summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBjörn Mattsson <bjorn@sunet.se>2022-05-20 09:27:18 +0200
committerBjörn Mattsson <bjorn@sunet.se>2022-05-20 09:27:18 +0200
commit5ead534da4468867f89a66da5282069705adda4f (patch)
tree3700c0f0dd062cc4b29abca1bf7a79c453f66d4f
parent12c2438b15cdd1bbf52f2e265d5f4ecd4c364f98 (diff)
SWAMID-942 Updated idp2.kkh.se
-rw-r--r--swamid-2.0/idp2.kkh.se-idp-shibboleth.xml138
1 files changed, 76 insertions, 62 deletions
diff --git a/swamid-2.0/idp2.kkh.se-idp-shibboleth.xml b/swamid-2.0/idp2.kkh.se-idp-shibboleth.xml
index c4b4dc9b..188c750a 100644
--- a/swamid-2.0/idp2.kkh.se-idp-shibboleth.xml
+++ b/swamid-2.0/idp2.kkh.se-idp-shibboleth.xml
@@ -4,27 +4,32 @@
<mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2018-01-05T12:16:26Z">
<mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
- <attr:EntityAttributes xmlns:attr="urn:oasis:names:tc:SAML:metadata:attribute">
- <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
- <saml:AttributeValue>http://www.swamid.se/policy/assurance/al1</saml:AttributeValue>
- </saml:Attribute>
- </attr:EntityAttributes>
+ <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
+ <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>http://www.swamid.se/policy/assurance/al1</samla:AttributeValue>
+ </samla:Attribute>
+ <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category-support" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>http://refeds.org/category/research-and-scholarship</samla:AttributeValue>
+ <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
+ </samla:Attribute>
+ </mdattr:EntityAttributes>
</md:Extensions>
- <IDPSSODescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0" errorURL="https://error.swamid.se/?errorurl_code=ERRORURL_CODE&amp;errorurl_ts=ERRORURL_TS&amp;errorurl_rp=ERRORURL_RP&amp;errorurl_tid=ERRORURL_TID&amp;errorurl_ctx=ERRORURL_CTX&amp;entityid=https://idp2.kkh.se/idp/shibboleth">
- <Extensions>
+ <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0" errorURL="https://error.swamid.se/?errorurl_code=ERRORURL_CODE&amp;errorurl_ts=ERRORURL_TS&amp;errorurl_rp=ERRORURL_RP&amp;errorurl_tid=ERRORURL_TID&amp;errorurl_ctx=ERRORURL_CTX&amp;entityid=https://idp2.kkh.se/idp/shibboleth">
+ <md:Extensions>
<shibmd:Scope regexp="false">kkh.se</shibmd:Scope>
<mdui:UIInfo>
<mdui:DisplayName xml:lang="sv">Kungl. Konsthögskolan</mdui:DisplayName>
<mdui:DisplayName xml:lang="en">Royal Institute of Art</mdui:DisplayName>
<mdui:Description xml:lang="sv">Identity Provider för Kungl. Konsthögskolan (KKH)</mdui:Description>
<mdui:Description xml:lang="en">Identity Provider for the Royal Institute of Art (KKH)</mdui:Description>
- <mdui:Logo xml:lang="sv" height="110" width="404">https://idp2.kkh.se/idp/images/kkh.png</mdui:Logo>
- <mdui:Logo xml:lang="en" height="110" width="404">https://idp2.kkh.se/idp/images/kkh.png</mdui:Logo>
<mdui:Keywords xml:lang="sv">KKH Kungl.+Konsthögskolan Kungliga+Konsthögskolan Royal+Institute+of+Art</mdui:Keywords>
<mdui:Keywords xml:lang="en">KKH Kungl.+Konsthögskolan Kungliga+Konsthögskolan Royal+Institute+of+Art</mdui:Keywords>
- <mdui:InformationURL xml:lang="sv">http://www.kkh.se/contact/</mdui:InformationURL>
- <mdui:InformationURL xml:lang="en">http://www.kkh.se/en/contact/</mdui:InformationURL>
- <mdui:PrivacyStatementURL xml:lang="sv">http://kkh.se/images/stories/helens/Personuppgifter_KKH_infotext.pdf</mdui:PrivacyStatementURL>
+ <mdui:InformationURL xml:lang="sv">https://kkh.se/sv/kontakt/</mdui:InformationURL>
+ <mdui:InformationURL xml:lang="en">https://www.kkh.se/en/contact/</mdui:InformationURL>
+ <mdui:PrivacyStatementURL xml:lang="sv">https://kkh.se/styrdokument/Riktlinjer_for_behandling_av_personuppgifter_vid_Kungl_Konsthogskolan.pdf</mdui:PrivacyStatementURL>
