summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorPaul Scott <paul.scott@kau.se>2022-02-28 09:59:32 +0100
committerPaul Scott <paul.scott@kau.se>2022-02-28 09:59:32 +0100
commitea1df9bdb30359f14bcaba53ebeb2da619256b76 (patch)
tree45036501d9e1ea97618c2b5d37eb6483fe4cd9c5
parentc1d1f1bc41c79e35b1397aed848de94153fb37fa (diff)
SWAMID-732 and SWAMID-733
-rw-r--r--swamid-2.0/adfs.ju.se-adfs-services-trust.xml28
-rw-r--r--swamid-2.0/idp.hj.se-idp-shibboleth.xml122
2 files changed, 79 insertions, 71 deletions
diff --git a/swamid-2.0/adfs.ju.se-adfs-services-trust.xml b/swamid-2.0/adfs.ju.se-adfs-services-trust.xml
index d8abd5ae..1c882b36 100644
--- a/swamid-2.0/adfs.ju.se-adfs-services-trust.xml
+++ b/swamid-2.0/adfs.ju.se-adfs-services-trust.xml
@@ -7,13 +7,16 @@
<mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
<samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<samla:AttributeValue>http://www.swamid.se/category/sfs-1993-1153</samla:AttributeValue>
- <samla:AttributeValue>http://refeds.org/category/hide-from-discovery</samla:AttributeValue>
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
</samla:Attribute>
<samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<samla:AttributeValue>http://www.swamid.se/policy/assurance/al1</samla:AttributeValue>
<samla:AttributeValue>http://www.swamid.se/policy/assurance/al2</samla:AttributeValue>
</samla:Attribute>
+ <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category-support" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>http://refeds.org/category/research-and-scholarship</samla:AttributeValue>
+ <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
+ </samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
<md:SPSSODescriptor WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
@@ -21,8 +24,8 @@
<mdui:UIInfo>
<mdui:Description xml:lang="en">This service is used for login to services at Jönköping University.</mdui:Description>
<mdui:Description xml:lang="sv">Denna applikation används för inloggning till tjänster hos Jönköping University.</mdui:Description>
- <mdui:DisplayName xml:lang="en">Jönköping University - Login service</mdui:DisplayName>
- <mdui:DisplayName xml:lang="sv">Jönköping University - Gemensam inloggningstjänst</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="en">Jönköping University</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="sv">Jönköping University</mdui:DisplayName>
<mdui:InformationURL xml:lang="en">http://ju.se/en/it-helpdesk.html</mdui:InformationURL>
<mdui:InformationURL xml:lang="sv">http://ju.se/it-helpdesk.html</mdui:InformationURL>
<mdui:Logo xml:lang="en" height="88" width="197">https://account.win.hj.se/JU_A_sv_Swamid.png</mdui:Logo>
@@ -52,7 +55,6 @@
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://adfs.ju.se/adfs/ls/" index="0" isDefault="true"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://adfs.ju.se/adfs/ls/" index="1"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://adfs.ju.se/adfs/ls/" index="2"/>
<md:AttributeConsumingService index="1">
<md:ServiceName xml:lang="en">Jönköping University - Login service</md:ServiceName>
<md:ServiceName xml:lang="sv">Jönköping University - Gemensam inloggningstjänst</md:ServiceName>
@@ -66,18 +68,22 @@
<mdui:UIInfo>
<mdui:Description xml:lang="en">The Jönköping University Identity Provider is used by employees and students at the university.</mdui:Description>
<mdui:Description xml:lang="sv">Inloggningstjänst för anställda och studenter vid Jönköping University.</mdui:Description>
- <mdui:DisplayName xml:lang="en">Jönköping University - ADFS</mdui:DisplayName>
- <mdui:DisplayName xml:lang="sv">Jönköping University - ADFS</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="en">Jönköping University</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="sv">Jönköping University</mdui:DisplayName>
<mdui:InformationURL xml:lang="en">http://ju.se/en.html</mdui:InformationURL>
<mdui:InformationURL xml:lang="sv">http://ju.se</mdui:InformationURL>
- <mdui:Keywords xml:lang="en">hj hogskolan+i+jonkoping jonkoping+university</mdui:Keywords>
- <mdui:Keywords xml:lang="sv">hj hogskolan+i+jonkoping jonkoping+university</mdui:Keywords>
- <mdui:Logo xml:lang="en" height="140" width="315">https://idp.hj.se/idp/images/logo.png</mdui:Logo>
- <mdui:Logo xml:lang="sv" height="140" width="315">https://idp.hj.se/idp/images/logo.png</mdui:Logo>
<mdui:PrivacyStatementURL xml:lang="en">https://ju.se/en/it-helpdesk/faq---manuals/my-user-account/other/joint-web-login-service.html</mdui:PrivacyStatementURL>
- <mdui:PrivacyStatementURL xml:lang="sv">http://hj.se/it-helpdesk/faq---manualer/mitt-anvandarkonto/ovrigt/gemensam-inloggningstjanst.html</mdui:PrivacyStatementURL>
+ <mdui:PrivacyStatementURL xml:lang="sv">http://ju.se/it-helpdesk/faq---manualer/mitt-anvandarkonto/ovrigt/gemensam-inloggningstjanst.html</mdui:PrivacyStatementURL>
