diff options
author | Björn Mattsson <bjorn@sunet.se> | 2021-12-15 11:31:21 +0100 |
---|---|---|
committer | Björn Mattsson <bjorn@sunet.se> | 2021-12-15 11:31:21 +0100 |
commit | 8a8b9fb3263e6f32e15012758df6ab08eed4c261 (patch) | |
tree | 7ddeb4cfdac6b203d4b7ef98d9e2e3d0579fb605 | |
parent | 38631397f1fc6e8faf149a579e4e68b3cb3ed45b (diff) |
SWAMID-564, Added 3 SP:s for sunet.se
-rw-r--r-- | swamid-2.0/kth-ni.cnaas.sunet.se.xml | 112 | ||||
-rw-r--r-- | swamid-2.0/mdh-ni.cnaas.sunet.se.xml | 112 | ||||
-rw-r--r-- | swamid-2.0/su-ni.cnaas.sunet.se.xml | 112 | ||||
-rw-r--r-- | swamid-sp-2.0.mxml | 3 |
4 files changed, 339 insertions, 0 deletions
diff --git a/swamid-2.0/kth-ni.cnaas.sunet.se.xml b/swamid-2.0/kth-ni.cnaas.sunet.se.xml new file mode 100644 index 00000000..6c63aea6 --- /dev/null +++ b/swamid-2.0/kth-ni.cnaas.sunet.se.xml @@ -0,0 +1,112 @@ +<?xml version="1.0" encoding="UTF-8"?> +<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://kth-ni.cnaas.sunet.se"> + <md:Extensions> + <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2021-12-15T11:27:53Z"> + <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy> + </mdrpi:RegistrationInfo> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/> + <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"> + <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue> + </samla:Attribute> + </mdattr:EntityAttributes> + </md:Extensions> + <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> + <md:Extensions> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://kth-ni.cnaas.sunet.se/Shibboleth.sso/DS/Login"/> + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://kth-ni.cnaas.sunet.se/Shibboleth.sso/DS/Login" index="1"/> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="sv">CnaaS KTH NI</mdui:DisplayName> + <mdui:DisplayName xml:lang="en">CnaaS KTH NI</mdui:DisplayName> + <mdui:Description xml:lang="sv">Inventariesystem för CnaaS på KTH.</mdui:Description> + <mdui:Description xml:lang="en">Inventory system for CnaaS at KTH.</mdui:Description> + <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/x/jYmvBg</mdui:PrivacyStatementURL> + <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/x/jYmvBg</mdui:PrivacyStatementURL> + </mdui:UIInfo> + </md:Extensions> + <md:KeyDescriptor> + <ds:KeyInfo> + <ds:KeyName>https://kth-ni.cnaas.sunet.se</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=https://kth-ni.cnaas.sunet.se</ds:X509SubjectName> + <ds:X509Certificate>MIIEKTCCApGgAwIBAgIUVbeWQb2aGO+wYRw64Gk+HVpBjM4wDQYJKoZIhvcNAQEL +BQAwKDEmMCQGA1UEAxMdaHR0cHM6Ly9rdGgtbmkuY25hYXMuc3VuZXQuc2UwHhcN +MjExMjE1MDg1OTE4WhcNMzExMjEzMDg1OTE4WjAoMSYwJAYDVQQDEx1odHRwczov +L2t0aC1uaS5jbmFhcy5zdW5ldC5zZTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCC +AYoCggGBALBxyu1NeLRXiHf8hIHZtPlyQk7Dt5sSDcgKTbdrtnghqoLKSG28z6hl +l6+6spIeCOZfpPdh6OfiELRUkKc7tXP5PfsLJQkoqhOHm3Q2ecZwGthwbQtV7xfE +J/7NDKRXTj4OoN3EU5Om2nNFszdvJtfD1M6D+scXuN6QcRDWesZpVIto56tXhSx6 +SDGC1gdffPL8XZwTpmX744/JN6ul6z8TO5BU2f5+RiqcSSkkMSEVPXBypbiyI2Ot ++ojOUBCfSkrYMitBBoj3DPf9f136JmVRawZi/A3hzOEB6b33dE7+/rOfmqWjZFiG +VQoX1p0j4X2zHGFbd3OePikizeBcghVGoOuSOPz6hGjmGHw7gmogwNq6I5bKQHEW ++L+D2QlICw2ypVApVERVnb6BxuMgTbdb8lrX5vvb0DtnoGrz6tULbd+oDfrY3gGV +5G586tIKBJ3BIKdokHb1ZwoY12LZlFM7XUv5VyDO27K8MwXB699Rpo+ZQayH23wk +UKO8ZxYtiQIDAQABo0swSTAoBgNVHREEITAfgh1odHRwczovL2t0aC1uaS5jbmFh +cy5zdW5ldC5zZTAdBgNVHQ4EFgQU72kxfDfKySu5jE3b0bqj1tg+R5cwDQYJKoZI +hvcNAQELBQADggGBAF+xRpuyjdgZ/qjybMXVA0Mg7an87EkgrQIfxCM9xgZ6M1M9 +3o1JXCO6IwFx4nEhyrZocg9PuZ4mlpoueQPFBJWLgxFA1tY3IWb/hTfZSNO1zyjr +s9M9WLGXw2hb0WLpwVXXfObVmpgRD+v2co2RkQ24mMaZczOSWDNs7K7Bn7dVTxXR +UxIT+cKlE+7cDQqoUApDiw/90YzT8grtrYv0nqXGs7VeIXHuL7XbLE1skw4smR+Z +vk7m2RV0iu9bPcucjH2xvskBDAxHMWDsVEWKO089nlSymrINN0u20xysAT18JDsC +Bs/5omtibp1xtw7toartV21911esFtXd8qHoWjr2Rb3cS7Mb1AbCIIpQ4P6tgeKS +ZIJ9xVO4IWOhdNxsmZHVeUKoE/C0bRngvFO+SkwOv8FJB6R1WzFMp/GcmashYS5S +5Fg6lFpKqhN0K/JAtoPXlHywrZC6s6v0DYAh8TyIkSd62VNXvbBYt+XAFAEwc3Be +/HAwqzru853o4EvyUQ== +</ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> + </md:KeyDescriptor> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://kth-ni.cnaas.sunet.se/Shibboleth.sso/Artifact/SOAP" index="1"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://kth-ni.cnaas.sunet.se/Shibboleth.sso/SLO/SOAP"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://kth-ni.cnaas.sunet.se/Shibboleth.sso/SLO/Redirect"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://kth-ni.cnaas.sunet.se/Shibboleth.sso/SLO/POST"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://kth-ni.cnaas.sunet.se/Shibboleth.sso/SLO/Artifact"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://kth-ni.cnaas.sunet.se/Shibboleth.sso/SAML2/POST" index="1"/> + <md:AttributeConsumingService index="1"> + <md:ServiceName xml:lang="sv">CnaaS KTH NI</md:ServiceName> + <md:ServiceName xml:lang="en">CnaaS KTH NI</md:ServiceName> + <md:RequestedAttribute FriendlyName="eduPersonAssurance" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + </md:AttributeConsumingService> + </md:SPSSODescriptor> + <md:Organization> + <md:OrganizationName xml:lang="sv">Sunet</md:OrganizationName> + <md:OrganizationName xml:lang="en">Sunet</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="sv">Sunet</md:OrganizationDisplayName> + <md:OrganizationDisplayName xml:lang="en">Sunet</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL> + <md:OrganizationURL xml:lang="en">https://www.sunet.se</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="technical"> + <md:SurName>Sunet NOC</md:SurName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="administrative"> + <md:SurName>Ernst Widerberg</md:SurName> + <md:EmailAddress>mailto:ernst@sunet.se</md:EmailAddress> + </md:ContactPerson> +</md:EntityDescriptor> diff --git a/swamid-2.0/mdh-ni.cnaas.sunet.se.xml b/swamid-2.0/mdh-ni.cnaas.sunet.se.xml new file mode 100644 index 00000000..87d885fb --- /dev/null +++ b/swamid-2.0/mdh-ni.cnaas.sunet.se.xml @@ -0,0 +1,112 @@ +<?xml version="1.0" encoding="UTF-8"?> +<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://mdh-ni.cnaas.sunet.se"> + <md:Extensions> + <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2021-12-15T11:27:53Z"> + <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy> + </mdrpi:RegistrationInfo> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/> + <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"> + <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue> + </samla:Attribute> + </mdattr:EntityAttributes> + </md:Extensions> + <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> + <md:Extensions> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://mdh-ni.cnaas.sunet.se/Shibboleth.sso/DS/Login"/> + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://mdh-ni.cnaas.sunet.se/Shibboleth.sso/DS/Login" index="1"/> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="sv">CnaaS MDH NI</mdui:DisplayName> + <mdui:DisplayName xml:lang="en">CnaaS MDH NI</mdui:DisplayName> + <mdui:Description xml:lang="sv">Inventariesystem för CnaaS på MDH.