Cliquez ici pour la version française

Federation Registry FAQ

Accessing to the registry (click to unfold)

Accessing to the registry (click to unfold)

# I cannot access to the registry by connecting with my home organization IDP (click to unfold)

# I cannot access to the registry by connecting with my home organization IDP (click to unfold)

It is likely that your IDP does not provide to the registry the required “mail” user attribute.

You can check that by yourself by connecting to the test and validation resource offered by RENATER (https://test-sp.federation.renater.fr/) with your home organization IDP (Click on “Connexion avec la fédération Éducation/Recherche” and then select your home organization IDP).
This test and validation resource allows to display all user attributes returned by the accessing user's home organization IDP.

You have to adapt the configuration of your IDP (attribute filter configuration file) accordingly if this attribute is actually not returned.

# I cannot access to the registry anymore with my CRU account (click to unfold)

# I cannot access to the registry anymore with my CRU account (click to unfold)

Once your CRU account is created, you can keep it indefinitely.
However, after a period of inactivity of 1 year, your CRU account will be automatically deleted.
In this case, you can if needed, recreate this account with the same email address by accessing to the CRU accounts management service : https://cru.renater.fr/sac/

# My organization is displayed in the list of the discovery service (https://discovery.renater.fr/renater). Do I still need a CRU account ? (click to unfold)

# My organization is displayed in the list of the discovery service (https://discovery.renater.fr/renater). Do I still need a CRU account ? (click to unfold)

No, you no longer need it.
If your organization is displayed in the discovery service list (https://discovery.renater.fr/renater), it means that you can use the account of your home organization instead of using a CRU account.


Visibility of SAML entities within the registry (click to unfold)

Visibility of SAML entities within the registry (click to unfold)

# I do connect to the registry using my home organization IDP or a CRU account but I cannot see my SAML entities (click to unfold)

# I do connect to the registry using my home organization IDP or a CRU account but I cannot see my SAML entities (click to unfold)

The visibility of SAML entities for an authenticated user is deduced from the email address returned by his connection IDP (i.e. home organization or CRU accounts IDP).

  • For a user with the “entity manager” role : he will be able to see SAML entities for which on the entity managers email address (declared from the “Contacts” tab) matches the one returned by the connection IDP.
  • For a user with the “orgnization manager” role : he will be able to see the set of SAML entities attached to his organization if on the orgnization managers email address (declared as part of the administrative registration procedure) matches the one returned by the connection IDP.


Attaching a SAML entity to an organization (click to unfold)

Attaching a SAML entity to an organization (click to unfold)

# I want to attach my SAML entity to my home organization but this latter doesn't appear in the list of organizations proposed by the registry (click to unfold)

# I want to attach my SAML entity to my home organization but this latter doesn't appear in the list of organizations proposed by the registry (click to unfold)

To ensure your organization appears in the list of organizations proposed by the registry, you must have done the administrative registration with RENATER beforehand (see §3.1).

In the event where this administrative registration with RENATER would already have been done but your organization is still missing in the list, please contact RENATER support team.


Registering a SAML entity in a production federation (click to unfold)

Registering a SAML entity in a production federation (click to unfold)

# I cannot register my SAML entity in a production federation (click to unfold)

# I cannot register my SAML entity in a production federation (click to unfold)

The registration in a production federation is not available if your SAML entity is still not attached to an organization (member or partner organization) registered with RENATER (see §3.1).

To do that, you have first to select an organization from the “Organization attachment” tab. The attachment request then must be validated by one of the two orgnization managers declared for this organization (see §5.1).


Updating contact information (click to unfold)

Updating contact information (click to unfold)

# I want to update the manager email address for my organization, what do I need to do ? (click to unfold)

# I want to update the manager email address for my organization, what do I need to do ? (click to unfold)

  • For a member organization : the designated point of contact for your organization must perform the update directly through the PASS interface. Then you have to notify us of this update here.
  • For a partner organization : please contact RENATER through our helpdesk.

# I want to update the manager email address of a SAML entity, what do I need to do ? (click to unfold)

# I want to update the manager email address of a SAML entity, what do I need to do ? (click to unfold)

The update of a manager email address can be performed directly through the federation registry from the editing page of your IDP or SP (“Contacts” tab) :

  • Either by the manager of your organization (who have access to all SAML entities attached to your organization) ;
  • Or directly by one of the manager declared for this SAML entity.


SAML certificate Rollover (click to unfold)

SAML certificate Rollover (click to unfold)

# Which is the procedure to replace the SAML certificate of my IDP or SP used in the federation metadata ?

# Which is the procedure to replace the SAML certificate of my IDP or SP used in the federation metadata ?

The rollover of SAML certificate for an IDP or SP is a sensitive operation.
In order to avoid any service interruption, please follow the instructions described on this page.


Updating technical information of a SAML entity (click to unfold)

Updating technical information of a SAML entity (click to unfold)

# I updated some technical information of my SAML entity on the registry but I do not see the changes propagated to the corresponding metadata. Is this normal ?

# I updated some technical information of my SAML entity on the registry but I do not see the changes propagated to the corresponding metadata. Is this normal ?

This is perfectly normal if your changes are not immediately visible into the metadata.

Indeed, when you submit changes for your SAML entity on the registry, you have to take into account :

  1. the propagation delay of these changes into the metadata file version that you used for your SAML entity (preview,intermediate or main) ;
  2. the metadata frequency reload configured at each SP/IDP (RENATER recommends it to be hourly).

Get more details on this page.


CRU account management (click to unfold)

CRU account management (click to unfold)

# How to create a CRU account ? (click to unfold)

# How to create a CRU account ? (click to unfold)

There is no prerequisite to have a CRU account. The service is open to all :

  • Go to the CRU accounts management service : https://cru.renater.fr/sac/
  • Fill in the account creation form ;
  • Then you will receive a email ;
  • Click on the link mentioned in this email to confirm the creation of your account ;
  • Your account is activated and functionnal. You will received a second email to confirm that.

# I did forget my CRU account password. What do I need to do ? (click to unfold)

# I did forget my CRU account password. What do I need to do ? (click to unfold)

  • Go to the CRU accounts management service : https://cru.renater.fr/sac/
  • Access to the Password lost ? section from the menu to the left ;
  • Enter your email address ;
  • You will receive then an email with instructions to define a new password.

# How to change my CRU account password ? (click to unfold)

# How to change my CRU account password ? (click to unfold)

  • Go to the CRU accounts management service : https://cru.renater.fr/sac/
  • Log in with your account (if not already done) ;
  • Access to the My account section from the menu to the left ;
  • Define then a new password.

# How to change my CRU account email address ? (click to unfold)

# How to change my CRU account email address ? (click to unfold)

  • Go to the CRU accounts management service : https://cru.renater.fr/sac/
  • Log in with your account (if not already done) ;
  • Access to the My account section from the menu to the left ;
  • Access to the email editing page ;
  • Enter your new email address ;
  • An email is automatically sent to this new address. Follow the instructions including in this email to finalize the procedure.