Note: The eIDAS-berichtenservice does not support a portal service.

This interface is exclusively applicable to eIDAS Inbound, and NOT to eIDAS Outbound.


Incoming authentication

When the EB serves as an Authenticatiedienst (AD) and Machtigingenregister (MR) for eIDAS-users from a different eIDAS member state; the HM will request the EB for both authentication and authorization information (machtiging) in one request. The eIDAS specifications transfer both in one message, thus separating these in two calls is deemed ineffective.

Request

A HM MUST request the EB with an AuthnRequest, identical to the AuthnRequest of the Interface specifications HM-AD. All processing rules MUST be adhered to.

Rules for procesing request

Additional processing rules for request

A receiving EB

The EB (in case of inbound authentication requests) MUST process the EntityConcernedTypesAllowed list 

Response

The EB MUST construct an Assertion identical to the Assertion of an AD as defined in the Interface specifications HM-AD. In case an authentication in another eIDAS member state uses representation, the EB MUST construct an Assertion identical to the Assertion of an MR as defined in the Interface specifications HM-MR.

The EB MUST respond to the AuthnRequest in a single SAML Response message (transferred via Artifact binding), using the following structure:

@ID

1

SAML: Unique message characteristic. MUST identify the message uniquely within the scope of the sender and receiver for a period of at least 12 months.

@InResponseTo

1

SAML: Unique attribute of the AuthnRequest for which this Response message is the answer.

@Version

1

SAML: Version of the SAML protocol. The value MUST be '2.0'.

@IssueInstant

1

SAML: Time of issuing of the Response.

@Destination

1

SAML: URL of the endpoint of the HM on which the message is offered. MUST match the HM's metadata.

@Consent

0

Elektronische Toegangsdiensten: MUST NOT be present

Issuer

1

Elektronische Toegangsdiensten: MUST contain the EntityID of the eIDAS-berichtenservice.

@NameQualifier0Elektronische Toegangsdiensten: MUST NOT be included.
@SPNameQualifier0Elektronische Toegangsdiensten: MUST NOT be included.
@Format0Elektronische Toegangsdiensten: MUST NOT be included.
@SPProvidedID0Elektronische Toegangsdiensten: MUST NOT be included.

Signature

0..1

Elektronische Toegangsdiensten: MUST contain the Digital signature of the HM for the enveloping message.

When communicated within a ArtifactResolveResponse the signature on the SAML:Response MAY be omitted, since the parent message already guarantees the integrity.

Extensions

0

Elektronische Toegangsdiensten: MUST NOT be included.

Status

1

Elektronische Toegangsdiensten: MUST contain a StatusCode element with the status of the authentication. See Error handling.

StatusCode

1SAML: MUST be present in a Status element.
@Value1

If not 'success' additional information should be provided. (conform Elektronische Toegangsdiensten specifications).

StatusCode0..1

Only present if top-level StatusCode is not 'success'.

@Value1

In the event of a cancellation or error, the element MUST be populated with the value AuthnFailed. See Error handling.

StatusMessage0..1

Only present if top-level StatusCode is not 'success'.

StatusDetail0

Elektronische Toegangsdiensten: MUST NOT be included.

Assertion

0..2

Elektronische Toegangsdiensten: MUST contain the <Assertion> that is delivered in the response, if the request was processed successfully. In case of representation MUST contain a second, linked Assertion, containing the <Assertion> with the authorization information. See below.

EncryptedAssertion0Elektronische Toegangsdiensten: MUST NOT be included.

Processing rules for responses

A responding EB

MUST respond with the identifier(s) using the following rules:


A receiving HM