diff options
author | Björn Mattsson <bjorn@sunet.se> | 2022-05-20 09:27:18 +0200 |
---|---|---|
committer | Björn Mattsson <bjorn@sunet.se> | 2022-05-20 09:27:18 +0200 |
commit | 5ead534da4468867f89a66da5282069705adda4f (patch) | |
tree | 3700c0f0dd062cc4b29abca1bf7a79c453f66d4f | |
parent | 12c2438b15cdd1bbf52f2e265d5f4ecd4c364f98 (diff) |
SWAMID-942 Updated idp2.kkh.se
-rw-r--r-- | swamid-2.0/idp2.kkh.se-idp-shibboleth.xml | 138 |
1 files changed, 76 insertions, 62 deletions
diff --git a/swamid-2.0/idp2.kkh.se-idp-shibboleth.xml b/swamid-2.0/idp2.kkh.se-idp-shibboleth.xml index c4b4dc9b..188c750a 100644 --- a/swamid-2.0/idp2.kkh.se-idp-shibboleth.xml +++ b/swamid-2.0/idp2.kkh.se-idp-shibboleth.xml @@ -4,27 +4,32 @@ <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2018-01-05T12:16:26Z"> <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy> </mdrpi:RegistrationInfo> - <attr:EntityAttributes xmlns:attr="urn:oasis:names:tc:SAML:metadata:attribute"> - <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> - <saml:AttributeValue>http://www.swamid.se/policy/assurance/al1</saml:AttributeValue> - </saml:Attribute> - </attr:EntityAttributes> + <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"> + <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <samla:AttributeValue>http://www.swamid.se/policy/assurance/al1</samla:AttributeValue> + </samla:Attribute> + <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category-support" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <samla:AttributeValue>http://refeds.org/category/research-and-scholarship</samla:AttributeValue> + <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue> + </samla:Attribute> + </mdattr:EntityAttributes> </md:Extensions> - <IDPSSODescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0" errorURL="https://error.swamid.se/?errorurl_code=ERRORURL_CODE&errorurl_ts=ERRORURL_TS&errorurl_rp=ERRORURL_RP&errorurl_tid=ERRORURL_TID&errorurl_ctx=ERRORURL_CTX&entityid=https://idp2.kkh.se/idp/shibboleth"> - <Extensions> + <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0" errorURL="https://error.swamid.se/?errorurl_code=ERRORURL_CODE&errorurl_ts=ERRORURL_TS&errorurl_rp=ERRORURL_RP&errorurl_tid=ERRORURL_TID&errorurl_ctx=ERRORURL_CTX&entityid=https://idp2.kkh.se/idp/shibboleth"> + <md:Extensions> <shibmd:Scope regexp="false">kkh.se</shibmd:Scope> <mdui:UIInfo> <mdui:DisplayName xml:lang="sv">Kungl. Konsthögskolan</mdui:DisplayName> <mdui:DisplayName xml:lang="en">Royal Institute of Art</mdui:DisplayName> <mdui:Description xml:lang="sv">Identity Provider för Kungl. Konsthögskolan (KKH)</mdui:Description> <mdui:Description xml:lang="en">Identity Provider for the Royal Institute of Art (KKH)</mdui:Description> - <mdui:Logo xml:lang="sv" height="110" width="404">https://idp2.kkh.se/idp/images/kkh.png</mdui:Logo> - <mdui:Logo xml:lang="en" height="110" width="404">https://idp2.kkh.se/idp/images/kkh.png</mdui:Logo> <mdui:Keywords xml:lang="sv">KKH Kungl.+Konsthögskolan Kungliga+Konsthögskolan Royal+Institute+of+Art</mdui:Keywords> <mdui:Keywords xml:lang="en">KKH Kungl.+Konsthögskolan Kungliga+Konsthögskolan Royal+Institute+of+Art</mdui:Keywords> - <mdui:InformationURL xml:lang="sv">http://www.kkh.se/contact/</mdui:InformationURL> - <mdui:InformationURL xml:lang="en">http://www.kkh.se/en/contact/</mdui:InformationURL> - <mdui:PrivacyStatementURL xml:lang="sv">http://kkh.se/images/stories/helens/Personuppgifter_KKH_infotext.pdf</mdui:PrivacyStatementURL> + <mdui:InformationURL xml:lang="sv">https://kkh.se/sv/kontakt/</mdui:InformationURL> + <mdui:InformationURL xml:lang="en">https://www.kkh.se/en/contact/</mdui:InformationURL> + <mdui:PrivacyStatementURL