diff options
author | Björn Mattsson <bjorn@sunet.se> | 2021-11-23 07:42:30 +0100 |
---|---|---|
committer | Björn Mattsson <bjorn@sunet.se> | 2021-11-23 07:42:30 +0100 |
commit | f26841e611c36bf7b393119402cab286a90bf99e (patch) | |
tree | bfe663041662b3ea475b980fcd56c07c7eef6a88 | |
parent | 33c6a5884c77777e11677a34d75025ff5d393455 (diff) |
SWAMID-511, added new key to SP
-rw-r--r-- | swamid-2.0/vfu.su.se-shibboleth.sso.xml | 102 |
1 files changed, 83 insertions, 19 deletions
diff --git a/swamid-2.0/vfu.su.se-shibboleth.sso.xml b/swamid-2.0/vfu.su.se-shibboleth.sso.xml index 86e78336..28317d6d 100644 --- a/swamid-2.0/vfu.su.se-shibboleth.sso.xml +++ b/swamid-2.0/vfu.su.se-shibboleth.sso.xml @@ -9,25 +9,43 @@ <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue> </samla:Attribute> </mdattr:EntityAttributes> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/> </md:Extensions> <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol urn:oasis:names:tc:SAML:2.0:protocol"> <md:Extensions> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="sv">Verksamhetsförlagd utbildning Stockholms universitet</mdui:DisplayName> + <mdui:DisplayName xml:lang="en">Workplace Situated Education at Stockholm University</mdui:DisplayName> + <mdui:Description xml:lang="sv">VFU är verksamhetsfölagd utbildning där utbildningen sker på en arbetsplats</mdui:Description> + <mdui:Description xml:lang="en">VFU is workplace situated education where the education takes place at a work place</mdui:Description> + <mdui:PrivacyStatementURL xml:lang="en">https://serviceportalen.su.se/sv-se/article/1366077</mdui:PrivacyStatementURL> + </mdui:UIInfo> <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF"/> <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vfu.su.se/Shibboleth.sso/WAYF" index="1"/> <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/wavelan"/> <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vfu.su.se/Shibboleth.sso/WAYF/wavelan" index="2"/> - <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/idp.secure.su.se"/> <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/idp.it.su.se"/> <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/guest-idp.it.su.se"/> <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/SWAMID"/> <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vfu.su.se/Shibboleth.sso/SWAMID" index="3"/> - <mdui:UIInfo> - <mdui:DisplayName xml:lang="sv">Verksamhetsförlagd utbildning Stockholms universitet</mdui:DisplayName> - <mdui:DisplayName xml:lang="en">Workplace Situated Education at Stockholm University</mdui:DisplayName> - <mdui:Description xml:lang="sv">VFU är verksamhetsfölagd utbildning där utbildningen sker på en arbetsplats</mdui:Description> - <mdui:Description xml:lang="en">VFU is workplace situated education where the education takes place at a work place</mdui:Description> - <mdui:PrivacyStatementURL xml:lang="en">https://serviceportalen.su.se/sv-se/article/1366077</mdui:PrivacyStatementURL> - </mdui:UIInfo> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/eduid.se"/> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vfu.su.se/Shibboleth.sso/WAYF/skolfederation-prod-ds"/> + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vfu.su.se/Shibboleth.sso/WAYF/skolfederation-prod-ds" index="4"/> </md:Extensions> <md:KeyDescriptor> <ds:KeyInfo> @@ -53,6 +71,55 @@ ZbIlfQJbU+IsF+PBKYkQ9oGeHIBu0E6lRYjrmIFz1n176w== </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> + </md:KeyDescriptor> + <md:KeyDescriptor> + <ds:KeyInfo> + <ds:KeyName>vfu-prod-app05.it.su.se</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=vfu-prod-app05.it.su.se</ds:X509SubjectName> + <ds:X509Certificate>MIIEDDCCAnSgAwIBAgIJAPC59dnuvAHaMA0GCSqGSIb3DQEBCwUAMCIxIDAeBgNV +BAMTF3ZmdS1wcm9kLWFwcDA1Lml0LnN1LnNlMB4XDTIxMTEyMjEyNDk0NVoXDTMx +MTEyMDEyNDk0NVowIjEgMB4GA1UEAxMXdmZ1LXByb2QtYXBwMDUuaXQuc3Uuc2Uw +ggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQD7BRcdGvDuvEKW7nI2IXhd +yhF0n8UTrpGZm5LCuKFKO+2FdMUCADxbQNRcZ+DUs+aHg14/j0AISwiye9DHxCt0 +haIRRXjUwVX8tTPRoVqrUhFFWkQF//NzQQwnXEaoeueBBpH1c42Elr+NRxKmMUfC +eHLiRfgL/edftRyPFCjj3viM6jrN2ZvNar49w0LEuHrHDNzxY8zsl/TiZw/bPYsc +UDfzMlUXPIlRB2x3LEvG21HZL9X9Hjh15CUcXMjLl4JLRlcHJwrCuPm6bbUKNBfY +NjuUk7sId/I6544/asXsvrZXzm8W6/nnBpJn/BDIlzgUVRXSBsBTa8/kgpoZLBtF +Bf/zBy7KX2hPtWIZsKeW89W2flBfNfqo9Hv4lgTU/dPW9Mxmunhj3a4mx4Q/u5pW +nhoMlHkl6xnxmWE34vSd/Okas44dkta3dOtU+xKu1qpbcdErcY4/ajAfg/enJsZE +crZEpsjZY4QDMUfippivhYJuxGkUljX7bqi4cdmMzicCAwEAAaNFMEMwIgYDVR0R +BBswGYIXdmZ1LXByb2QtYXBwMDUuaXQuc3Uuc2UwHQYDVR0OBBYEFE9CiR/TH779 +Jb54z/8T9msdl1JiMA0GCSqGSIb3DQEBCwUAA4IBgQAYWpcAE9WvpSB6Yw4isTv0 +e2G4vKEZt0Jb43SxFZYFsBJKOQQcruW2q2GzQ91RdR4yXNqxH+lg0jN+ZFxwUmud +1YXdNfqJj1XTKiyOwM7wAgTfH6Dxra6AYrqw3dFa7o4KWFfWRBC9CgdBchxQfKU7 +ePNyPD/+ivBKuNyRkujEbveZl/5DAkM8RuwSHPv58t42VUENH0xS2o9J9/Ji0BDL +xg4+EPADl0CZA7X0n47KtoiJRAWMHb5ncucUDi1U/df3sclekojzlZeoJp9dujaS +O5XKFYximElL4oFRoadCp5duFWTfepDvt5djjUEvJyOWlDYQvE7k4G14DPfkM4GD +G/ySPwDEM2A0z1AEaGFpTfKSFJElnBDFk0nSO2BMduLScwYJsufVNq7YAWj9X6Mu +qOfw/9G0lx9aKTCBDIqSWsuQ9ia5eWZ/CG1YsMMeGzwQ6kmwXPuDFLaQMafM3JrL +xtIkLUQaKMFwmgCD9Ty7aIm61iPNZZJKBPXNpHbx5Ck= +</ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> </md:KeyDescriptor> <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vfu.su.se/Shibboleth.sso/Artifact/SOAP" index="1"/> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vfu.su.se/Shibboleth.sso/SLO/SOAP"/> @@ -64,21 +131,18 @@ ZbIlfQJbU+IsF+PBKYkQ9oGeHIBu0E6lRYjrmIFz1n176w== <md:ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vfu.su.se/Shibboleth.sso/NIM/POST"/> <md:ManageNameIDService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vfu.su.se/Shibboleth.sso/NIM/Artifact"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://vfu.su.se/Shibboleth.sso/SAML/POST" index="5"/> - <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://vfu.su.se/Shibboleth.sso/SAML/Artifact" index="6"/> - <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vfu.su.se/Shibboleth.sso/SAML2/POST" index="7"/> - <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://vfu.su.se/Shibboleth.sso/SAML2/POST-SimpleSign" index="8"/> - <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vfu.su.se/Shibboleth.sso/SAML2/Artifact" index="9"/> - <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://vfu.su.se/Shibboleth.sso/SAML2/ECP" index="10"/> - <md:AttributeConsumingService index="1"> - <md:ServiceName xml:lang="en">VFU</md:ServiceName> - <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vfu.su.se/Shibboleth.sso/SAML2/POST" index="6"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vfu.su.se/Shibboleth.sso/SAML2/Artifact" index="7"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://vfu.su.se/Shibboleth.sso/SAML2/ECP" index="8"/> + <md:AttributeConsumingService index="1" isDefault="true"> + <md:ServiceName xml:lang="en">VFU-portalen</md:ServiceName> + <md:RequestedAttribute FriendlyName="email" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> <md:RequestedAttribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> <md:RequestedAttribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> - <md:RequestedAttribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:RequestedAttribute FriendlyName="surName" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> <md:RequestedAttribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> <md:RequestedAttribute FriendlyName="norEduPersonNIN" Name="urn:oid:1.3.6.1.4.1.2428.90.1.5" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> - <md:RequestedAttribute FriendlyName="eduPersonAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> - <md:RequestedAttribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> </md:AttributeConsumingService> </md:SPSSODescriptor> <md:Organization> |