Tuakiri has migrated from legacy tooling (Federation Registry run in combination with the SAML Service) to a new system, centered around the Metadata Tool, developed by SUNET (Swedish NREN) to operate SWAMID (Swedish R&E Identity Federation). This will allow Tuakiri to remove technical debt and provide access to new features and specifications developed by the international community.
The Metadata Tool also provides a web interface to submitting new SAML metadata for an IdP or SP, as well as for requesting changes to already published metadata. Authentication to the Metadata Tool is via Tuakiri, same as it was for Federation Registry. However, the way the metadata is submitted, as well as the processes to get the change reflected in published metadata, are different.
The Metadata Tool reuses the public hostnames originally used by the Federation Registry (as it still acts as the registry of entities registered in Tuakiri). The hostnames are:
The Metadata Tool first presents a landing page that does not require authentication and presents a read-only view of entities registered in Tuakiri (and also of entities accepted from eduGAIN).
To request a new registration or changes to an existing registration, follow the Access through your institution link and authenticate with your institutional login through Tuakiri. If your institution is not listed or you are not able to authenticate, please contact Tuakiri Support at tuakiri@reannz.co.nz
A new registration is started by uploading an XML file with the entity metadata. This file does not have to cover all details required by Tuakiri, but it is important it has all the required technical components (certificates and SAML endpoint URLs). Most SAML implementations produce such metadata, typically at a well-known URL.
For common implementations, the URLs take the following form (available at the specific hostname, using *.example.org as a placeholder here):
https://idp.example.org/idp/shibbolethhttps://sp.example.org/Shibboleth.sso/Metadatahttps://sp.example.org/simplesaml/module.php/saml/sp/metadata.php/default-sphttps or data: URL, plus the logo’s height and width.example.orgExample UniversityGivenName, Surname and EmailAddress.Validate the draft metadata.Request publication (either into Tuakiri only or Tuakiri and eduGAIN).After submitting the publication request, the Metadata Tool will send you an email confirming the request.
Forward this email to tuakiri@reannz.co.nz to trigger the next step.
A Tuakiri Service Desk team member will process the request and publish the metadata.
An existing entity registration can be updated by creating a Draft from the existing Published entity, making changes in the Draft copy, and submitting the draft for publication.
Request admin access. A request will be sent to technical and administrative contacts of the entity who will be asked to confirm your request.Validate the draft metadata.Request Publication of the updated metadata.Same as when submitting a new registration, the Metadata Tool will send you an email confirming the request.
Forward this email to tuakiri@reannz.co.nz to trigger the next step.
A Tuakiri Service Desk team member will process the request and publish the updated metadata.
It is also possible to request removal of published metadata.
Request removal of the metadata.Same as in the other scenarios above, the Metadata Tool will send you an email confirming the request.
Forward this email to tuakiri@reannz.co.nz to trigger the next step.
A Tuakiri Service Desk team member will process the request and remove the entity metadata.