xml:lang="sv">https://kkh.se/styrdokument/Riktlinjer_for_behandling_av_personuppgifter_vid_Kungl_Konsthogskolan.pdf</mdui:PrivacyStatementURL> + <mdui:Logo xml:lang="en" height="225" width="225">https://idp2.kkh.se/idp/images/Kungl_Konsthogskolan_Vapen_225.png</mdui:Logo> + <mdui:Logo xml:lang="sv" height="225" width="225">https://idp2.kkh.se/idp/images/Kungl_Konsthogskolan_Vapen_225.png</mdui:Logo> + <mdui:PrivacyStatementURL xml:lang="en">https://kkh.se/styrdokument/Riktlinjer_for_behandling_av_personuppgifter_vid_Kungl_Konsthogskolan.pdf</mdui:PrivacyStatementURL> </mdui:UIInfo> <mdui:DiscoHints> <mdui:DomainHint>kkh.se</mdui:DomainHint> @@ -32,8 +37,8 @@ <mdui:IPHint>130.242.8.0/24</mdui:IPHint> <mdui:GeolocationHint>geo:59.324458,18.082998</mdui:GeolocationHint> </mdui:DiscoHints> - </Extensions> - <KeyDescriptor use="signing"> + </md:Extensions> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -57,8 +62,8 @@ txB7BxAsEsxkzuE7M1p2N62744NyMWs= </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="signing"> + </md:KeyDescriptor> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -82,8 +87,8 @@ NlZX5y7b3GoY/Eio8u4N/p6Id9sfmbUb </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="encryption"> + </md:KeyDescriptor> + <md:KeyDescriptor use="encryption"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -107,25 +112,25 @@ R/BU8rcOeQ5KU1e3ooJqSzIKBhWce80g4TaX1u1rYibKqkSUwgp1Jh2MSnKN0B8c </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.kkh.se:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/> - <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.kkh.se:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/> + </md:KeyDescriptor> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.kkh.se:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.kkh.se:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/> <!-- <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp2.kkh.se/idp/profile/SAML2/Redirect/SLO"/> <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp2.kkh.se/idp/profile/SAML2/POST/SLO"/> <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.kkh.se:8443/idp/profile/SAML2/SOAP/SLO"/> --> - <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat> - <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat> - <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp2.kkh.se/idp/profile/Shibboleth/SSO"/> - <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp2.kkh.se/idp/profile/SAML2/POST/SSO"/> - <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp2.kkh.se/idp/profile/SAML2/Redirect/SSO"/> - </IDPSSODescriptor> - <AttributeAuthorityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol"> - <Extensions> + <md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat> + <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> + <md:SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp2.kkh.se/idp/profile/Shibboleth/SSO"/> + <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp2.kkh.se/idp/profile/SAML2/POST/SSO"/> + <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp2.kkh.se/idp/profile/SAML2/Redirect/SSO"/> + </md:IDPSSODescriptor> + <md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol"> + <md:Extensions> <shibmd:Scope regexp="false">kkh.se</shibmd:Scope> - </Extensions> - <KeyDescriptor use="signing"> + </md:Extensions> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -149,8 +154,8 @@ txB7BxAsEsxkzuE7M1p2N62744NyMWs= </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="signing"> + </md:KeyDescriptor> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -174,8 +179,8 @@ NlZX5y7b3GoY/Eio8u4N/p6Id9sfmbUb </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="encryption"> + </md:KeyDescriptor> + <md:KeyDescriptor use="encryption"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -199,33 +204,42 @@ R/BU8rcOeQ5KU1e3ooJqSzIKBhWce80g4TaX1u1rYibKqkSUwgp1Jh2MSnKN0B8c </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.kkh.se:8443/idp/profile/SAML1/SOAP/AttributeQuery"/> + </md:KeyDescriptor> + <md:AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp2.kkh.se:8443/idp/profile/SAML1/SOAP/AttributeQuery"/> <!