summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBjörn Mattsson <bjorn@sunet.se>2022-06-02 16:33:01 +0200
committerBjörn Mattsson <bjorn@sunet.se>2022-06-02 16:33:01 +0200
commit81527a4f802594a46e6d3b4b30cd702bbba4f285 (patch)
treef223fc2ff0b7557243a94728a385b5d79b6a76ba
parent53ae6e997754e91e9b870a0857fbb8251cf6ca97 (diff)
SWAMID-1003 Updated aktivera-test.su.se
-rw-r--r--swamid-2.0/aktivera-test.su.se-Shibboleth.sso.xml (renamed from swamid-2.0/aktivera-test.su.se-shibboleth.sso.xml)120
-rw-r--r--swamid-sp-2.0.mxml2
2 files changed, 86 insertions, 36 deletions
diff --git a/swamid-2.0/aktivera-test.su.se-shibboleth.sso.xml b/swamid-2.0/aktivera-test.su.se-Shibboleth.sso.xml
index 45e8de35..f23a674c 100644
--- a/swamid-2.0/aktivera-test.su.se-shibboleth.sso.xml
+++ b/swamid-2.0/aktivera-test.su.se-Shibboleth.sso.xml
@@ -1,55 +1,96 @@
<?xml version="1.0" encoding="UTF-8"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://aktivera-test.su.se/Shibboleth.sso">
<md:Extensions>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
<mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2013-12-05T13:37:25Z">
<mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
<mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
- <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category">
+ <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
</samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
<md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
- <DiscoveryResponse xmlns="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://aktivera-test.su.se/Shibboleth.sso/WAYF" index="1"/>
- <DiscoveryResponse xmlns="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://aktivera-test.su.se/Shibboleth.sso/WAYF/wavelan" index="2"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://aktivera-test.su.se/Shibboleth.sso/WAYF/antagning.se"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://aktivera-test.su.se/Shibboleth.sso/WAYF/eduid.se"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://aktivera-test.su.se/Shibboleth.sso/WAYF"/>
+ <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://aktivera-test.su.se/Shibboleth.sso/WAYF" index="1"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://aktivera-test.su.se/Shibboleth.sso/WAYF/wavelan"/>
+ <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://aktivera-test.su.se/Shibboleth.sso/WAYF/wavelan" index="2"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://aktivera-test.su.se/Shibboleth.sso/WAYF/idp.it.su.se"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://aktivera-test.su.se/Shibboleth.sso/SWAMID"/>
+ <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://aktivera-test.su.se/Shibboleth.sso/SWAMID" index="3"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://aktivera-test.su.se/Shibboleth.sso/WAYF/otc-idp.it.su.se"/>
<mdui:UIInfo>
- <mdui:DisplayName xml:lang="sv">Aktivera-test.su.se</mdui:DisplayName>
- <mdui:DisplayName xml:lang="en">Aktivera-test.su.se</mdui:DisplayName>
- <mdui:Description xml:lang="sv">Kontoaktivering (test) vid Stockholms universitet</mdui:Description>
<mdui:Description xml:lang="en">Activate account (test) at Stockholm University</mdui:Description>
- <mdui:PrivacyStatementURL xml:lang="sv">https://www.su.se/behandling-av-personuppgifter-vid-aktivera-1.582741</mdui:PrivacyStatementURL>
+ <mdui:Description xml:lang="sv">Kontoaktivering (test) vid Stockholms universitet</mdui:Description>
+ <mdui:DisplayName xml:lang="en">Aktivera-test.su.se</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="sv">Aktivera-test.su.se</mdui:DisplayName>
