...
A list of groups – where is the user a member and about what the service has an interest
Group entitlement (only VO) - value: urn:geant:muni.cz:group:MU#idmMU#idm.ics.muni.cz
Entitlement (only group in VO) - value: urn:geant:cesnet.cz:group:einfra:group1#http://perun.cesnet.cz
Resource capabilities – it´s used to indicate rights to resources and is expressed by a URN namespace which is used for representing group membership and role information.
Resource capabilities - value: urn:geant:cesnet.cz:res:TestingCapabilitiesValue1#http://perun.cesnet.cz
Forwarded entitlement- this attribute is provided by organizations with no possibility of change.
Forwarded entitlement - value: urn:geant:muni.cz:group:MU#idmMU#idm.ics.muni.cz
The description of attribute´s values
There is an example of attribute values and its description. The syntax can look like:
urn:geant:cesnet.cz:res:TestingCapabilitiesValue1#http://perunTestingCapabilitiesValue1#perun.cesnet.cz
urn:geant:cesnet.cz - a prefix which represents a namespace of ProxyIdP
res:TestingCapabilitiesValue1 - a value
http://perun.cesnet.cz - a suffix which represents the authoritative provider of the attribute
...