summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBjörn Mattsson <bjorn@sunet.se>2022-04-11 16:20:26 +0200
committerBjörn Mattsson <bjorn@sunet.se>2022-04-11 16:20:26 +0200
commit3581d08908843ca83073dbf1c6a7d34d6bb5d0e7 (patch)
tree5ea9195bc72ef82a3d2c11db7c0e317f24d5187a
parentc3829dd9502e665a3a058edf56d3a4efdff0e2be (diff)
SWAMID-828, SWAMID-829, SWAMID-830 add 3 SP:s for vr-*.cnaas.sunet.se
-rw-r--r--swamid-2.0/vr-graylog.cnaas.sunet.se.xml122
-rw-r--r--swamid-2.0/vr-nav.cnaas.sunet.se.xml122
-rw-r--r--swamid-2.0/vr-ni.cnaas.sunet.se.xml122
-rw-r--r--swamid-sp-2.0.mxml3
4 files changed, 369 insertions, 0 deletions
diff --git a/swamid-2.0/vr-graylog.cnaas.sunet.se.xml b/swamid-2.0/vr-graylog.cnaas.sunet.se.xml
new file mode 100644
index 00000000..9d60095f
--- /dev/null
+++ b/swamid-2.0/vr-graylog.cnaas.sunet.se.xml
@@ -0,0 +1,122 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://vr-graylog.cnaas.sunet.se">
+ <md:Extensions>
+ <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2022-04-11T16:19:27Z">
+ <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
+ </mdrpi:RegistrationInfo>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
+ <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
+ <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
+ </samla:Attribute>
+ </mdattr:EntityAttributes>
+ </md:Extensions>
+ <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
+ <md:Extensions>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/DS/Login"/>
+ <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/DS/Login" index="1"/>
+ <mdui:UIInfo>
+ <mdui:DisplayName xml:lang="sv">CnaaS VR Graylog</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="en">CnaaS VR Graylog</mdui:DisplayName>
+ <mdui:Description xml:lang="sv">Loggsystem för CnaaS på VR.</mdui:Description>
+ <mdui:Description xml:lang="en">Logging system for CnaaS at VR.</mdui:Description>
+ <mdui:InformationURL xml:lang="sv">https://www.graylog.org</mdui:InformationURL>
+ <mdui:InformationURL xml:lang="en">https://www.graylog.org</mdui:InformationURL>
+ <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+Graylog+when+using+federated+login</mdui:PrivacyStatementURL>
+ <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+Graylog+when+using+federated+login</mdui:PrivacyStatementURL>
+ </mdui:UIInfo>
+ </md:Extensions>
+ <md:KeyDescriptor>
+ <ds:KeyInfo>
+ <ds:KeyName>https://vr-graylog.cnaas.sunet.se</ds:KeyName>
+ <ds:X509Data>
+ <ds:X509SubjectName>CN=https://vr-graylog.cnaas.sunet.se</ds:X509SubjectName>
+ <ds:X509Certificate>MIIENTCCAp2gAwIBAgIUc+OWQ/HvMHq60VytGy8LurM8nsAwDQYJKoZIhvcNAQEL
+BQAwLDEqMCgGA1UEAxMhaHR0cHM6Ly92ci1ncmF5bG9nLmNuYWFzLnN1bmV0LnNl
+MB4XDTIyMDQxMTA4Mjc1MFoXDTMyMDQwODA4Mjc1MFowLDEqMCgGA1UEAxMhaHR0
+cHM6Ly92ci1ncmF5bG9nLmNuYWFzLnN1bmV0LnNlMIIBojANBgkqhkiG9w0BAQEF
+AAOCAY8AMIIBigKCAYEAxUQNmSbDLJxjyMNiTXtuuBiJ2ZXiG4e306N3exjRGaft
+Ozu3XbpDd8ctLD9bJ/Mq7XJjZwBOg4IBBwqtDqJan2tzjy0uuI3rYA+q0WpNEOre
+5IdNa2DO2ZuD6BwGv4/V4aYYYd3fUfOhnpYnW+ouNysvD2B9g5fxG8K6Wi9mvMW1
+w6SNQlbOx5wXi9D8wbCO/YzCqNS9pbz7Ctv4VdzB49p/CuBvDUWD83zEyDzv1vAc
+mrvMWEdpo0u5fos5O8zpn3bYyzuOyLPCBNQy5vXCg9zqOEhBy+DUpt7qzLGelyM4
+zSSsHcEnKqL3AHuF7OP1uBPrd2xbF52xodi4LktZE0gDEVznWsjepBWEI626JhYG
+Dqt4wFsRfPucV1iP4ROGD/wK7zmHhm3ThHdb8PqvNIL4CKQeKBBef77kuoGT5L4V
+5BLhihr7e/6rUFSDDwzP4+4Y2FdEeu/cKbZ6h7aLT87cgdNz1Y0L1M4h876E4PhL
+PkGlqQiaF2rGdRhliO41AgMBAAGjTzBNMCwGA1UdEQQlMCOCIWh0dHBzOi8vdnIt
+Z3JheWxvZy5jbmFhcy5zdW5ldC5zZTAdBgNVHQ4EFgQU/TH99+zMyvk/5KWzb1vS
