Configuring SAML-Based SSO with InCommon

RapidIdentity Platform Documentation

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

InCommon Federation Overview

The InCommon Federation provides single sign-on (SSO) access to services and global collaboration tools provided by educational institutions, research organizations, and commercial resource providers. RapidIdentity supports participation in the InCommon Federation through SAML 2.0 Federation Partners with the InCommon option enabled.

Configuring an InCommon Federation Partner

When you create a SAML 2.0 Federation Partner under Configuration > Security > Identity Providers > Federation Partners, the General menu includes an Is InCommon option. Enabling this option activates the InCommon feature and defines how frequently InCommon metadata is refreshed.

SettingDescription
Is InCommonWhen enabled, the federation partner participates in the InCommon federation. RapidIdentity refreshes InCommon metadata on the configured interval to reflect changes in any of the InCommon environments.
Metadata Refresh Interval (Hours) - InCommon OnlyThe frequency, in hours, at which RapidIdentity refreshes InCommon metadata. Valid range is 1 to 24.

Required Attributes for InCommon

InCommon SAML federation partner configurations require the following attributes to be released by RapidIdentity:

AttributeDescription
eduPersonPrincipalNameThe identifier corresponding to the name of the user.
eduPersonScopedAffiliationThe identifier corresponding to the user's relationship to the institution (for example, Student or Teacher).