Home
Other Configuration

Register Bridge With InCommon

How to register your Cirrus Bridge with the federation.

Requirements

To register the Cirrus Bridge as an InCommon Identity Provider, you will need:

  • Access to InCommon Federation Manager as a “Site Administrator” (SA)
  • Parameters specific to your organization’s Cirrus Bridge deployment
  • Contact, policy, & branding information for your organization
Tip

To get access to Federation Manager, follow the Federation Manager Guide.

For those organizations that have previously registered with InCommon, it is generally recommended that you update your IdP instead of registering a new one. Changing your Entity ID with InCommon can be very disruptive.

Cirrus Bridge Parameters For InCommon Registration

Once the Cirrus Bridge instance is provisioned, Cirrus will provide parameters to register the identity provider with InCommon.

ParameterDescription
Entity IDThe unique ID for the identity provider. It must be in your domain.
Attribute ScopeGenerally the root domain for the organization.
SAML SSO Binding EndpointThe Bridge supports both HTTP-Redirect and HTTP-POST for performing SSO.
SAML SLO Binding EndpointThe Bridge supports advertising a single-logout endpoint, but SLO must also be configured between the source authentication provider and the Bridge.
CertificateThe certificate Bridge will use to sign and encrypt assertions.
Error URLThe errorURL can either be the default page provided by Cirrus Bridge, or a static URL hosted by the organization.
Tip

The default error URL provided by the Cirrus Bridge supports the basic functionality specified by REFEDS.

Contact, Policy, & Branding

Before registering, the Site Administrator should also have the following information ready:

SettingExampleDescription
ContactsAdministrative: alice@example.edu
Technical: iam@example.edu
Security: iso@example.edu
Contacts for the identity provider. All should be for your organization.
Display Name“Example University”The display name for the identity provider.
DescriptionThe main identity provider for Example University.A short description for the identity provider.
Information URLhttps://www.example.eduA link to provide information about the Identity Provider. Many organizations will use their primary website.
Privacy URLhttps://www.example.edu/privacyA link to a privacy policy that covers the identities asserted by your organization.
Logohttps://branding.example.edu/logo.pngAn organizational logo hosted on a website & directly available from a URL (redirects are not supported by InCommon). Cirrus Bridge does not support hosting a logo.
Assert R&S SupportN/ACirrus recommends asserting R&S support. See Declare R&S Support for details.
Assert SIRTFI ComplianceN/AThe provder cannot be registered without SIRTFI compliance. See Declare SIRTFI Compliance for details.
Export MetadataN/ACirrus recommends exporting metadata to eduGAIN. See Metadata Export Options for details.

Registration Process

After logging into Federation Manager, you should see a button to add an identity provider.

This will start a wizard that will ask you for the values needed to register (noted above). Many of these values are required as set by InCommon Baseline Requirements.

Submission

Once all data has been entered, review & submit your registration to InCommon.

Depending on the time of day the submission takes place, the metadata will be published by InCommon within 24 to 72 business hours. It can take an additional 24 to 48 hours for metadata to propagate to applications reliant on the global eduGAIN metadata service.

See Metadata Service for the latest information on the submission & publishing process.