+0oJ+5L4wDQYJKoZIhvcNAQELBQADggGBAKEaUcToKkEfcgt+XASaOUKSxUI1xrEm
+xSpTNI1J6S5sdaGge5UWdBwAbLnyoScwXJpynX/4vQGCGnq9hxmcTzHyaKd8pbYR
+AoA97W8/RytVYpOgc+IabC4VzW1lXtkKR0tX9S2TuFuDaXl6rSyM4WV7DKRXXhXr
+0OLf0gaFXxaqK0UuF0y3Tc21KMGja1u6K1flpUaCxbaJR5rEUNhEHc+PU0ltqxks
+OlalzJLd2J5XT4JWfovkF7ZxHLEIHqSNzkSDizIWMucfweDgG6ZA6MMrUZZoAISN
+Y0bzDNFTbM5Ic4M9jBqXpMRtLv/4gzM8iFCF3XRpPJuOJIWZFKaJHop1D7OZC67I
+8cqdaNYI5WyhGCsvjDa32BWcyrkegDi79+Wt8qXaGCsItKnpIo9Aj/Sys3gCKDCZ
+XSVWRG272Kd+EAB3DXH4RBBSItGTWFiGro5Rj72UxQ+Me6zaVVfmbTljEQNqw7Bd
+k/NdOp8HphaQKtlQnK7oGfZdAZkhCMWQBg==
+</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
+ </md:KeyDescriptor>
+ <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/Artifact/SOAP" index="1"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/SLO/SOAP"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/SLO/Redirect"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/SLO/POST"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/SLO/Artifact"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/SAML2/POST" index="1"/>
+ <md:AttributeConsumingService index="1">
+ <md:ServiceName xml:lang="sv">CnaaS VR Graylog</md:ServiceName>
+ <md:ServiceName xml:lang="en">CnaaS VR Graylog</md:ServiceName>
+ <md:RequestedAttribute FriendlyName="eduPersonAssurance" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ </md:AttributeConsumingService>
+ </md:SPSSODescriptor>
+ <md:Organization>
+ <md:OrganizationName xml:lang="sv">Sunet</md:OrganizationName>
+ <md:OrganizationName xml:lang="en">Sunet</md:OrganizationName>
+ <md:OrganizationDisplayName xml:lang="en">Sunet</md:OrganizationDisplayName>
+ <md:OrganizationDisplayName xml:lang="sv">Sunet</md:OrganizationDisplayName>
+ <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL>
+ <md:OrganizationURL xml:lang="en">https://www.sunet.se/en</md:OrganizationURL>
+ </md:Organization>
+ <md:ContactPerson contactType="technical">
+ <md:GivenName>Sunet NOC</md:GivenName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="support">
+ <md:GivenName>Sunet NOC</md:GivenName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
+ <md:GivenName>Sunet NOC</md:GivenName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="administrative">
+ <md:GivenName>Ernst Widerberg</md:GivenName>
+ <md:EmailAddress>mailto:ernst@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+</md:EntityDescriptor>
diff --git a/swamid-2.0/vr-nav.cnaas.sunet.se.xml b/swamid-2.0/vr-nav.cnaas.sunet.se.xml
new file mode 100644
index 00000000..a9cee193
--- /dev/null
+++ b/swamid-2.0/vr-nav.cnaas.sunet.se.xml
@@ -0,0 +1,122 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://vr-nav.cnaas.sunet.se">
+ <md:Extensions>
+ <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2022-04-11T16:19:27Z">
+ <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
+ </mdrpi:RegistrationInfo>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
+ <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
+ <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
+ </samla:Attribute>
+ </mdattr:EntityAttributes>
+ </md:Extensions>
+ <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
+ <md:Extensions>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/DS/Login"/>
+ <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/DS/Login" index="1"/>
+ <mdui:UIInfo>
+ <mdui:DisplayName xml:lang="sv">CnaaS VR NAV</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="en">CnaaS VR NAV</mdui:DisplayName>
+ <mdui:Description xml:lang="sv">Nätverksövervakningssystem för CnaaS på VR.</mdui:Description>
