summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorPaul Scott <paul.scott@kau.se>2015-05-07 11:04:43 +0200
committerPaul Scott <paul.scott@kau.se>2015-05-07 11:04:43 +0200
commit546aef302563a52ef984d2c8789f2cc2dbcc4406 (patch)
tree815681fa24dc41b4471a718f3f66d7d61747d5a7
parent1531f270e62c40f24ecf411f3b4497d6b8dff4bd (diff)
Partially resolves SWAMIDOPS-7665, waiting for mdui
-rw-r--r--swamid-2.0/minastudier-test.su.se-shibboleth.sso.xml117
1 files changed, 63 insertions, 54 deletions
diff --git a/swamid-2.0/minastudier-test.su.se-shibboleth.sso.xml b/swamid-2.0/minastudier-test.su.se-shibboleth.sso.xml
index c05a7ad6..7d94267f 100644
--- a/swamid-2.0/minastudier-test.su.se-shibboleth.sso.xml
+++ b/swamid-2.0/minastudier-test.su.se-shibboleth.sso.xml
@@ -1,64 +1,74 @@
<?xml version="1.0" encoding="UTF-8"?>
+<!--
+This is example metadata only. Do *NOT* supply it as is without review,
+and do *NOT* provide it in real time to your partners.
+ -->
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://minastudier-test.su.se/Shibboleth.sso">
+ <md:Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport">
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
+ </md:Extensions>
<md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
- <DiscoveryResponse xmlns="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://minastudier-test.su.se/Shibboleth.sso/WAYF" index="1"/>
- <DiscoveryResponse xmlns="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://minastudier-test.su.se/Shibboleth.sso/WAYF/wavelan" index="1"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://minastudier-test.su.se/Shibboleth.sso/WAYF/idp-test.it.su.se"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://minastudier-test.su.se/Shibboleth.sso/WAYF/idp.it.su.se"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://minastudier-test.su.se/Shibboleth.sso/WAYF"/>
+ <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://minastudier-test.su.se/Shibboleth.sso/WAYF" index="1"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://minastudier-test.su.se/Shibboleth.sso/WAYF/wavelan"/>
+ <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://minastudier-test.su.se/Shibboleth.sso/WAYF/wavelan" index="2"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://minastudier-test.su.se/Shibboleth.sso/WAYF/idp.secure.su.se"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://minastudier-test.su.se/Shibboleth.sso/SWAMID"/>
</md:Extensions>
- <md:KeyDescriptor use="signing">
+ <md:KeyDescriptor>
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
- <ds:KeyName>lpwtool-test-minastudier1.it.su.se</ds:KeyName>
+ <ds:KeyName>lpwtool-mstest-sp01</ds:KeyName>
<ds:X509Data>
- <ds:X509SubjectName>CN=lpwtool-test-minastudier1.it.su.se</ds:X509SubjectName>
