IDEM – (IDEntity Management for authentication and authorization)/eduGAIN

About IDEM

The Università della Valle d’Aosta-Université de la Vallée d’Aoste has joined the IDEM Federation (IDEntity Management for federated access), aimed at setting up the Authentication and Authorizazion infrastructure of the GARR network, as well as the interfederation eduGAIN.

 

IDEM is the Italian national federation for universities and research institutions for authentication and authorisation, which grants access to a number of federated services using the institutional digital identity. For example, users can access electronic journals, data bases and any other resource made available by the Federation by logging in with the credentials they use for the other services offered by the University (email, Wi-Fi, etc.).

 

Click below to view the list of resources related to the IDEM GARR AAI Federation which can be accessed via the credentials provided by the University: IDEM Federation Resources

Members of the IDEM Federation agree to accept and comply with of the Acceptable Use Policies (AUP) for accessing and using the GARR network.

 

eduGAIN is the inter-federation service that connects identity federations worldwide and enables collaboration among them.

Access to eduGAIN is granted exclusively through an identity federation; therefore, participation requires membership in an existing federation. IDEM is a member of eduGAIN.

In addition to the standard eduGAIN authentication (invoked by each individual inter-federation service), the University of Valle d’Aosta provides, for certain services, an integrated eduGAIN authentication managed through a dedicated UNIVDA Service Gateway.

Who the Services Are Intended For

The IDEM service is intended for:

  • Academic staff
  • Technical and administrative staff
  • Students (currently enrolled)

The UNIVDA Service Gateway is intended for:

  • Users from universities federated through eduGAIN

Technical support

If you encounter any problems logging in, please contactsistemi@univda.it

How user attributes are released to resource providers

To access a specific resource within the IDEM/eduGAIN Federation, the University’s Identity Provider (IdP) must supply the resource provider with certain information (attributes) about the user attempting to log in; only the attributes strictly necessary are transmitted.

During the authentication process, the attributes requested by the resource are clearly displayed, and access to the requested service will be granted only upon the user’s consent.

The set of user information to be transmitted may vary from one resource to another.
The University’s Identity Provider (IdP) will send each resource only the information that the resource specifically requires.

The table below lists all the information that the University of Valle d’Aosta’s IdP may transmit to an IDEM/eduGAIN resource upon request:

 

Attribute   Meaning
sn Surname
givenName First name
employeeID Tax ID code
uid user name
mail Institutional email
userPrincipalName user name@domain name
eduPersonPrincipalName Identificativo univoco per l’utente
eduPersonScopeAffiliation Type of affiliation with the organization
eduPersonEntitlement One o more URI (URN or URL) to access to some resources
schacPersonalUniqueID A unique and legally recognized identifier associated with an individual, used within federated identity frameworks.
schacPersonalUniqueCode A unique and persistent personal identifier primarily used to transmit the European Student Identifier (ESI) within the Erasmus+ framework.
schacHomeOrganization A standard attribute used within identity federations to uniquely identify a user’s home organization.

The privacy policy applied by the Università della Valle d’Aosta-Université de la Vallée d’Aoste is available at the following link: Privacy Policy

To view the Data Protection Notice of the Università della Valle d’Aosta click here: Notice

Salva