diff options
author | Björn Mattsson <bjorn@sunet.se> | 2022-02-15 16:15:06 +0100 |
---|---|---|
committer | Björn Mattsson <bjorn@sunet.se> | 2022-02-15 16:15:06 +0100 |
commit | 636f73f2259a5b0fb997844d1456d66630df105a (patch) | |
tree | 2e200d7d59c1e885988798a6a2aee17c5af49c34 | |
parent | 95d03f3fc2bb5fb0dbda0490a596cb4936c41ed9 (diff) |
SWAMID-702, Update of idp-shib.slu.se
-rw-r--r-- | swamid-2.0/idp-shib.slu.se-idp.xml | 124 |
1 files changed, 64 insertions, 60 deletions
diff --git a/swamid-2.0/idp-shib.slu.se-idp.xml b/swamid-2.0/idp-shib.slu.se-idp.xml index f066325d..9b96fd71 100644 --- a/swamid-2.0/idp-shib.slu.se-idp.xml +++ b/swamid-2.0/idp-shib.slu.se-idp.xml @@ -4,22 +4,22 @@ <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2020-11-13T10:19:03Z"> <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy> </mdrpi:RegistrationInfo> - <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion"> - <saml:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> - <saml:AttributeValue>http://www.swamid.se/policy/assurance/al1</saml:AttributeValue> - </saml:Attribute> - <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category-support"> - <saml:AttributeValue>http://refeds.org/category/research-and-scholarship</saml:AttributeValue> - <saml:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</saml:AttributeValue> - </saml:Attribute> + <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"> + <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <samla:AttributeValue>http://www.swamid.se/policy/assurance/al1</samla:AttributeValue> + </samla:Attribute> + <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category-support"> + <samla:AttributeValue>http://refeds.org/category/research-and-scholarship</samla:AttributeValue> + <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue> + </samla:Attribute> </mdattr:EntityAttributes> </md:Extensions> - <IDPSSODescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0" errorURL="https://saml-error.slu.se/?errorurl_code=ERRORURL_CODE&errorurl_ts=ERRORURL_TS&errorurl_rp=ERRORURL_RP&errorurl_tid=ERRORURL_TID&errorurl_ctx=ERRORURL_CTX"> - <Extensions> + <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0" errorURL="https://saml-error.slu.se/?errorurl_code=ERRORURL_CODE&errorurl_ts=ERRORURL_TS&errorurl_rp=ERRORURL_RP&errorurl_tid=ERRORURL_TID&errorurl_ctx=ERRORURL_CTX"> + <md:Extensions> <shibmd:Scope regexp="false">slu.se</shibmd:Scope> <mdui:UIInfo> <mdui:DisplayName xml:lang="sv">Sveriges Lantbruksuniversitet</mdui:DisplayName> - <mdui:DisplayName xml:lang="en">Swedish University of Agricultural Science</mdui:DisplayName> + <mdui:DisplayName xml:lang="en">Swedish University of Agricultural Sciences</mdui:DisplayName> <mdui:Description xml:lang="sv">Shibboleth Identity Provider för SLU.</mdui:Description> <mdui:Description xml:lang="en">Shibboleth Identity Provider for SLU.</mdui:Description> <mdui:InformationURL xml:lang="sv">https://idp-shib.slu.se/info/om.html</mdui:InformationURL> @@ -34,9 +34,9 @@ <mdui:DiscoHints> <mdui:DomainHint>slu.se</mdui:DomainHint> </mdui:DiscoHints> - </Extensions> + </md:Extensions> <!-- First signing certificate is BackChannel, the Second is FrontChannel --> - <KeyDescriptor use="signing"> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -66,8 +66,8 @@ wPg6Xtq8Rb1EphE= </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="signing"> + </md:KeyDescriptor> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -97,8 +97,8 @@ UgKStld+SURLHX8= </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="encryption"> + </md:KeyDescriptor> + <md:KeyDescriptor use="encryption"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -128,22 +128,22 @@ ffEVzH+iKOe5hd6R </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp-shib.slu.se:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/> - <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp-shib.slu.se:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp-shib.slu.se/idp/profile/SAML2/POST/SLO"/> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp-shib.slu.se/idp/profile/SAML2/Redirect/SLO"/> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp-shib.slu.se:8443/idp/profile/SAML2/SOAP/SLO"/> - <SingleSignOnService xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" req-attr:supportsRequestedAttributes="true" Location="https://idp-shib.slu.se/idp/profile/SAML2/POST/SSO"/> - <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp-shib.slu.se/idp/profile/Shibboleth/SSO"/> - <SingleSignOnService