- <ds:X509Certificate>MIIDLTCCAhWgAwIBAgIJAO6dTFyNy8P8MA0GCSqGSIb3DQEBBQUAMC0xKzApBgNV
-BAMTImxwd3Rvb2wtdGVzdC1taW5hc3R1ZGllcjEuaXQuc3Uuc2UwHhcNMTAwNDE2
-MTMzODEyWhcNMjAwNDEzMTMzODEyWjAtMSswKQYDVQQDEyJscHd0b29sLXRlc3Qt
-bWluYXN0dWRpZXIxLml0LnN1LnNlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB
-CgKCAQEApE9pxymoa/IN2TGMMI4U7N2vLBkuRrQc7EQp27mKQ3iYx47Avgy+uXgO
-TdzpdNyfl7g97UoaavjGrPBruDCqDVQ6FmTZMtKyLBgcAhdYk8Rh3WJfUKxTJlLY
-m1Ul5bp331hX64/55Ol37W7ptXarWdO0JAJ+/V4p+sD0V0yXU2ER0Y6iYZebjJUj
-nVJqH7bkLrHowTHXRRRVsGBennZ/7MfeVeNgYF9E2+0zCzLBihB7AKKP/guCJ48L
-FL2UlIX16eDttaV8dYQVx7NjkZIKaGndMwTL6f2hjdTDPkxQ+kBH5Hd5mseqUkrD
-iUcJoW2J+xMPsGiE+6sxEXryIiY5xQIDAQABo1AwTjAtBgNVHREEJjAkgiJscHd0
-b29sLXRlc3QtbWluYXN0dWRpZXIxLml0LnN1LnNlMB0GA1UdDgQWBBSWNsYqg7gK
-GpoHl72/rcWgUYJ14DANBgkqhkiG9w0BAQUFAAOCAQEAilGUE3B8Be7jdqohQ7v5
-jk5N/DHRiPR5M0U1Q3GojKyL88PkMSxhoiiOxQxWbkm5vCkiTBe9TW8ImE8tW26h
-hedSYgMWqLcCG/ryNLV0kuEoufdYK01HZvjWdUOow8R7fhizWW8ui8dY4X2JqsyR
-M7jwX8Ouk5x+0OrWPGRQvtTRBQwXPcLskGsFFADXP381VWJF+x4/FUn2j6X6wh5h
-NlWn2FgI/5o342VnqfcLVgSO1EouAuHkZO3KXlBij/GPXJkhwzZz6rChMrj4vXW5
-ZK2zpCBoomJUHOg1LC4f0gDNWwog62bUCyxzXmIycz+y9n1xn0thBuOjAOQOZ32K
-Og==
-</ds:X509Certificate>
- </ds:X509Data>
- </ds:KeyInfo>
- </md:KeyDescriptor>
- <md:KeyDescriptor use="encryption">
- <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
- <ds:KeyName>lpwtool-test-minastudier1.it.su.se</ds:KeyName>
- <ds:X509Data>
- <ds:X509SubjectName>CN=lpwtool-test-minastudier1.it.su.se</ds:X509SubjectName>
- <ds:X509Certificate>MIIDLTCCAhWgAwIBAgIJAO6dTFyNy8P8MA0GCSqGSIb3DQEBBQUAMC0xKzApBgNV
-BAMTImxwd3Rvb2wtdGVzdC1taW5hc3R1ZGllcjEuaXQuc3Uuc2UwHhcNMTAwNDE2
-MTMzODEyWhcNMjAwNDEzMTMzODEyWjAtMSswKQYDVQQDEyJscHd0b29sLXRlc3Qt
-bWluYXN0dWRpZXIxLml0LnN1LnNlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB
-CgKCAQEApE9pxymoa/IN2TGMMI4U7N2vLBkuRrQc7EQp27mKQ3iYx47Avgy+uXgO
-TdzpdNyfl7g97UoaavjGrPBruDCqDVQ6FmTZMtKyLBgcAhdYk8Rh3WJfUKxTJlLY
-m1Ul5bp331hX64/55Ol37W7ptXarWdO0JAJ+/V4p+sD0V0yXU2ER0Y6iYZebjJUj
-nVJqH7bkLrHowTHXRRRVsGBennZ/7MfeVeNgYF9E2+0zCzLBihB7AKKP/guCJ48L
-FL2UlIX16eDttaV8dYQVx7NjkZIKaGndMwTL6f2hjdTDPkxQ+kBH5Hd5mseqUkrD
-iUcJoW2J+xMPsGiE+6sxEXryIiY5xQIDAQABo1AwTjAtBgNVHREEJjAkgiJscHd0
-b29sLXRlc3QtbWluYXN0dWRpZXIxLml0LnN1LnNlMB0GA1UdDgQWBBSWNsYqg7gK
-GpoHl72/rcWgUYJ14DANBgkqhkiG9w0BAQUFAAOCAQEAilGUE3B8Be7jdqohQ7v5
-jk5N/DHRiPR5M0U1Q3GojKyL88PkMSxhoiiOxQxWbkm5vCkiTBe9TW8ImE8tW26h
-hedSYgMWqLcCG/ryNLV0kuEoufdYK01HZvjWdUOow8R7fhizWW8ui8dY4X2JqsyR
-M7jwX8Ouk5x+0OrWPGRQvtTRBQwXPcLskGsFFADXP381VWJF+x4/FUn2j6X6wh5h
-NlWn2FgI/5o342VnqfcLVgSO1EouAuHkZO3KXlBij/GPXJkhwzZz6rChMrj4vXW5
-ZK2zpCBoomJUHOg1LC4f0gDNWwog62bUCyxzXmIycz+y9n1xn0thBuOjAOQOZ32K
-Og==
+ <ds:X509SubjectName>CN=lpwtool-mstest-sp01</ds:X509SubjectName>
