Switch edu-ID Resource Registry

The Resource Registry is a tool developed by Switch to manage information about Resources and Home Organizations participating in Switch edu-ID, the so-called Federation Metadata.

Resource Registry Diagram

Its intended audience are Service (Resource) and Home Organization Administrators.
It is accessible via https://rr.aai.switch.ch/ and requires a Switch edu-ID enabled account.

Purpose

The Resource Registry serves multiple purposes:

Resources declare their Attribute Requirements

Within his entry in the Resource Registry, a Resource Administrator specifies which attributes the Resource needs to get for a user in order to provide access. In addition, attributes desired to get can be listed. Desired attributes should provide additional benefit to justify their use.
The data protection principle counts: Process only data which is really necessary!

Resources declare the Intended Audience

A Resource administrator can also specify to which audience the resource is of interest, i.e. from which Home Organizations it will accept users.
For example, a Resource is only of interest to medical students. Then, there is no point in adding that Resource to the metadata of the universities of applied sciences.
However, it is still the duty of the Resource to configure its authorization rules properly!

Federation Members can control Resources in their Domain

Each Resource needs to get approved before its entry in the Resource Registry gets activated. Each Home Organization approves Resources from its domain and from Federation Partners it sponsers. It delegates this control to a number of people who act as 'Resource Registration Authority Administrators' for the Home Organization.
They get an alert by e-Mail, whenever approval is required for a new Resource or for changes to an existing Resource entry.

Home Organizations declare which Attributes they support

Not all of the attributes specified for Switch edu-ID are mandatory to implement. The Home Organizations can document in their Resource Registry entry which ones are implemented in their IdP and potentially available to Resources.

Federation Metadata can be generated (SAML)

Based on the information collected, the SAML Federation Metadata files for the Home Organisation's IdP as well as Service Providers get generated.
Each IdP needs to know all potential Service Providers with whom it should communicate and vice versa.
Each IdP has to maintain an Attribute Release Policy (ARP) configuration. The Resource Registry provides them tailored templates for the attribute-release.