<mdui:PrivacyStatementURL xml:lang="en">https://www.su.se/behandling-av-personuppgifter-vid-aktivera-1.582741</mdui:PrivacyStatementURL>
+ <mdui:PrivacyStatementURL xml:lang="sv">https://www.su.se/behandling-av-personuppgifter-vid-aktivera-1.582741</mdui:PrivacyStatementURL>
+ <mdui:InformationURL xml:lang="en">https://www.su.se/english/education/a-smooth-start/get-access-to-it-services-your-university-account-and-order-a-university-card</mdui:InformationURL>
+ <mdui:InformationURL xml:lang="sv">https://www.su.se/utbildning/en-lyckad-start/aktivera-ditt-universitetskonto</mdui:InformationURL>
</mdui:UIInfo>
</md:Extensions>
- <md:KeyDescriptor use="signing">
+ <md:KeyDescriptor>
<ds:KeyInfo>
- <ds:KeyName>signuptool-test-app1</ds:KeyName>
+ <ds:KeyName>signuptool-test-app01.it.su.se</ds:KeyName>
<ds:X509Data>
- <ds:X509SubjectName>CN=signuptool-test-app1</ds:X509SubjectName>
- <ds:X509Certificate>MIIDAzCCAeugAwIBAgIJAK5pPeHRZOXtMA0GCSqGSIb3DQEBBQUAMB8xHTAbBgNV
-BAMTFHNpZ251cHRvb2wtdGVzdC1hcHAxMB4XDTExMDIyMTE1MjYxNloXDTIxMDIx
-ODE1MjYxNlowHzEdMBsGA1UEAxMUc2lnbnVwdG9vbC10ZXN0LWFwcDEwggEiMA0G
-CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDY+owzEC+S0BF0nCbN13lR0CHlp7mg
-/7YhK3ESVboh9kUtM4/awXRjvJFMfcuFbaJV2DXCX85hFvBIw0D4u6bjNNPye9oS
-VPAFenaFnHAE75O5C3FYnuB5X3P9HDdBoc5m21CDwLmGek7KwPTxpJtqevNUAO2C
-/EEtdk1xe+2T4+fikdRMP9uvf6xz7/WgGzm1V/olbV3tgph7ye4KEB2F6Z/hsyyn
-JaekNZD3oKOk3DsXfxHKRhD/nUjqXoGoUwkD4HLT1fKdP5VYb+T/SzdxLSaoUoJJ
-fVv2Xs/wlD3Vx3zvV5l3x8EJ4paySeh4RdNsUAylbshYUXN9frk5g/WzAgMBAAGj
-QjBAMB8GA1UdEQQYMBaCFHNpZ251cHRvb2wtdGVzdC1hcHAxMB0GA1UdDgQWBBSt
-cBtmU+scg9g8iK1x07dqKTh+QDANBgkqhkiG9w0BAQUFAAOCAQEAw0NLLpKeYIhn
-rL0edePtkGr3sFNmOyg8k9qkPxgwrozjLg/+AkssNft+rs7nZp87IIhZUiNZxr7w
-qnRPJXoxq56IfsbZpQwAH0QIRc9gl5BjzvdqByGH76Z5dDPFUaTrxnd7XdWybOiZ
-bX4d2LgWklI0aTw7xQEjw0qX/nWW0guZRC/nJfgiHjV7xEJLcoxcyn0+dqo1+XkU
-y60nYKhdp2qnCnRCR8by5ykruSaDJ4c/OCsGh9WIE6HvpDunTTzisfqrdZ22LTLR
-vaJm+7MsfXQvQZz6YUW2MGSYOa6G9v2dS4Dz9v/9JQjn6bBqqSouw3spYPDAbzGp
-u/S7d9rEGQ==
+ <ds:X509SubjectName>CN=signuptool-test-app01.it.su.se</ds:X509SubjectName>
+ <ds:X509Certificate>MIIEITCCAomgAwIBAgIJAPPDAE8MhEE9MA0GCSqGSIb3DQEBCwUAMCkxJzAlBgNV
+BAMTHnNpZ251cHRvb2wtdGVzdC1hcHAwMS5pdC5zdS5zZTAeFw0yMjA1MzAxMjAz
+MjFaFw0zMjA1MjcxMjAzMjFaMCkxJzAlBgNVBAMTHnNpZ251cHRvb2wtdGVzdC1h
+cHAwMS5pdC5zdS5zZTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBALLW
+9v2g8HWwakb8dpjyhtYG19AfQpU/l91r4nPPevzBA6UD/ce5vcOF/ulZlOjQYka1
+Hk8g9rFbiZkUDnA2ItsQpvovnbdaBI9BbdoK43o0oOV4zUmcHzerkx7gi0rw/ePb
+CCetXD+fwz+A7OeUUPDrGOi2uQ5/2zViELC9nzGRB2VnKhhoLIdmOTE+iuVta7Kx
+08I5ekl3Q6Oe80BwpJzFubvjnC7peQzna76q8dtiTsXcGhaFJyRXPVUFNxtaFBT8
+N2CinCI5Nn55kYZaZ7KRsQr2JNi/Llb0kWS17Xj6UMZcG7Jku0P0Gzn7lmQFGomv
+lyKLrDQOMqJL/UwbZlfIMrBklY3+z8imc9al5zUtqiH8ZVMvWoC+kMF8iP6gWIjh
+iDwXmOyFE49etFvleS+SuHostqORk83Qm8LmL5HF/E4WfKGoiDyXIRhreXnUAS+F
+BTEoed+Gi2z0fkM4TYuB1VdtUzW0fliadEg0S7nx79ndGs1sRJ2pf/bskOqAnQID
+AQABo0wwSjApBgNVHREEIjAggh5zaWdudXB0b29sLXRlc3QtYXBwMDEuaXQuc3Uu
+c2UwHQYDVR0OBBYEFIm1WkPQgL9W2OLlMrH4EJCnSzC8MA0GCSqGSIb3DQEBCwUA
+A4IBgQCBhhG/tgEIegkUXMRO3o+t3yqN6RdSlW3lEUO0H5j8rCqntFa6bg/T8SNZ
+8lzrbWcun1BiqKE+IkodUGHXlLVH6eygmoGXrGxviEyYtW8eu7oWln2YcFHYXZk6
+qmsmQE0jlXPUIifuuNvGB2PGjMWw8xoZ4skXlo/nuawGBMiDfo73CqxfYgPw1/IV
+XRKTwXF9pl1+w2KoZvlpB95oa+uwvnKE6Von5iPLO1Ro0DYOsCT8jjhwnG5Ln3x6
+PqC1nGid5zgiJYBpye4dpjsJJEUYrkqS54oBm1BLxgcnI6tIDzNBxJvHgUG6GO6S
+z7PeFNOsl0ep7Yy9wSsxA1A+vLxjaZSq/ppneIfPFiqG/p88m+/E1CLZTP4r/Jfu
+dimScHMt5IrUDoV+uKQS0qQy28+JEUND5W3yoxYY2C8ExYbXiHCyt/kVQ6wkF9sM
+GWkv5dXgR75us8B2QAMz/MH45Y6iC4n/XvV0abB+rqUJJn4CIKQ6ySUnPTkSDBEW
+UOt6LBw=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
</md:KeyDescriptor>
- <md:KeyDescriptor use="encryption">