</mdui:Description> + <mdui:Description xml:lang="en">Inventory system for CnaaS at MDH.</mdui:Description> + <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/x/jYmvBg</mdui:PrivacyStatementURL> + <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/x/jYmvBg</mdui:PrivacyStatementURL> + </mdui:UIInfo> + </md:Extensions> + <md:KeyDescriptor> + <ds:KeyInfo> + <ds:KeyName>https://mdh-ni.cnaas.sunet.se</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=https://mdh-ni.cnaas.sunet.se</ds:X509SubjectName> + <ds:X509Certificate>MIIEKTCCApGgAwIBAgIUR9eg+yPjcjfPMBsPAf86AcCOSIQwDQYJKoZIhvcNAQEL +BQAwKDEmMCQGA1UEAxMdaHR0cHM6Ly9tZGgtbmkuY25hYXMuc3VuZXQuc2UwHhcN +MjExMjE1MDg1OTU3WhcNMzExMjEzMDg1OTU3WjAoMSYwJAYDVQQDEx1odHRwczov +L21kaC1uaS5jbmFhcy5zdW5ldC5zZTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCC +AYoCggGBAN6M3RSGAemhATawNGEGvy9Da7iC0BDuTdU3EwJvORD8Pg4hsL5Xjgdv +Kx2HUFI3w+Zp/TEu3ZmUnLP3D+4p7P/TBFtDl0cwm8rjbM0V8IkaUKORt01GHzHq +JVemtl4c0x1UyNLR6MWnmuyIPnrySdr1fDERqQ9eS/Wf3FLMf1FX4OqSLcn+7Cuh +dMjD9pxedxQCAsj7wd0Hfo9Ir2ZssCPGFWQ2GpkXxxm3kR1fgQczAVbO0C6f8x85 +Xhvdy8RNyNglj4+WMtNr7EE9n6KkMNZtKZ8yonsCWamPgkPW/9AYqBX8GkmZ2APA +Zw1cDbDG/UUgBAryVGhg4kQIXln11kRhGhjfVNqnEw4QkerEYKcjUtteExNP8Y7N +Is+GPG6FfNjD8KrJapRh203WV+bhFIlnmQnkr4hqfkK4K0fFIVREum0gpnm0hhuP +P+rGhfQvcbrocit4hKLBlptPSqJQNRF2VORuZ3dop+PAjzu7ax5kTwbyHjQPX8jD +C/qGJIoAeQIDAQABo0swSTAoBgNVHREEITAfgh1odHRwczovL21kaC1uaS5jbmFh +cy5zdW5ldC5zZTAdBgNVHQ4EFgQUrOfRBlRHz9K3Cvvd/oOFUuO3mogwDQYJKoZI +hvcNAQELBQADggGBAMXuWUUBlYKEZrN+aZWlMJn6zh3dIvM+BZnjHZnWJoI1DoK/ +qXaOpTN5F4GJB6kJI6rbUpiwwhUWrdjLLUI4WpRxvWrJhEbUyiZ7LvabufdWGJkl +tE95NJxZYg1gWp13UhS8RnWiWSUIGH03PhXE3/oNANinNjO2qO5HSjA/CcJKF/4g +kg63aWgFhyJxvPbiehWRuiq0X0EibSoQfSRQ68xCC9CLPjdGIv7RgVMvYQOjsYzj +F12mJG+KjZTkpT9/IMqOViYePAWs7vi0kUNb3I8eju9Ly3fH/WEalqKnpzKNBnfN +ZuQHxG8s6CZC8jAvTWe6nEMzZrzpGRCpiAcd/IylhK//ZviVHvRaOLscZeaRDfwM ++om99Jz2kAWA1ucXrkAzh3gNyrWno2cBAOpudyfEKBSHv1I0vD+oyNgxE7wzHTyg +xzRwO7/3p5y/WBL4SoNEEXl1lRfBePgHfTY37go3JOs4zclgtHBd6Y7KFhOeYXyH +9q5LfkAfbJRwMWqqmg== +</ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> + </md:KeyDescriptor> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://mdh-ni.cnaas.sunet.se/Shibboleth.sso/Artifact/SOAP" index="1"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://mdh-ni.cnaas.sunet.se/Shibboleth.sso/SLO/SOAP"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://mdh-ni.cnaas.sunet.se/Shibboleth.sso/SLO/Redirect"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://mdh-ni.cnaas.sunet.se/Shibboleth.sso/SLO/POST"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://mdh-ni.cnaas.sunet.se/Shibboleth.sso/SLO/Artifact"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://mdh-ni.cnaas.sunet.se/Shibboleth.sso/SAML2/POST" index="1"/> + <md:AttributeConsumingService index="1"> + <md:ServiceName xml:lang="sv">CnaaS