AAI Demo
The scenarios and pages below are protected by AAI. They are proteced by the open source Shibboleth Service Provider software developed by the Shibboleth Consortium
When a user successfully logs to this service with edu-ID, user attributes can be used for authorisation and to display information about the user. This demo service is part of the edu-ID Test Federation, not the production edu-ID Federation.
Scenario | Description | Valid users | Invalid users |
---|---|---|---|
Demo Portal | Shows a very simple portal application, where logged-in users get customized content. |
demouser:demo demostudent:demo |
all unauthenticated users |
Any authenticated user Home Organization choice by Discovery Service |
Any properly authenticated user gets access. | demouser:demo demostudent:demo |
all unauthenticated users |
Any authenticated user | Any properly authenticated user gets access. | demouser:demo demostudent:demo |
all unauthenticated users |
Any student | All users with an affiliation "student" are authorized to access it. | demouser2:demo demostudent:demo |
demouser:demo demostaff:demo |
Staff from aai-demo-idp.switch.ch | All users with an affiliation "staff" and home organization "aai-demo-idp.switch.ch" are authorized to access it. |
demostaff:demo | demostudent:demo |
An explicit user | Only "demouser2" is authorized to access it. | demouser2:demo | all others |
Lazy session | Authentication is optional, but the application can enforce user authentication when it is needed. |
all users | - |
Re-authentication enforcement | Application enforce Re-authentication of the user at the IdP, although the IdP session is still valid. |
demouser:demo demo[1..50]:demo |
all unauthenticated users |
Passive authentication enforcement | Application enforce a passive authentication of the user at the IdP, means disallowing any user interaction on the IdP side. |
all authenticated users | all unauthenticated users |
Using a different account
Prior to switching to a different user account, quit and restart your web browser or use the private/incognito mode.
Information provided by this Service Provider