+ <ds:X509Certificate>MIIDADCCAeigAwIBAgIJAJalLGXlzrucMA0GCSqGSIb3DQEBBQUAMB4xHDAaBgNV
+BAMTE2xwd3Rvb2wtbXN0ZXN0LXNwMDEwHhcNMTUwNTA2MTIxMjUxWhcNMjUwNTAz
+MTIxMjUxWjAeMRwwGgYDVQQDExNscHd0b29sLW1zdGVzdC1zcDAxMIIBIjANBgkq
+hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEArNRHDHOKP1CUDuDW/85MifgZ8Ho/cOKP
+9orjRrjr0YUsM6x2HXooxCkpdTOcCaPPJtr1lP4tGtqPCWXjchyxX0HrIWqe7kWT
+W1DkE3Iv6SmgaI+7J6OBCDuuy0E2A7z0n9MnZE3iM2ICR9j8gUFkBGT3rHD7ZJ6J
+mQkSw8CsHMx5b3ASNHtmbhIdtCGM/POKgUWcK31Ef3GEhulPUogJ8+QmRND8C5oy
+cG6ObaVHy9JZ+y3nlEkKQxdgIpBO/PwkYd7WkPvHtm4enzXE3VIftTrdcbRPKC0Q
+goB8gncZS9LXtrirrQyfdHyvdoO5a09dx7QO3i8hG41EfZfZup2DnwIDAQABo0Ew
+PzAeBgNVHREEFzAVghNscHd0b29sLW1zdGVzdC1zcDAxMB0GA1UdDgQWBBTc7nW/
+1CG97xuDpga/x7OolZkWRjANBgkqhkiG9w0BAQUFAAOCAQEAGRXo6GCdHfkgSbI6
+xUJamYO1uw9Ao5bCARgIDVwBxKn9Ui4HgEiIROJfCV3+w5d7b9ipek6AXUOv90yH
+Uxf1GR+M5VMC71AimByyIaRv8LjG34IxGgpCgMWilyAs13V9BQLSau4SMCtMhPI6
++1lf3ECSO7pA98p34uGuEwFNCQ7QSOAaNjHz8b1znghRWzZO7XBJnF9fcsWem4ID
+XYCIfPsH3AqPrFK+RjXdaQGe0NLYTi/bgbFT3nmskF2rHwi8KILTZg2YXOldA9N7
+ai7Ak2EMywr/CkuMVSwv0HzkxGfNu+ef7E+SUOs/uNwGk4jLNravN2pM8ulUIb4X
+5yOvLg==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
</md:KeyDescriptor>
+ <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://minastudier-test.su.se/Shibboleth.sso/Artifact/SOAP" index="1"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://minastudier-test.su.se/Shibboleth.sso/SLO/SOAP"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://minastudier-test.su.se/Shibboleth.sso/SLO/Redirect"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://minastudier-test.su.se/Shibboleth.sso/SLO/POST"/>
@@ -69,9 +79,8 @@ Og==
<md:ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://minastudier-test.su.se/Shibboleth.sso/NIM/Artifact"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://minastudier-test.su.se/Shibboleth.sso/SAML/POST" index="5"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://minastudier-test.su.se/Shibboleth.sso/SAML/Artifact" index="6"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://minastudier-test.su.se/Shibboleth.sso/SAML2/POST" index="1"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://minastudier-test.su.se/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://minastudier-test.su.se/Shibboleth.sso/SAML2/Artifact" index="3"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://minastudier-test.su.se/Shibboleth.sso/SAML2/ECP" index="4"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://minastudier-test.su.se/Shibboleth.sso/SAML2/POST" index="7"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://minastudier-test.su.se/Shibboleth.sso/SAML2/Artifact" index="9"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://minastudier-test.su.se/Shibboleth.sso/SAML2/ECP" index="10"/>
</md:SPSSODescriptor>
</md:EntityDescriptor>