swedenconnect / technical-framework

Technical Specifications for the Swedish eID Framework
28 stars 3 forks source link

Add mappedPersonalIdentityNumber and mappedCoordinationNumber #167

Closed martin-lindstrom closed 3 years ago

martin-lindstrom commented 3 years ago

Currently there is an attribute set, eIDAS Natural Person Attribute Set, defined in Attribute Specification for the Swedish eID Framework.

This attribute profile declares that a personalIdentityNumber can be delivered if there is a mapping from the eIDAS ID to the Swedish personal identity number. This attribute is accompanied by the personalIdentityNumberBinding. There is a huge risk that an SP just grabs the personalIdentityNumber without checking whether the personalIdentityNumberBinding is acceptable.

Therefore we introduce two new attributes, mappedPersonalIdentityNumber and mappedCoordinationNumber to be used in this set instead of personalIdentityNumber.