+ <mdui:Logo xml:lang="en" height="225" width="225">https://idp2.kkh.se/idp/images/Kungl_Konsthogskolan_Vapen_225.png</mdui:Logo>
+ <mdui:Logo xml:lang="sv" height="225" width="225">https://idp2.kkh.se/idp/images/Kungl_Konsthogskolan_Vapen_225.png</mdui:Logo>
+ <mdui:PrivacyStatementURL xml:lang="en">https://kkh.se/styrdokument/Riktlinjer_for_behandling_av_personuppgifter_vid_Kungl_Konsthogskolan.pdf</mdui:PrivacyStatementURL>
</mdui:UIInfo>
<mdui:DiscoHints>
<mdui:DomainHint>kkh.se</mdui:DomainHint>
@@ -32,8 +37,8 @@
<mdui:IPHint>130.242.8.0/24</mdui:IPHint>
<mdui:GeolocationHint>geo:59.324458,18.082998</mdui:GeolocationHint>
</mdui:DiscoHints>
- </Extensions>
- <KeyDescriptor use="signing">
+ </md:Extensions>
+ <md:KeyDescriptor use="signing">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -57,8 +62,8 @@ txB7BxAsEsxkzuE7M1p2N62744NyMWs=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <KeyDescriptor use="signing">
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="signing">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -82,8 +87,8 @@ NlZX5y7b3GoY/Eio8u4N/p6Id9sfmbUb
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <KeyDescriptor use="encryption">
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="encryption">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -107,25 +112,25 @@ R/BU8rcOeQ5KU1e3ooJqSzIKBhWce80g4TaX1u1rYibKqkSUwgp1Jh2MSnKN0B8c
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.kkh.se:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
- <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.kkh.se:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
+ </md:KeyDescriptor>
+ <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.kkh.se:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
+ <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.kkh.se:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
<!--
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp2.kkh.se/idp/profile/SAML2/Redirect/SLO"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp2.kkh.se/idp/profile/SAML2/POST/SLO"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.kkh.se:8443/idp/profile/SAML2/SOAP/SLO"/>
-->
- <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
- <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
- <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp2.kkh.se/idp/profile/Shibboleth/SSO"/>
- <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp2.kkh.se/idp/profile/SAML2/POST/SSO"/>
- <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp2.kkh.se/idp/profile/SAML2/Redirect/SSO"/>
- </IDPSSODescriptor>
- <AttributeAuthorityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
- <Extensions>
+ <md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat>
+ <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
+ <md:SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp2.kkh.se/idp/profile/Shibboleth/SSO"/>
+ <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp2.kkh.se/idp/profile/SAML2/POST/SSO"/>
+ <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp2.kkh.se/idp/profile/SAML2/Redirect/SSO"/>
+ </md:IDPSSODescriptor>
+ <md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
+ <md:Extensions>
<shibmd:Scope regexp="false">kkh.se</shibmd:Scope>
- </Extensions>
- <KeyDescriptor use="signing">
+ </md:Extensions>
+ <md:KeyDescriptor use="signing">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -149,8 +154,8 @@ txB7BxAsEsxkzuE7M1p2N62744NyMWs=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <KeyDescriptor use="signing">
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="signing">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -174,8 +179,8 @@ NlZX5y7b3GoY/Eio8u4N/p6Id9sfmbUb
