Explaining Persistent-ID

By EssingtonITS team ·

The article explains how Persistent-ID in Shibboleth authentication helps maintain user continuity across sessions. It highlights challenges when switching authentication systems and suggests a hybrid solution to retain Persistent-ID.

Persistent-ID in Shibboleth Authentication

Persistent-ID is used in Shibboleth authentication by Service Providers (SPs) from the attributes released by an Identity Provider (IdP). These attributes determine who is authorised to access content on the SP's servers. Persistent identifiers are unique to a given user and remain consistent across sessions. They enable continuity between sessions at a given SP, facilitating user registration, personalisation of the account or session, and remote saving of work. This means users don't have to set up their account each time they access the resource in question.

Core Attributes for UK Federation Members

For UK federation members, two core attributes can be described as persistent identifiers:

  • eduPersonPrincipalName (ePPN)
  • eduPersonTargetedID (ePTId)

ePPN can be linked to a specific user and thus needs to be released with caution. ePTId is generally what is meant by persistent-id or targeted-id because it’s pseudonymous, meaning it is unique to any given user when accessing any given SP. This version of persistent-ID is generated by the software and uniquely identifies the user. It is used in library licensing for paid resources. Therefore, any changes to the setup of the calculation of the coding for the eduPersonTargetedID attribute, including the entityID of the issuing IdP, will change the attribute value. This severs the connection between that institution's users and any of their information saved at SPs, disrupting the information saved on the SP's server.

Changing Authentication to AzureAD from LDAP Authentication

The challenge for all parties involved here is that switching to AzureAD breaks Persistent-ID, so users can lose SP content. Any change, therefore, needs to be carefully considered. Essington ITS Ltd offers a hybrid solution that retains persistent-ID. Please contact us if you are interested.

References

Looking to streamline your identity management with Shibboleth? At EssingtonITS.co.uk, we offer expert guidance and bespoke solutions tailored to your needs. Let us help you enhance your IT infrastructure with confidence.

person people found this useful.

Tags: #Persistent-ID #Shibboleth #UK federation

Related

Knowledge base 10 Jun 2026

Personal Notebook in eLLM

The personal notebook in eLLM allows users to organise and store notes, images, and files in a private, searchable timeline. It ensures privacy by keeping contents visible only to the user, and it can be integrated with the assistant for personalised answers.

Knowledge base 9 Jun 2026

Git Commands Quick Reference Guide

This quick reference guide covers essential Git commands for repository setup, staging, branching, merging, and working with remote repositories, making it a handy tool for developers to streamline their workflow.

Knowledge base 9 Jun 2026

Organisation Skills in the eLLM Admin Console

The article explains how the eLLM Admin Console allows organisations to create and manage shared instruction sets called "organisation skills" to ensure consistent responses across teams. These skills can be customised, restricted to specific groups, and integrated with extern…

Expand 29 Jul 2026

How AI can support pupils with SEND

Explore how AI tools are aiding pupils with special educational needs and disabilities by simplifying text, breaking down tasks, and enhancing accessibility. Learn about the considerations schools should make before implementation.

Expand 29 Jul 2026

AI policy and practice in further education

Further education colleges need distinct AI policies due to their unique mix of vocational courses, diverse age groups, and specific funding and inspection requirements. This guidance highlights the importance of tailored AI approaches in FE settings.