+ <mdui:Logo xml:lang="en" height="88" width="197">https://account.win.hj.se/JU_A_sv_Swamid.png</mdui:Logo>
+ <mdui:Logo xml:lang="sv" height="88" width="197">https://account.win.hj.se/JU_A_sv_Swamid.png</mdui:Logo>
+ <mdui:Keywords xml:lang="en">ju hj hogskolan+i+jonkoping jonkoping+university</mdui:Keywords>
+ <mdui:Keywords xml:lang="sv">ju hj hogskolan+i+jonkoping jonkoping+university</mdui:Keywords>
</mdui:UIInfo>
<mdui:DiscoHints>
+ <mdui:GeolocationHint>geo:57.7783,14.1633</mdui:GeolocationHint>
+ <mdui:DomainHint>hj.se</mdui:DomainHint>
+ </mdui:DiscoHints>
+ <mdui:DiscoHints>
<mdui:DomainHint>hj.se</mdui:DomainHint>
<mdui:GeolocationHint>geo:57.7783,14.1633</mdui:GeolocationHint>
</mdui:DiscoHints>
diff --git a/swamid-2.0/idp.hj.se-idp-shibboleth.xml b/swamid-2.0/idp.hj.se-idp-shibboleth.xml
index 6065db70..4ff9d44f 100644
--- a/swamid-2.0/idp.hj.se-idp-shibboleth.xml
+++ b/swamid-2.0/idp.hj.se-idp-shibboleth.xml
@@ -4,23 +4,23 @@
<mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2016-03-14T13:20:10Z">
<mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
- <attr:EntityAttributes xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:attr="urn:oasis:names:tc:SAML:metadata:attribute">
- <saml:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
- <saml:AttributeValue>http://www.swamid.se/policy/assurance/al1</saml:AttributeValue>
- <saml:AttributeValue>http://www.swamid.se/policy/assurance/al2</saml:AttributeValue>
- </saml:Attribute>
+ <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
+ <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>http://www.swamid.se/policy/assurance/al1</samla:AttributeValue>
+ <samla:AttributeValue>http://www.swamid.se/policy/assurance/al2</samla:AttributeValue>
+ </samla:Attribute>
<samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category-support">
<samla:AttributeValue>http://refeds.org/category/research-and-scholarship</samla:AttributeValue>
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
</samla:Attribute>
- </attr:EntityAttributes>
+ </mdattr:EntityAttributes>
</md:Extensions>
- <IDPSSODescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0" errorURL="https://idp.hj.se/error/?errorurl_code=ERRORURL_CODE&amp;errorurl_ts=ERRORURL_TS&amp;errorurl_rp=ERRORURL_RP&amp;errorurl_tid=ERRORURL_TID&amp;errorurl_ctx=ERRORURL_CTX">
- <Extensions>
+ <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0" errorURL="https://idp.hj.se/error/?errorurl_code=ERRORURL_CODE&amp;errorurl_ts=ERRORURL_TS&amp;errorurl_rp=ERRORURL_RP&amp;errorurl_tid=ERRORURL_TID&amp;errorurl_ctx=ERRORURL_CTX">
+ <md:Extensions>
<shibmd:Scope regexp="false">hj.se</shibmd:Scope>
<mdui:UIInfo>
- <mdui:DisplayName xml:lang="sv">Jönköping University</mdui:DisplayName>
- <mdui:DisplayName xml:lang="en">Jönköping University</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="sv">Jönköping University - OLD</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="en">Jönköping University - OLD</mdui:DisplayName>
<mdui:Description xml:lang="sv">Inloggningstjänst för anställda och studenter vid Jönköping University.</mdui:Description>
<mdui:Description xml:lang="en">The Jönköping University Identity Provider is used by employees and students at the university.</mdui:Description>
<mdui:InformationURL xml:lang="sv">http://ju.se</mdui:InformationURL>
@@ -36,8 +36,8 @@
<mdui:DomainHint>hj.se</mdui:DomainHint>
<mdui:GeolocationHint>geo:57.7783,14.1633</mdui:GeolocationHint>
</mdui:DiscoHints>
- </Extensions>
- <KeyDescriptor use="signing">
+ </md:Extensions>
+ <md:KeyDescriptor use="signing">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -61,8 +61,8 @@ qbiphg2PJniZhcfItlrn7pTs/g==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <KeyDescriptor use="signing">
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="signing">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -86,8 +86,8 @@ wHTEWQ0LC1zCU0Mh0mCpi9a19HI=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <KeyDescriptor use="encryption">
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="encryption">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -111,25 +111,25 @@ I91KnWp+FpSd3F3W0MlM1+MiKQ==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.hj.se:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
- <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.hj.se:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
+ </md:KeyDescriptor>
+ <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.hj.se:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
+ <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.hj.se:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
<!--
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.hj.se/idp/profile/SAML2/Redirect/SLO"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.hj.se/idp/profile/SAML2/POST/SLO"/>
<SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.hj.se:8443/idp/profile/SAML2/SOAP/SLO"/>
-->