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <KeyDescriptor use="encryption">
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="encryption">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -199,33 +204,42 @@ R/BU8rcOeQ5KU1e3ooJqSzIKBhWce80g4TaX1u1rYibKqkSUwgp1Jh2MSnKN0B8c
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.kkh.se:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
+ </md:KeyDescriptor>
+ <md:AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.kkh.se:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
<!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.kkh.se:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
<!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->
- </AttributeAuthorityDescriptor>
- <Organization xmlns="urn:oasis:names:tc:SAML:2.0:metadata">
- <OrganizationName xml:lang="en">KKH</OrganizationName>
- <OrganizationDisplayName xml:lang="sv">Kungl. Konsthögskolan</OrganizationDisplayName>
- <OrganizationDisplayName xml:lang="en">Royal Institute of Art</OrganizationDisplayName>
- <OrganizationURL xml:lang="en">http://www.kkh.se</OrganizationURL>
- </Organization>
- <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="administrative">
- <Company>Kungl. Konsthögskolan</Company>
- <SurName>Fredrik Reuterswärd</SurName>
- <EmailAddress>mailto:fredrik.reutersward@kkh.se</EmailAddress>
- <TelephoneNumber>+4686144064</TelephoneNumber>
- </ContactPerson>
- <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="technical">
- <Company>Kungl. Konsthögskolan</Company>
- <SurName>Fredrik Reuterswärd</SurName>
- <EmailAddress>mailto:fredrik.reutersward@kkh.se</EmailAddress>
- <TelephoneNumber>+4686144064</TelephoneNumber>
- </ContactPerson>
- <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="support">
- <Company>Kungl. Konsthögskolan</Company>
- <SurName>Fredrik Reuterswärd</SurName>
- <EmailAddress>mailto:fredrik.reutersward@kkh.se</EmailAddress>
- <TelephoneNumber>+4686144064</TelephoneNumber>
- </ContactPerson>
+ </md:AttributeAuthorityDescriptor>
+ <md:Organization>
+ <md:OrganizationName xml:lang="en">KKH</md:OrganizationName>
+ <md:OrganizationName xml:lang="sv">KKH</md:OrganizationName>
+ <md:OrganizationDisplayName xml:lang="sv">Kungl. Konsthögskolan</md:OrganizationDisplayName>
+ <md:OrganizationDisplayName xml:lang="en">Royal Institute of Art</md:OrganizationDisplayName>
+ <md:OrganizationURL xml:lang="en">https://www.kkh.se</md:OrganizationURL>
+ <md:OrganizationURL xml:lang="sv">https://www.kkh.se</md:OrganizationURL>
+ </md:Organization>
+ <md:ContactPerson contactType="administrative">
+ <md:Company>Kungl. Konsthögskolan</md:Company>
+ <md:SurName>Fredrik Reuterswärd</md:SurName>
+ <md:EmailAddress>mailto:it-support@kkh.se</md:EmailAddress>
+ <md:TelephoneNumber>+4686144000</md:TelephoneNumber>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="technical">
+ <md:Company>Kungl. Konsthögskolan</md:Company>
+ <md:SurName>IT-Support</md:SurName>
+ <md:EmailAddress>mailto:it-support@kkh.se</md:EmailAddress>
+ <md:TelephoneNumber>+4686144000</md:TelephoneNumber>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="support">
+ <md:Company>Kungl. Konsthögskolan</md:Company>
+ <md:SurName>IT-Support</md:SurName>
+ <md:EmailAddress>mailto:it-support@kkh.se</md:EmailAddress>
+ <md:TelephoneNumber>+4686144000</md:TelephoneNumber>
+ </md:ContactPerson>
+ <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
+ <md:Company>Kungl. Konsthögskolan</md:Company>
+ <md:GivenName>KKH</md:GivenName>
+ <md:SurName>IT-Security</md:SurName>
+ <md:EmailAddress>mailto:abuse@kkh.se</md:EmailAddress>
+ <md:TelephoneNumber>+4686144000</md:TelephoneNumber>
+ </md:ContactPerson>
</md:EntityDescriptor>