summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBjörn Mattsson <bjorn@sunet.se>2021-11-23 07:42:30 +0100
committerBjörn Mattsson <bjorn@sunet.se>2021-11-23 07:42:30 +0100
commitf26841e611c36bf7b393119402cab286a90bf99e (patch)
treebfe663041662b3ea475b980fcd56c07c7eef6a88
parent33c6a5884c77777e11677a34d75025ff5d393455 (diff)
SWAMID-511, added new key to SP
-rw-r--r--swamid-2.0/vfu.su.se-shibboleth.sso.xml102
1 files changed, 83 insertions, 19 deletions
diff --git a/swamid-2.0/vfu.su.se-shibboleth.sso.xml b/swamid-2.0/vfu.su.se-shibboleth.sso.xml
index 86e78336..28317d6d 100644
--- a/swamid-2.0/vfu.su.se-shibboleth.sso.xml
+++ b/swamid-2.0/vfu.su.se-shibboleth.sso.xml
@@ -9,25 +9,43 @@
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
</samla:Attribute>
</mdattr:EntityAttributes>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
</md:Extensions>
<md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
+ <mdui:UIInfo>
+ <mdui:DisplayName xml:lang="sv">Verksamhetsförlagd utbildning Stockholms universitet</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="en">Workplace Situated Education at Stockholm University</mdui:DisplayName>
+ <mdui:Description xml:lang="sv">VFU är verksamhetsfölagd utbildning där utbildningen sker på en arbetsplats</mdui:Description>
+ <mdui:Description xml:lang="en">VFU is workplace situated education where the education takes place at a work place</mdui:Description>
+ <mdui:PrivacyStatementURL xml:lang="en">https://serviceportalen.su.se/sv-se/article/1366077</mdui:PrivacyStatementURL>
+ </mdui:UIInfo>
<init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF"/>
<idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vfu.su.se/Shibboleth.sso/WAYF" index="1"/>
<init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/wavelan"/>
<idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vfu.su.se/Shibboleth.sso/WAYF/wavelan" index="2"/>
- <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/idp.secure.su.se"/>
<init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/idp.it.su.se"/>
<init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/guest-idp.it.su.se"/>
<init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/SWAMID"/>
<idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vfu.su.se/Shibboleth.sso/SWAMID" index="3"/>
- <mdui:UIInfo>
- <mdui:DisplayName xml:lang="sv">Verksamhetsförlagd utbildning Stockholms universitet</mdui:DisplayName>
- <mdui:DisplayName xml:lang="en">Workplace Situated Education at Stockholm University</mdui:DisplayName>
- <mdui:Description xml:lang="sv">VFU är verksamhetsfölagd utbildning där utbildningen sker på en arbetsplats</mdui:Description>
- <mdui:Description xml:lang="en">VFU is workplace situated education where the education takes place at a work place</mdui:Description>
- <mdui:PrivacyStatementURL xml:lang="en">https://serviceportalen.su.se/sv-se/article/1366077</mdui:PrivacyStatementURL>
- </mdui:UIInfo>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/eduid.se"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/skolfederation-prod-ds"/>
+ <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vfu.su.se/Shibboleth.sso/WAYF/skolfederation-prod-ds" index="4"/>
</md:Extensions>
<md:KeyDescriptor>
<ds:KeyInfo>
@@ -53,6 +71,55 @@ ZbIlfQJbU+IsF+PBKYkQ9oGeHIBu0E6lRYjrmIFz1n176w==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
+ </md:KeyDescriptor>
+ <md:KeyDescriptor>
+ <ds:KeyInfo>
+ <ds:KeyName>vfu-prod-app05.it.su.se</ds:KeyName>
+ <ds:X509Data>
+ <ds:X509SubjectName>CN=vfu-prod-app05.it.su.se</ds:X509SubjectName>
+ <ds:X509Certificate>MIIEDDCCAnSgAwIBAgIJAPC59dnuvAHaMA0GCSqGSIb3DQEBCwUAMCIxIDAeBgNV
