If you want to allow other universities or research entities to access your application via federated authentication, you can publish your application (Service Provider or SP) with the InCommon Federation. You do not need to register with InCommon if you are only authenticating UC Berkeley affiliates or sponsored guests.
Onboarding an InCommon SP requires a working SSO integration using SAML. Common scenarios include using the Shibboleth SP or SimpleSAMLphp client with your application.
Registration Steps
Collect the information listed below and open a ticket by emailing calnet-admin@berkeley.edu. An InCommon site administrator will verify your data and contact you with next steps.
- Designated SP Contacts: Provide the name and email address for the following roles. We strongly recommend using email lists or aliases rather than individual addresses.
- Technical Contact: For communication regarding technical issues (Required).
- Administrative Contact: For communication regarding non-technical issues (Required).
- Security Contact: For communication regarding security matters (Required).
- Support Contact: For end-user technical support (Recommended).
- Display Name: A user-friendly name for your SP (Required).
- Service Description: A brief description (140 characters or less) of the service provided (Recommended).
- Information URL: A URL where users can read more about your service (Recommended).
- Privacy Statement URL: A link to your online privacy statement. UC Berkeley SPs should generally use the official Privacy Statement for UC Berkeley Websites (Required).
- Logo URL: An
httpslink to a logo representing your service. Please provide the width and height in pixels. (Required).
Logo Guidelines:- Transparent background.
- Landscape orientation (width > height).
- Minimum width: 100 pixels.
- Height: Minimum 75 pixels, maximum 150 pixels.
- Discovery Response Endpoints: If using the Centralized Discovery Service (WAYF/IdP chooser) or another service using the IdP discovery protocol, include your
DiscoveryResponseendpoint(s). - Attribute Release: Indicate which attributes your SP requires from InCommon IdPs. You may select up to six (Recommended):
common name (cn)displayNameeduPersonAffiliationeduPersonEntitlementeduPersonPrincipalName (ePPN)eduPersonScopedAffiliationeduPersonTargetedID (ePTID)givenNamemailorganizationName (o)surname (sn)
- SP Metadata: Attach your SP metadata file to the ticket (Required).
Questions? Contact the CalNet team at calnet-admin@berkeley.edu for assistance with federated authentication.