+ <md:KeyDescriptor use="signing">
<ds:KeyInfo>
<ds:KeyName>signuptool-test-app1</ds:KeyName>
<ds:X509Data>
@@ -87,23 +128,23 @@ u/S7d9rEGQ==
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://aktivera-test.su.se/Shibboleth.sso/SAML/POST" index="5"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://aktivera-test.su.se/Shibboleth.sso/SAML/Artifact" index="6"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://aktivera-test.su.se/Shibboleth.sso/SAML2/POST" index="7"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://aktivera-test.su.se/Shibboleth.sso/SAML2/POST-SimpleSign" index="8"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://aktivera-test.su.se/Shibboleth.sso/SAML2/Artifact" index="9"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://aktivera-test.su.se/Shibboleth.sso/SAML2/ECP" index="10"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://aktivera-test.su.se/Shibboleth.sso/SAML2/Artifact" index="8"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://aktivera-test.su.se/Shibboleth.sso/SAML2/ECP" index="9"/>
<md:AttributeConsumingService index="1">
- <md:ServiceName xml:lang="sv">Aktivera test</md:ServiceName>
<md:ServiceName xml:lang="en">Aktivera test</md:ServiceName>
+ <md:ServiceName xml:lang="sv">Aktivera test</md:ServiceName>
<md:RequestedAttribute FriendlyName="eduPersonAssurance" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
- <md:RequestedAttribute FriendlyName="norEduPersonNIN" Name="urn:oid:1.3.6.1.4.1.2428.90.1.5" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="norEduPersonNIN" Name="urn:oid:1.3.6.1.4.1.2428.90.1.5" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
</md:AttributeConsumingService>
</md:SPSSODescriptor>
<md:Organization>
<md:OrganizationName xml:lang="sv">SU</md:OrganizationName>
- <md:OrganizationDisplayName xml:lang="sv">Stockholms universitet</md:OrganizationDisplayName>
+ <md:OrganizationName xml:lang="en">SU</md:OrganizationName>
<md:OrganizationDisplayName xml:lang="en">Stockholm University</md:OrganizationDisplayName>
- <md:OrganizationURL xml:lang="sv">https://www.su.se/</md:OrganizationURL>
+ <md:OrganizationDisplayName xml:lang="sv">Stockholms universitet</md:OrganizationDisplayName>
<md:OrganizationURL xml:lang="en">https://www.su.se/</md:OrganizationURL>
+ <md:OrganizationURL xml:lang="sv">https://www.su.se/</md:OrganizationURL>
</md:Organization>
<md:ContactPerson contactType="administrative">
<md:SurName>IT-avdelningen</md:SurName>
@@ -113,4 +154,13 @@ u/S7d9rEGQ==
<md:SurName>IT-avdelningen</md:SurName>
<md:EmailAddress>mailto:helpdesk@su.se</md:EmailAddress>
</md:ContactPerson>
+ <md:ContactPerson contactType="support">
+ <md:SurName>IT-avdelningen</md:SurName>
+ <md:EmailAddress>mailto:helpdesk@su.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
+ <md:GivenName>IT</md:GivenName>
+ <md:SurName>avdelningen</md:SurName>
+ <md:EmailAddress>mailto:helpdesk@su.se</md:EmailAddress>
+ </md:ContactPerson>
</md:EntityDescriptor>
diff --git a/swamid-sp-2.0.mxml b/swamid-sp-2.0.mxml
index 50d9e444..584bb844 100644
--- a/swamid-sp-2.0.mxml
+++ b/swamid-sp-2.0.mxml
@@ -46,7 +46,7 @@
<xi:include href="swamid-2.0/se.timeedit.net-umu-student-sp.xml"/>
<xi:include href="swamid-2.0/shib1.oru.se-shibboleth.xml"/>
<xi:include href="swamid-2.0/sp.it.gu.se-shibboleth.xml"/>
- <xi:include href="swamid-2.0/aktivera-test.su.se-shibboleth.sso.xml"/>
+ <xi:include href="swamid-2.0/aktivera-test.su.se-Shibboleth.sso.xml"/>
<xi:include href="swamid-2.0/aktivera.su.se-shibboleth.sso.xml"/>
<xi:include href="swamid-2.0/account.mdh.se-shibboleth.xml"/>
<xi:include href="swamid-2.0/dedserv79.levonline.com-shibboleth.xml"/>