAthens Keystone only)
Allows you to toggle rule sets on and off. Changes take place immediately after saving.
-
Common EduPerson and Extended EduPerson translate the attribute names commonly used in educational federations to OpenID Connect claims. See eduPerson attributes
-
Affiliation and scope derived from EduPersonScopedAffiliation extracts useful identifiers from the main eduPerson attribute used in federations
SAML connector
Entity
This is the entityID of your application and defaults to https://sp.{domain}/entity. If you change this, make sure to save changes and confirm the page has updated. You almost certainly will not want to change the entityID once you are live.
The three-dots menu gives you access to view the entity metadata. You can download the metadata or copy the published address to send to federations you are joining or to direct 1:1 connections.
The entity metadata has two options for logos. Inline (the default) stores logo and banner as base64 encoded png images in the metadata. Hosted presents the banner as a URL and drops the logo. The reason for this choice is that some federations require logos to be hosted rather than embedded.
Certificate
This is your metadata certificate. The same certificate is used for signing and encryption. A federation might ask you to confirm its thumbprint when you register with them.
The three-dots menu gives you access to view the certificate details.
Privacy policies
Allows you to add and remove links to your privacy policy in the metadata. You can specify one link per language.
Depending on your memberships, linking to a privacy policy may be recommended or required. It is required if you assert the GÉANT Data Protection Code of Conduct entity category.
-
Press Add a privacy policy.
-
In Enter URL, type or paste the address of your privacy policy.
-
Select the language of the policy from the drop-down selector.
-
Press Add policy.
OpenAthens Federation
Allow sign-in for live OpenAthens identity providers
This signals inclusion in the OpenAthens Federation once the application is set as live on the application page and approved. The application will then be visible to all OpenAthens IdPs.
Other federations
This section lists other federations you might join. If you switch a federation to On, its metadata will be added to your configuration. Setting the switch does not register you in that federation and you will still need to take steps to join. See Enabling federations and How to join other federations.
1:1 connections
In this section, manage your connections with SAML IdPs that are not in a common federation. (It is up to you to decide whether it is easier to join any given federation than to configure IdPs separately.). See Entities that are not in a federation.
See also
Entity categories
This section allows you to indicate in your metadata which entity categories you support. After saving, you'll be able to see changes immediately in the internal metadata view, but it will take up to six hours for them to appear in the published OpenAthens Federation metadata. You will need to report the changes to any other federations in which you are registered. (Education federations that include you via eduGAIN will pick up the change from the federation in which you are registered.)
Since most entity categories signify compliance with a set of rules or behaviors, it's best to leave these turned off until everything else is in place.