The Virginia Tech Shibboleth project supports federated identity management among higher education and related institutions. Virginia Tech is a member of the popular InCommon federation. Most members of a federation participate in two distinct, complimentary roles:
A list of Shibbolized services available to InCommon federation members is available on the InCommon Wiki.
The VT Shibboleth IDP provides two principal services:
Authentication is currently available only to VT users with an active PID account. Attribute release is governed by a policy that can be defined at the scope of all service providers, federation member service providers, individual service providers, or any combination thereof.
There are currently two policy rules in effect. In all cases, no personally-identifying information is released to any service provider such that they could, individually or collectively, identify an end user based on any or all attributes.
The following attributes are released to all service providers.
The IDP releases the following attributes to any InCommon service providers:
Since the vocabulary of the eduPersonAffiliation attribute, and consequently the eduPersonScopedAffiliation attribute, is controlled, the vocabulary of VT affiliation values must be mapped onto eduPerson schema values before release. Following is an interpretation of the official attribute mapping found in the attribute-resolver.xml configuration file used by the Shib IDP:
| VT Affiliation | eduPerson Affiliation(s) |
|---|---|
| VT-STUDENT-ENROLLED | student, member |
| VT-EMPLOYEE-STATE | employee, member |
| VT-EMPLOYEE-WAGE | employee, member |
| VT-STUDENT-WAGE | employee, member |
| VT-STAFF | staff, employee, member |
| VT-FACULTY | faculty, employee, member |
| VT-ALUM | alum |
| VT-STUDENT-FUTURE | affiliate |
| VT-STUDENT-RECENT | affiliate |
| VT-EMPLOYEE-NON-STATE | affiliate |
| VT-EMPLOYEE-PREHIRE | affiliate |
| VT-EMPLOYEE-RETIREE | affiliate |
| VT-EMPLOYEE-TEMPORARY | affiliate |
| VT-EMPLOYEE-VOLUNTEER | affiliate |
| VT-AFFILIATE-TEMPORARY | affiliate |
Any VT affiliations not mentioned in the above mapping are ignored and not released.