xmlns:req-attr="urn:oasis:names:tc:SAML:protocol:ext:req-attr" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" req-attr:supportsRequestedAttributes="true" Location="https://idp-shib.slu.se/idp/profile/SAML2/Redirect/SSO"/> - </IDPSSODescriptor> - <AttributeAuthorityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"> - <Extensions> + </md:KeyDescriptor> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp-shib.slu.se:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp-shib.slu.se:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp-shib.slu.se/idp/profile/SAML2/POST/SLO"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp-shib.slu.se/idp/profile/SAML2/Redirect/SLO"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp-shib.slu.se:8443/idp/profile/SAML2/SOAP/SLO"/> + <md:SingleSignOnService xmlns:ns1="urn:oasis:names:tc:SAML:protocol:ext:req-attr" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" ns1:supportsRequestedAttributes="true" Location="https://idp-shib.slu.se/idp/profile/SAML2/POST/SSO"/> + <md:SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp-shib.slu.se/idp/profile/Shibboleth/SSO"/> + <md:SingleSignOnService xmlns:ns1="urn:oasis:names:tc:SAML:protocol:ext:req-attr" Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" ns1:supportsRequestedAttributes="true" Location="https://idp-shib.slu.se/idp/profile/SAML2/Redirect/SSO"/> + </md:IDPSSODescriptor> + <md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"> + <md:Extensions> <shibmd:Scope regexp="false">slu.se</shibmd:Scope> - </Extensions> + </md:Extensions> <!-- First signing certificate is BackChannel, the Second is FrontChannel --> - <KeyDescriptor use="signing"> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -173,8 +173,8 @@ wPg6Xtq8Rb1EphE= </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="signing"> + </md:KeyDescriptor> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -204,8 +204,8 @@ UgKStld+SURLHX8= </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="encryption"> + </md:KeyDescriptor> + <md:KeyDescriptor use="encryption"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -235,29 +235,33 @@ ffEVzH+iKOe5hd6R </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp-shib.slu.se:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> - <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp-shib.slu.se:8443/idp/profile/SAML1/SOAP/AttributeQuery"/> - </AttributeAuthorityDescriptor> - <Organization xmlns="urn:oasis:names:tc:SAML:2.0:metadata"> - <OrganizationName xml:lang="sv">Sveriges Lantbruksuniversitet</OrganizationName> - <OrganizationName xml:lang="en">Swedish University of Agricultural Science</OrganizationName> - <OrganizationDisplayName xml:lang="sv">SLU</OrganizationDisplayName> - <OrganizationDisplayName xml:lang="en">SLU</OrganizationDisplayName> - <OrganizationURL xml:lang="sv">https://www.slu.se</OrganizationURL> - <OrganizationURL xml:lang="en">https://www.slu.se/en</OrganizationURL> - </Organization> - <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="technical"> - <GivenName>IT Help Desk</GivenName> - <EmailAddress>mailto:IT-stod@slu.se</EmailAddress> - </ContactPerson> - <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="administrative"> - <GivenName>IT Help Desk</GivenName> - <EmailAddress>mailto:IT-stod@slu.se</EmailAddress> - </ContactPerson> - <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="support"> - <GivenName>IT Help Desk</GivenName> - <EmailAddress>mailto:IT-stod@slu.se</EmailAddress> - <TelephoneNumber>+46 18 67 66 00</TelephoneNumber> - </ContactPerson> + </md:KeyDescriptor> + <md:AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp-shib.slu.se:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> + <md:AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp-shib.slu.se:8443/idp/profile/SAML1/SOAP/AttributeQuery"/> + </md:AttributeAuthorityDescriptor> + <md:Organization> + <md:OrganizationName xml:lang="sv">Sveriges Lantbruksuniversitet</md:OrganizationName> + <md:OrganizationName xml:lang="en">Swedish University of Agricultural Sciences</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="sv">SLU</md:OrganizationDisplayName> + <md:OrganizationDisplayName xml:lang="en">SLU</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="sv">https://www.slu.se</md:OrganizationURL> + <md:OrganizationURL xml:lang="en">https://www.slu.se/en</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="technical"> + <md:GivenName>IT Help Desk</md:GivenName> + <md:EmailAddress>mailto:support@slu.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="administrative"> + <md:GivenName>IT Help Desk</md:GivenName> + <md:EmailAddress>mailto:support@slu.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="support"> + <md:GivenName>IT Help Desk</md:GivenName> + <md:EmailAddress>mailto:support@slu.se</md:EmailAddress> + <md:TelephoneNumber>+46 18 67 66 00</md:TelephoneNumber> + </md:ContactPerson> + <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security"> + <md:GivenName>IT Help Desk</md:GivenName> + <md:EmailAddress>mailto:support@slu.se</md:EmailAddress> + </md:ContactPerson> </md:EntityDescriptor> |