MDH NI</md:ServiceName> + <md:ServiceName xml:lang="en">CnaaS MDH NI</md:ServiceName> + <md:RequestedAttribute FriendlyName="eduPersonAssurance" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + </md:AttributeConsumingService> + </md:SPSSODescriptor> + <md:Organization> + <md:OrganizationName xml:lang="sv">Sunet</md:OrganizationName> + <md:OrganizationName xml:lang="en">Sunet</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="sv">Sunet</md:OrganizationDisplayName> + <md:OrganizationDisplayName xml:lang="en">Sunet</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL> + <md:OrganizationURL xml:lang="en">https://www.sunet.se</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="technical"> + <md:SurName>Sunet NOC</md:SurName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="administrative"> + <md:SurName>Ernst Widerberg</md:SurName> + <md:EmailAddress>mailto:ernst@sunet.se</md:EmailAddress> + </md:ContactPerson> +</md:EntityDescriptor> diff --git a/swamid-2.0/su-ni.cnaas.sunet.se.xml b/swamid-2.0/su-ni.cnaas.sunet.se.xml new file mode 100644 index 00000000..808952c2 --- /dev/null +++ b/swamid-2.0/su-ni.cnaas.sunet.se.xml @@ -0,0 +1,112 @@ +<?xml version="1.0" encoding="UTF-8"?> +<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://su-ni.cnaas.sunet.se"> + <md:Extensions> + <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2021-12-15T11:27:53Z"> + <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy> + </mdrpi:RegistrationInfo> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/> + <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"> + <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue> + </samla:Attribute> + </mdattr:EntityAttributes> + </md:Extensions> + <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> + <md:Extensions> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://su-ni.cnaas.sunet.se/Shibboleth.sso/DS/Login"/> + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://su-ni.cnaas.sunet.se/Shibboleth.sso/DS/Login" index="1"/> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="sv">CnaaS SU NI</mdui:DisplayName> + <mdui:DisplayName xml:lang="en">CnaaS SU NI</mdui:DisplayName> + <mdui:Description xml:lang="sv">Inventariesystem för CnaaS på SU.</mdui:Description> + <mdui:Description xml:lang="en">Inventory system for CnaaS at SU.</mdui:Description> + <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/x/jYmvBg</mdui:PrivacyStatementURL> + <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/x/jYmvBg</mdui:PrivacyStatementURL> + </mdui:UIInfo> + </md:Extensions> + <md:KeyDescriptor> + <ds:KeyInfo> + <ds:KeyName>https://su-ni.cnaas.sunet.se</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=https://su-ni.cnaas.sunet.se</ds:X509SubjectName> + <ds:X509Certificate>MIIEJjCCAo6gAwIBAgIUQ26g66/p8SbJeizIprvwI8ky/7QwDQYJKoZIhvcNAQEL +BQAwJzElMCMGA1UEAxMcaHR0cHM6Ly9zdS1uaS5jbmFhcy5zdW5ldC5zZTAeFw0y +MTEyMTUwODU5NDJaFw0zMTEyMTMwODU5NDJaMCcxJTAjBgNVBAMTHGh0dHBzOi8v +c3UtbmkuY25hYXMuc3VuZXQuc2UwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGK +AoIBgQDSG7oEWe2H7GX+1W/4aEFhL+SGtjqvNidHozH8vR0Bbo7RYVKElYs2B+FQ +8ih/ihCFuZAlNmzM3kMT7tiMxPsVW7ofhPgS56yLMsoHrS7WodCta8/ng/z+ZUQj +VW/GEm2qahqCHtfnU4s+psexo9cgxdXUUBzxpB0wQFlHMDJf2plbvquHjs4Oodq4 +johJaH4UA68KqgvZ4bBOEUhj22wmBYrPf2ReZJjxwyDHSP1G7DyOxoauEOV5Apv0 +vcNA7T75u+Mr9m41Yt3MjCZRPdrekWRqMzlxUXodZlhXzVko0VYtFgqV/fT+4T0W +ZdOsY6lCGFoUa4vxsWkpRjWjnkGFmxM4wq0ucjed01OawR9HgFexaSgfL2r/03R1 +wWQkESUQ/96yhn3ueLPDi+wPce7++EKZwFzUVGj4FPQq+G5wKBMymXIj/k5VR15i +pE2qK5fwlnMhGFiq9q5rTBXRtVa93xfJ1wFhGF+IQ7x063BlXy2RjJE0FTf/D8ni +/Jq76FECAwEAAaNKMEgwJwYDVR0RBCAwHoIcaHR0cHM6Ly9zdS1uaS5jbmFhcy5z +dW5ldC5zZTAdBgNVHQ4EFgQUIX4BCuQxjRvVQMEDD/KiJqMz/BMwDQYJKoZIhvcN +AQELBQADggGBAF3Avp4tM5Yb8NgIW/viNTkHW64kmYJDLf4frJk9Sys63S+pZPq0 +fWXOE4zLwBtBxrSFoTPDWc0rrhSjBe9p30FvtSPQ8fvKzvdnASTWWRr5xDitNREL +FYbGA9gOKWj5i1Kn2N1NHSGxFly6uLL6tenm5JLtQzEu+yaM66NTcTdKHtY0BOLw +snUUXvoNZmTIna6TuPm/UHNCenIQIbfR9xmH2sfMLwFYF0rXYxzMbJ5J8700h1TZ +N/CtsCaflW9ZSS+wWEBSMCjOHgaOLizPs5JIPFaUJcZi25uTS597Y9HBn7TgcZbC +/qua207vc47JRBwy8pRT2c0odjXZOHG2mdhlpB3Z09keTvF7PtoGQvXtF8Sh8+t0 +deJtq65msFY0gWbvk8vRt5N8RPDu1qfM8xRcX/wdC+pLJ1bAyZwz+iKDUiLiTM/0 +t/MHG7X2QW9kvmO+IaK52SWkkbLK+a554hifBtQq39DmTXctv65uCSPzE2EfRYU3 +/QWzFvXkB8TcvA== +</ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> + </md:KeyDescriptor> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://su-ni.cnaas.sunet.se/Shibboleth.sso/Artifact/SOAP" index="1"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://su-ni.cnaas.sunet.se/Shibboleth.sso/SLO/SOAP"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://su-ni.cnaas.sunet.se/Shibboleth.sso/SLO/Redirect"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://su-ni.cnaas.sunet.se/Shibboleth.sso/SLO/POST"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://su-ni.cnaas.sunet.se/Shibboleth.sso/SLO/Artifact"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://su-ni.cnaas.sunet.se/Shibboleth.sso/SAML2/POST" index="1"/> + <md:AttributeConsumingService index="1"> + <md:ServiceName xml:lang="sv">CnaaS SU NI</md:ServiceName> + <md:ServiceName xml:lang="en">CnaaS SU NI</md:ServiceName> + <md:RequestedAttribute FriendlyName="eduPersonAssurance" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + </md:AttributeConsumingService> + </md:SPSSODescriptor> + <md:Organization> + <md:OrganizationName xml:lang="sv">Sunet</md:OrganizationName> + <md:OrganizationName xml:lang="en">Sunet</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="sv">Sunet</md:OrganizationDisplayName> + <md:OrganizationDisplayName xml:lang="en">Sunet</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL> + <md:OrganizationURL xml:lang="en">https://www.sunet.se</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="technical"> + <md:SurName>Sunet NOC</md:SurName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="administrative"> + <md:SurName>Ernst Widerberg</md:SurName> + <md:EmailAddress>mailto:ernst@sunet.se</md:EmailAddress> + </md:ContactPerson> +</md:EntityDescriptor> diff --git a/swamid-sp-2.0.mxml b/swamid-sp-2.0.mxml index bcc9a620..a388f706 100644 --- a/swamid-sp-2.0.mxml +++ b/swamid-sp-2.0.mxml @@ -710,4 +710,7 @@ <xi:include href="swamid-2.0/test.play.gu.se.xml"/> <xi:include href="swamid-2.0/play.his.se.xml"/> <xi:include href="swamid-2.0/se-kau-shibboleth.moveon4.de-shibboleth.xml"/> + <xi:include href="swamid-2.0/kth-ni.cnaas.sunet.se.xml"/> + <xi:include href="swamid-2.0/mdh-ni.cnaas.sunet.se.xml"/> + <xi:include href="swamid-2.0/su-ni.cnaas.sunet.se.xml"/> </md:EntitiesDescriptor> |