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp2.kkh.se:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> --> <!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above --> - </AttributeAuthorityDescriptor> - <Organization xmlns="urn:oasis:names:tc:SAML:2.0:metadata"> - <OrganizationName xml:lang="en">KKH</OrganizationName> - <OrganizationDisplayName xml:lang="sv">Kungl. Konsthögskolan</OrganizationDisplayName> - <OrganizationDisplayName xml:lang="en">Royal Institute of Art</OrganizationDisplayName> - <OrganizationURL xml:lang="en">http://www.kkh.se</OrganizationURL> - </Organization> - <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="administrative"> - <Company>Kungl. Konsthögskolan</Company> - <SurName>Fredrik Reuterswärd</SurName> - <EmailAddress>mailto:fredrik.reutersward@kkh.se</EmailAddress> - <TelephoneNumber>+4686144064</TelephoneNumber> - </ContactPerson> - <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="technical"> - <Company>Kungl. Konsthögskolan</Company> - <SurName>Fredrik Reuterswärd</SurName> - <EmailAddress>mailto:fredrik.reutersward@kkh.se</EmailAddress> - <TelephoneNumber>+4686144064</TelephoneNumber> - </ContactPerson> - <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="support"> - <Company>Kungl. Konsthögskolan</Company> - <SurName>Fredrik Reuterswärd</SurName> - <EmailAddress>mailto:fredrik.reutersward@kkh.se</EmailAddress> - <TelephoneNumber>+4686144064</TelephoneNumber> - </ContactPerson> + </md:AttributeAuthorityDescriptor> + <md:Organization> + <md:OrganizationName xml:lang="en">KKH</md:OrganizationName> + <md:OrganizationName xml:lang="sv">KKH</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="sv">Kungl. Konsthögskolan</md:OrganizationDisplayName> + <md:OrganizationDisplayName xml:lang="en">Royal Institute of Art</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="en">https://www.kkh.se</md:OrganizationURL> + <md:OrganizationURL xml:lang="sv">https://www.kkh.se</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="administrative"> + <md:Company>Kungl. Konsthögskolan</md:Company> + <md:SurName>Fredrik Reuterswärd</md:SurName> + <md:EmailAddress>mailto:it-support@kkh.se</md:EmailAddress> + <md:TelephoneNumber>+4686144000</md:TelephoneNumber> + </md:ContactPerson> + <md:ContactPerson contactType="technical"> + <md:Company>Kungl. Konsthögskolan</md:Company> + <md:SurName>IT-Support</md:SurName> + <md:EmailAddress>mailto:it-support@kkh.se</md:EmailAddress> + <md:TelephoneNumber>+4686144000</md:TelephoneNumber> + </md:ContactPerson> + <md:ContactPerson contactType="support"> + <md:Company>Kungl. Konsthögskolan</md:Company> + <md:SurName>IT-Support</md:SurName> + <md:EmailAddress>mailto:it-support@kkh.se</md:EmailAddress> + <md:TelephoneNumber>+4686144000</md:TelephoneNumber> + </md:ContactPerson> + <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security"> + <md:Company>Kungl. Konsthögskolan</md:Company> + <md:GivenName>KKH</md:GivenName> + <md:SurName>IT-Security</md:SurName> + <md:EmailAddress>mailto:abuse@kkh.se</md:EmailAddress> + <md:TelephoneNumber>+4686144000</md:TelephoneNumber> + </md:ContactPerson> </md:EntityDescriptor> |