SWAMID-646, update of idp.sunet.se
authorBjörn Mattsson <bjorn@sunet.se>
Tue, 25 Jan 2022 09:21:45 +0000 (10:21 +0100)
committerBjörn Mattsson <bjorn@sunet.se>
Tue, 25 Jan 2022 09:21:45 +0000 (10:21 +0100)
swamid-2.0/idp.sunet.se-idp.xml

index 716fd21..201c34a 100644 (file)
@@ -5,26 +5,26 @@
       <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
     </mdrpi:RegistrationInfo>
     <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
-      <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
-        <saml:AttributeValue>http://www.swamid.se/policy/assurance/al1</saml:AttributeValue>
-      </saml:Attribute>
+      <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+        <samla:AttributeValue>http://www.swamid.se/policy/assurance/al1</samla:AttributeValue>
+      </samla:Attribute>
     </mdattr:EntityAttributes>
-    <samla:DigestMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2001/04/xmlenc#ripemd160"/>
-    <samla:DigestMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
-    <samla:DigestMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
-    <samla:DigestMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
-    <samla:DigestMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
-    <samla:DigestMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
-    <samla:SigningMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
-    <samla:SigningMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-ripemd160"/>
-    <samla:SigningMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
-    <samla:SigningMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha224"/>
-    <samla:SigningMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
-    <samla:SigningMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
-    <samla:SigningMethod xmlns:samla="urn:oasis:names:tc:SAML:metadata:algsupport" Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
+    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#ripemd160"/>
+    <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
+    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
+    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
+    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
+    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-ripemd160"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha224"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
   </md:Extensions>
-  <saml:IDPSSODescriptor xmlns:saml="urn:oasis:names:tc:SAML:2.0:metadata" WantAuthnRequestsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" errorURL="https://error.swamid.se/?errorurl_code=ERRORURL_CODE&amp;errorurl_ts=ERRORURL_TS&amp;errorurl_rp=ERRORURL_RP&amp;errorurl_tid=ERRORURL_TID&amp;errorurl_ctx=ERRORURL_CTX&amp;entityid=https://idp.sunet.se/idp">
-    <saml:Extensions>
+  <md:IDPSSODescriptor WantAuthnRequestsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" errorURL="https://error.swamid.se/?errorurl_code=ERRORURL_CODE&amp;errorurl_ts=ERRORURL_TS&amp;errorurl_rp=ERRORURL_RP&amp;errorurl_tid=ERRORURL_TID&amp;errorurl_ctx=ERRORURL_CTX&amp;entityid=https://idp.sunet.se/idp">
+    <md:Extensions>
       <shibmd:Scope regexp="false">sunet.se</shibmd:Scope>
       <mdui:UIInfo>
         <mdui:DisplayName xml:lang="sv">SUNET</mdui:DisplayName>
         <mdui:Description xml:lang="en">Login for SUNET employees</mdui:Description>
         <mdui:Logo xml:lang="sv" height="205" width="256">https://static.sunet.se/images/sunet256.png</mdui:Logo>
         <mdui:Logo xml:lang="en" height="205" width="256">https://static.sunet.se/images/sunet256.png</mdui:Logo>
+        <mdui:InformationURL xml:lang="sv">https://wiki.sunet.se/display/info/Sunet+Identity+Provider+Service+Definition+and+Privacy+Policy?showLanguage=sv_SE</mdui:InformationURL>
+        <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/info/Sunet+Identity+Provider+Service+Definition+and+Privacy+Policy?showLanguage=sv_SE</mdui:PrivacyStatementURL>
+        <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/info/Sunet+Identity+Provider+Service+Definition+and+Privacy+Policy?showLanguage=en_GB</mdui:PrivacyStatementURL>
+        <mdui:InformationURL xml:lang="en">https://wiki.sunet.se/display/info/Sunet+Identity+Provider+Service+Definition+and+Privacy+Policy?showLanguage=en_GB</mdui:InformationURL>
       </mdui:UIInfo>
       <mdui:DiscoHints>
         <mdui:DomainHint>sunet.se</mdui:DomainHint>
       </mdui:DiscoHints>
-    </saml:Extensions>
-    <saml:KeyDescriptor use="signing">
+    </md:Extensions>
+    <md:KeyDescriptor use="signing">
       <ds:KeyInfo>
         <ds:X509Data>
           <ds:X509Certificate>MIIFBzCCAu+gAwIBAgIJAIlMiGxSE+2zMA0GCSqGSIb3DQEBCwUAMBoxGDAWBgNV
@@ -71,22 +75,33 @@ jiN2PVb/fS119Yu9s/jk86TcHIATZtmc/h6y5FkHzADUHGPPNum92l027dPIVqeT
 </ds:X509Certificate>
         </ds:X509Data>
       </ds:KeyInfo>
-    </saml:KeyDescriptor>
-    <saml:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</saml:NameIDFormat>
-    <saml:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.sunet.se/Saml2SP/sso/redirect"/>
-    <saml:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.sunet.se/Saml2SP/sso/post"/>
-  </saml:IDPSSODescriptor>
-  <saml:Organization xmlns:saml="urn:oasis:names:tc:SAML:2.0:metadata">
-    <saml:OrganizationName xml:lang="en">SUNET</saml:OrganizationName>
-    <saml:OrganizationDisplayName xml:lang="en">SUNET</saml:OrganizationDisplayName>
-    <saml:OrganizationURL xml:lang="en">https://sunet.se</saml:OrganizationURL>
-  </saml:Organization>
-  <saml:ContactPerson xmlns:saml="urn:oasis:names:tc:SAML:2.0:metadata" contactType="technical">
-    <saml:GivenName>Technical</saml:GivenName>
-    <saml:EmailAddress>mailto:noc@sunet.se</saml:EmailAddress>
-  </saml:ContactPerson>
-  <saml:ContactPerson xmlns:saml="urn:oasis:names:tc:SAML:2.0:metadata" contactType="support">
-    <saml:GivenName>Support</saml:GivenName>
-    <saml:EmailAddress>mailto:noc@sunet.se</saml:EmailAddress>
-  </saml:ContactPerson>
+    </md:KeyDescriptor>
+    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
+    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.sunet.se/Saml2SP/sso/redirect"/>
+    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.sunet.se/Saml2SP/sso/post"/>
+  </md:IDPSSODescriptor>
+  <md:Organization>
+    <md:OrganizationName xml:lang="en">SUNET</md:OrganizationName>
+    <md:OrganizationName xml:lang="sv">SUNET</md:OrganizationName>
+    <md:OrganizationDisplayName xml:lang="en">SUNET</md:OrganizationDisplayName>
+    <md:OrganizationDisplayName xml:lang="sv">SUNET</md:OrganizationDisplayName>
+    <md:OrganizationURL xml:lang="en">https://sunet.se</md:OrganizationURL>
+    <md:OrganizationURL xml:lang="sv">https://sunet.se</md:OrganizationURL>
+  </md:Organization>
+  <md:ContactPerson contactType="technical">
+    <md:GivenName>SUNET NOC</md:GivenName>
+    <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+  </md:ContactPerson>
+  <md:ContactPerson contactType="support">
+    <md:GivenName>SUNET NOC</md:GivenName>
+    <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+  </md:ContactPerson>
+  <md:ContactPerson contactType="administrative">
+    <md:GivenName>SUNET NOC</md:GivenName>
+    <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+  </md:ContactPerson>
+  <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
+    <md:GivenName>SUNET CERT</md:GivenName>
+    <md:EmailAddress>mailto:cert@cert.sunet.se</md:EmailAddress>
+  </md:ContactPerson>
 </md:EntityDescriptor>