How can we help you?

Policies & Resources

Below are the list of policies that currently govern SIFULAN Malaysian Access Federation:

Federation Policy
SAML Web Single Sign-On Technology Profile
Metadata Registration Practice Statement
Data Protection Profile

Federation Metadata

SIFULAN Malaysian Access Federation publishes two SAML metadata: Production Metadata and Test Metadata. The Production Metadata consists of IdP and SP metadata that have passed/complied with the technical requirement of SIFULAN Malaysian Access Federation, while the Test Metadata consists of IdP and SP metadata that have yet to pass/comply with the technical requirement or are still under development. Both metadata are signed with SIFULAN Malaysian Access Federation digital signature.

Metadata Registration Practice Statement (MRPS)

The MRPS describes the metadata management process conducted by the SIFULAN Malaysian Access Federation Operator.

SIFULAN Metadata Registration Practice Statement

SAML Web Single Sign-On Technology Profile

The SAML Web Single Sign-On (SSO) Technology Profile defines a standard that enables Identity Providers and Relying Parties to create and use Web SSO services using SAML.

SIFULAN SAML Web Single Sign-On Technology Profile

Frequently asked questions

We now have an FAQ list that we hope will help
you answer some of the more common ones.

How to access or share a service internationally via eduGAIN?

eduGAIN is an interfederation service, connecting identity federations like SIFULAN Federation around the world and simplifies access to content, resources and services for global research and education community. If your organisation is already a SIFULAN Federation participants as an Identity Provider, you will be able to connect to eduGAIN automatically. While if you are a Service Provider member, you would need to opt-in to be included in the eduGAIN. Learn more

Compliance - What obligations does my organisation have to meet if we join the federation?

To become a SIFULAN Federation member, your organisation MUST comply with SIFULAN Federation policies. Prior a fully acceptance as a member, SIFULAN Federation technical team will look through at the implementation and compliance with the technical standard and policies. Once the technical team satisfied, your organisation will be fully accepted as a SIFULAN Federation member.

How do I know if my organisation is a member of SIFULAN Federation?

You can check your organisation membership status HERE.

How do I know if my Identity Management System/Identity Provider release the correct attribute to SIFULAN Federation?

You can check it by using the Attribute Release Checker tool.

What happens when I access a Federated service?

When you access a Federated service, you may have to choose an Identity Provider/Home Organisation which can verify your identity. After that your web browser is redirected to your Identity Provider/Home Organisation’s login page and you need to perform authentication and if it is successful, you will be redirected back to the resource. Notice that, you are able to access other resources directly without having to login again once you have been successfully authenticated earlier, provided you do not close your browser in-between.

Who should I contact if I cannot login or forgot my password?

Please contact your Home Organisation helpdesk for login and password-related problems.

What about privacy and data protection?

All SIFULAN Federation members are part of a unified framework, which includes obligations for all federated solutions and services.

 

The SIFULAN Federation is based on the Security Assertion Markup Language (SAML), and SIFULAN Connect utilizes open-source software that implements SAML with a robust security design. All data exchanged—including user data and attribute values—between participating components is encrypted using secure SSL connections.

Is SIFULAN Connect secure?

Yes, SIFULAN Connect is secure. It has been designed by federated identity management experts to ensure reliable and secure deployment. SIFULAN Connect does not store a copy of your login credentials, except in hosted mode. Our environment is regularly reviewed to maintain ongoing security.

Is SIFULAN Connect login screen customisable, if I were to make it look official?

Yes, SIFULAN Connect is customisable to a certain extent. You can choose your preferred background image and login button colour. Customisation will be handled by the SIFULAN technical team; simply send your high-resolution image and colour code (Hex or RGB) to [email protected]. Click HERE to view a sample login page.

Can we integrate SIFULAN Connect with the cloud-based authentication services that we are using (Okta/Entra ID/Google Workspace/other cloud services)?

Yes, we can configure SIFULAN Connect to securely connect to your cloud-hosted authentication service. Connections between SIFULAN Connect and your authentication directory use well-established methods, ensuring the process is straightforward, secure, and easy to manage.

Does SIFULAN Connect support a bilateral connection?

Yes, it does. Your existing and future bilateral connections can be configured in your SIFULAN Connect instance. There is no limit to the number of bilateral connections allowed.

Contact Us

Birunisoft PLT (LLP0020400LGN)

D109, Block D, Level 1, Kelana Square,
Jalan SS 7/26, Kelana Jaya,
Petaling Jaya 47301, Selangor, Malaysia