+BAMTF3ZmdS1wcm9kLWFwcDA1Lml0LnN1LnNlMB4XDTIxMTEyMjEyNDk0NVoXDTMx
+MTEyMDEyNDk0NVowIjEgMB4GA1UEAxMXdmZ1LXByb2QtYXBwMDUuaXQuc3Uuc2Uw
+ggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQD7BRcdGvDuvEKW7nI2IXhd
+yhF0n8UTrpGZm5LCuKFKO+2FdMUCADxbQNRcZ+DUs+aHg14/j0AISwiye9DHxCt0
+haIRRXjUwVX8tTPRoVqrUhFFWkQF//NzQQwnXEaoeueBBpH1c42Elr+NRxKmMUfC
+eHLiRfgL/edftRyPFCjj3viM6jrN2ZvNar49w0LEuHrHDNzxY8zsl/TiZw/bPYsc
+UDfzMlUXPIlRB2x3LEvG21HZL9X9Hjh15CUcXMjLl4JLRlcHJwrCuPm6bbUKNBfY
+NjuUk7sId/I6544/asXsvrZXzm8W6/nnBpJn/BDIlzgUVRXSBsBTa8/kgpoZLBtF
+Bf/zBy7KX2hPtWIZsKeW89W2flBfNfqo9Hv4lgTU/dPW9Mxmunhj3a4mx4Q/u5pW
+nhoMlHkl6xnxmWE34vSd/Okas44dkta3dOtU+xKu1qpbcdErcY4/ajAfg/enJsZE
+crZEpsjZY4QDMUfippivhYJuxGkUljX7bqi4cdmMzicCAwEAAaNFMEMwIgYDVR0R
+BBswGYIXdmZ1LXByb2QtYXBwMDUuaXQuc3Uuc2UwHQYDVR0OBBYEFE9CiR/TH779
+Jb54z/8T9msdl1JiMA0GCSqGSIb3DQEBCwUAA4IBgQAYWpcAE9WvpSB6Yw4isTv0
+e2G4vKEZt0Jb43SxFZYFsBJKOQQcruW2q2GzQ91RdR4yXNqxH+lg0jN+ZFxwUmud
+1YXdNfqJj1XTKiyOwM7wAgTfH6Dxra6AYrqw3dFa7o4KWFfWRBC9CgdBchxQfKU7
+ePNyPD/+ivBKuNyRkujEbveZl/5DAkM8RuwSHPv58t42VUENH0xS2o9J9/Ji0BDL
+xg4+EPADl0CZA7X0n47KtoiJRAWMHb5ncucUDi1U/df3sclekojzlZeoJp9dujaS
+O5XKFYximElL4oFRoadCp5duFWTfepDvt5djjUEvJyOWlDYQvE7k4G14DPfkM4GD
+G/ySPwDEM2A0z1AEaGFpTfKSFJElnBDFk0nSO2BMduLScwYJsufVNq7YAWj9X6Mu
+qOfw/9G0lx9aKTCBDIqSWsuQ9ia5eWZ/CG1YsMMeGzwQ6kmwXPuDFLaQMafM3JrL
+xtIkLUQaKMFwmgCD9Ty7aIm61iPNZZJKBPXNpHbx5Ck=
+</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
</md:KeyDescriptor>
<md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vfu.su.se/Shibboleth.sso/Artifact/SOAP" index="1"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vfu.su.se/Shibboleth.sso/SLO/SOAP"/>
@@ -64,21 +131,18 @@ ZbIlfQJbU+IsF+PBKYkQ9oGeHIBu0E6lRYjrmIFz1n176w==
<md:ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vfu.su.se/Shibboleth.sso/NIM/POST"/>
<md:ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vfu.su.se/Shibboleth.sso/NIM/Artifact"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://vfu.su.se/Shibboleth.sso/SAML/POST" index="5"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://vfu.su.se/Shibboleth.sso/SAML/Artifact" index="6"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vfu.su.se/Shibboleth.sso/SAML2/POST" index="7"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://vfu.su.se/Shibboleth.sso/SAML2/POST-SimpleSign" index="8"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vfu.su.se/Shibboleth.sso/SAML2/Artifact" index="9"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://vfu.su.se/Shibboleth.sso/SAML2/ECP" index="10"/>
- <md:AttributeConsumingService index="1">
- <md:ServiceName xml:lang="en">VFU</md:ServiceName>
- <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vfu.su.se/Shibboleth.sso/SAML2/POST" index="6"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vfu.su.se/Shibboleth.sso/SAML2/Artifact" index="7"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://vfu.su.se/Shibboleth.sso/SAML2/ECP" index="8"/>
+ <md:AttributeConsumingService index="1" isDefault="true">
+ <md:ServiceName xml:lang="en">VFU-portalen</md:ServiceName>
+ <md:RequestedAttribute FriendlyName="email" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
- <md:RequestedAttribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="surName" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="norEduPersonNIN" Name="urn:oid:1.3.6.1.4.1.2428.90.1.5" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
- <md:RequestedAttribute FriendlyName="eduPersonAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
- <md:RequestedAttribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
</md:AttributeConsumingService>
</md:SPSSODescriptor>
<md:Organization>