Direct Connection to eHerkenning Broker
The following steps will outline how to configure the eHerkenning Broker, without the Signicat Identity Broker, using a direct connection.
For those without the Signicat Identity Broker, the connection to the eHerkenning Broker must be done directly.

Login Representation Flow

The representation flow is the flow where the user logs in to act on behalf of a company.
Step 1: The service provider sends an AuthnRequest to the eHerkenning Broker via Artifact Binding, Post binding or Redirect binding to the relevant SingleSignOnService of the eHerkenning Broker from the metadata.
Example:
1
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact"
2
Location="https://eh01.staging.connectis.nl/broker/sso/1.13"/>
Copied!
Example AuthnRequest:
1
<saml2p:AuthnRequest xmlns:saml2p="urn:oasis:names:tc:SAML:2.0:protocol"
2
AttributeConsumingServiceIndex="6"
3
Destination="https://eh01.staging.connectis.nl/broker/sso/1.13"
4
ForceAuthn="false"
5
ID="_91b639b6cdeb6fe2c618f762a9b96e9a"
6
IssueInstant="2021-04-23T11:28:42.471Z"
7
ProviderName="Example"
8
Version="2.0"
9
>
10
<saml2:Issuer xmlns:saml2="urn:oasis:names:tc:SAML:2.0:assertion">urn:etoegang:DV:00000003244440010000:entities:0006</saml2:Issuer>
11
</saml2p:AuthnRequest>
Copied!
Step 2: The eHerkenning Broker verifies the signature and SAMLRequest.
Step 3: The eHerkenning Broker determines the service that is being requested, based on the OIN of the issuer and the AttributeConsumingServiceIndex.
The AttributeConsumingServiceIndex could optionally be mapped by AttributeConsumingServices in the metadata to another index. In below example, index 2 maps to index 50. And, if no AttributeConsumingServiceIndex is sent, index will be 1 (because of isDefault)
Step 4: Show IdP Selection Screen. Filter IdP from the network metadata based on:
  • requested LoA (each IdP specifies a maximum LoA they support)
  • Requested ECTAset (some IdPs do not support certain ECTA, e.g. Pseudo)
Step 5: Create an IdP request and send to the IdP's Single Sign-On Service using Artifact binding.
Example:
1
https://acc-ehlogin.we-id.nl/ad113_preprod/process?SAMLart
Copied!
Once the above steps have been followed, next, you access eHerkenning.

Access the eHerkenning Broker

To proceed, an authentication method with at least a Level of Assurance (LoA) 3 must be used. More information on purchasing an eHerkenning Level 3 supplier can be found on the leveranciersoverzicht page.
Using the dropdown, select the provider of the authentication method to choose how to log in.
eHerkenning Broker IdP screen

eHerkenning Level 3 Suppliers

You can choose an authentication method from the following suppliers that offer LoA level 3. Use the links to find out more about each supplier:
Last modified 3mo ago