- <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
- <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
- <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.hj.se/idp/profile/Shibboleth/SSO"/>
- <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.hj.se/idp/profile/SAML2/POST/SSO"/>
- <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.hj.se/idp/profile/SAML2/Redirect/SSO"/>
- </IDPSSODescriptor>
- <AttributeAuthorityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
- <Extensions>
+ <md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat>
+ <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
+ <md:SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.hj.se/idp/profile/Shibboleth/SSO"/>
+ <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.hj.se/idp/profile/SAML2/POST/SSO"/>
+ <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.hj.se/idp/profile/SAML2/Redirect/SSO"/>
+ </md:IDPSSODescriptor>
+ <md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
+ <md:Extensions>
<shibmd:Scope regexp="false">hj.se</shibmd:Scope>
- </Extensions>
- <KeyDescriptor use="signing">
+ </md:Extensions>
+ <md:KeyDescriptor use="signing">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -153,8 +153,8 @@ qbiphg2PJniZhcfItlrn7pTs/g==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <KeyDescriptor use="signing">
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="signing">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -178,8 +178,8 @@ wHTEWQ0LC1zCU0Mh0mCpi9a19HI=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <KeyDescriptor use="encryption">
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="encryption">
<ds:KeyInfo>
<ds:X509Data>
<ds:X509Certificate>
@@ -203,33 +203,35 @@ I91KnWp+FpSd3F3W0MlM1+MiKQ==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
- </KeyDescriptor>
- <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.hj.se:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
+ </md:KeyDescriptor>
+ <md:AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.hj.se:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
<!-- <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.hj.se:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> -->
<!-- If you uncomment the above you should add urn:oasis:names:tc:SAML:2.0:protocol to the protocolSupportEnumeration above -->
- </AttributeAuthorityDescriptor>
- <Organization xmlns="urn:oasis:names:tc:SAML:2.0:metadata">
- <OrganizationName xml:lang="en">HJ</OrganizationName>
- <OrganizationDisplayName xml:lang="sv">Högskolan i Jönköping</OrganizationDisplayName>
- <OrganizationDisplayName xml:lang="en">Jönköping University</OrganizationDisplayName>
- <OrganizationURL xml:lang="en">http://www.ju.se</OrganizationURL>
- </Organization>
- <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="administrative">
- <Company>Jönköping University</Company>
- <SurName>Joakim Danielsson</SurName>
- <EmailAddress>mailto:swamid@ju.se</EmailAddress>
- <TelephoneNumber>+46 36 101116</TelephoneNumber>
- </ContactPerson>
- <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="technical">
- <Company>Jönköping University</Company>
- <SurName>Stefan Kindh</SurName>
- <EmailAddress>mailto:swamid@ju.se</EmailAddress>
- <TelephoneNumber>+46 36 101170</TelephoneNumber>
- </ContactPerson>
- <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="support">
- <Company>Jönköping University</Company>
- <SurName>IT-Helpdesk</SurName>
- <EmailAddress>mailto:swamid@ju.se</EmailAddress>
- <TelephoneNumber>+46 36 101112</TelephoneNumber>
- </ContactPerson>
+ </md:AttributeAuthorityDescriptor>
+ <md:Organization>
+ <md:OrganizationName xml:lang="en">HJ</md:OrganizationName>
+ <md:OrganizationName xml:lang="sv">HJ</md:OrganizationName>
+ <md:OrganizationDisplayName xml:lang="sv">Högskolan i Jönköping</md:OrganizationDisplayName>
+ <md:OrganizationDisplayName xml:lang="en">Jönköping University</md:OrganizationDisplayName>
+ <md:OrganizationURL xml:lang="en">http://www.ju.se</md:OrganizationURL>
+ <md:OrganizationURL xml:lang="sv">http://www.ju.se</md:OrganizationURL>
+ </md:Organization>
+ <md:ContactPerson contactType="administrative">
+ <md:Company>Jönköping University</md:Company>
+ <md:SurName>Joakim Danielsson</md:SurName>
+ <md:EmailAddress>mailto:swamid@ju.se</md:EmailAddress>
+ <md:TelephoneNumber>+46 36 101116</md:TelephoneNumber>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="technical">
+ <md:Company>Jönköping University</md:Company>
+ <md:SurName>Stefan Kindh</md:SurName>
+ <md:EmailAddress>mailto:swamid@ju.se</md:EmailAddress>
+ <md:TelephoneNumber>+46 36 101170</md:TelephoneNumber>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="support">
+ <md:Company>Jönköping University</md:Company>
+ <md:SurName>IT-Helpdesk</md:SurName>
+ <md:EmailAddress>mailto:swamid@ju.se</md:EmailAddress>
+ <md:TelephoneNumber>+46 36 101112</md:TelephoneNumber>
+ </md:ContactPerson>
</md:EntityDescriptor>