+ <mdui:Description xml:lang="en">Network monitoring system for CnaaS at VR.</mdui:Description>
+ <mdui:InformationURL xml:lang="sv">https://nav.uninett.no</mdui:InformationURL>
+ <mdui:InformationURL xml:lang="en">https://nav.uninett.no</mdui:InformationURL>
+ <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+NAV+when+using+federated+login</mdui:PrivacyStatementURL>
+ <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+NAV+when+using+federated+login</mdui:PrivacyStatementURL>
+ </mdui:UIInfo>
+ </md:Extensions>
+ <md:KeyDescriptor>
+ <ds:KeyInfo>
+ <ds:KeyName>https://vr-nav.cnaas.sunet.se</ds:KeyName>
+ <ds:X509Data>
+ <ds:X509SubjectName>CN=https://vr-nav.cnaas.sunet.se</ds:X509SubjectName>
+ <ds:X509Certificate>MIIEKTCCApGgAwIBAgIUPJvDSw/6kkN19HuLaHc//PEwHRgwDQYJKoZIhvcNAQEL
+BQAwKDEmMCQGA1UEAxMdaHR0cHM6Ly92ci1uYXYuY25hYXMuc3VuZXQuc2UwHhcN
+MjIwNDExMDgzNjU3WhcNMzIwNDA4MDgzNjU3WjAoMSYwJAYDVQQDEx1odHRwczov
+L3ZyLW5hdi5jbmFhcy5zdW5ldC5zZTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCC
+AYoCggGBAMnGGaBocrpOyWQOU1s9uxGqmNR/nUMYg2RA6lRDeAa90NLO0ZZb7xaO
+VJ2Z/piyey8c0eg0x6ZbzscOXN9iLMLotcv3iAOfmJIb11+XaTOWT9QXlBpooLBL
+2SQuIHv0B+KcQDy8I+PbvKpXQhH4yV7eS61FX5+27M2oYcA7xurqxv1O6SOVSAxr
+TWGpZ6zCu4hETQKRNdn74VTODMxHj8JLGZdbuv8CpwVAqMwhn9DN18Wx5qqmocx2
+radjrkT4NppHgpaZbDgmmwEBSaSyZHU6fBT4CcP5av6LImPpzCeSqz+8zPdpUH0/
+tuYpxc446GCC6Y4veFcHsLiQDGXqryiSOzlxSJad07QcnifR1VnWrnR5XVvN7eir
+WTwxkyC5ZiBNMk+JORidcyWVlRcnpLtJ6PhXRWI6vGFnhAysHkcwBkPMC2iwv9Wy
+yWYlAlBvR/7mB+eCoY/u+TFfBkCkaOElILpTwswlfUyh7UUzkCBf/5yEyyksedSG
+/uyv4JW9tQIDAQABo0swSTAoBgNVHREEITAfgh1odHRwczovL3ZyLW5hdi5jbmFh
+cy5zdW5ldC5zZTAdBgNVHQ4EFgQUgC0pSR5awu3XBFEOjrn72b24wggwDQYJKoZI
+hvcNAQELBQADggGBAMM8/Winiri0dPikLF5i1BInCQ3L1HGpmQ/dHx+S/p4pvHDZ
+rxARCKgpR1+x8DTrRmkXfm0SAo+REc1Lh+0IDsR2V5rtmuTzFUrurV4E4hTlkBfH
+TmScQZ+9yxm2xnVmnrriVf75nhlbQ5JS5q0cPJJ0rsyAQ3fJRMrrOZMCGpsOaSeD
+8jE77dG63B7lXZ9fjs7IH5QwawJBJFvNvNyyj6aP0VRU4yf1QWDVJQvlEtAgph53
+OMZ99tu3W1DxMsBWnwROe2UieHc6LicOLeQmzHOTQDy9R9k1M2x5hLCB/12BJaqm
+81bnqv0gOuo0dkDSKyEk9HUNLdS0JdzTKzK6/saSZe5Fh1jvEDf5xVq9tF+nwJnO
+zWuhvm/aPGyyG7H97A0vDFvJmTrRx+H/D9hZdaDLZn8MbjfVvLVA3KCzft/bJKHn
+v6lGtuS06TpiAR+VqxrLpKOhx5zWHAqNFaEIWV3Ga2w7pCAr8i5WWystz1WibTLE
+bctpP7CAUeaP0UPPrg==
+</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
+ </md:KeyDescriptor>
+ <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/Artifact/SOAP" index="1"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/SLO/SOAP"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/SLO/Redirect"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/SLO/POST"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/SLO/Artifact"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/SAML2/POST" index="1"/>
+ <md:AttributeConsumingService index="1">
+ <md:ServiceName xml:lang="sv">CnaaS VR NAV</md:ServiceName>
+ <md:ServiceName xml:lang="en">CnaaS VR NAV</md:ServiceName>
+ <md:RequestedAttribute FriendlyName="eduPersonAssurance" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ </md:AttributeConsumingService>
+ </md:SPSSODescriptor>
+ <md:Organization>
+ <md:OrganizationName xml:lang="sv">Sunet</md:OrganizationName>
+ <md:OrganizationName xml:lang="en">Sunet</md:OrganizationName>
+ <md:OrganizationDisplayName xml:lang="en">Sunet</md:OrganizationDisplayName>
+ <md:OrganizationDisplayName xml:lang="sv">Sunet</md:OrganizationDisplayName>
+ <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL>
+ <md:OrganizationURL xml:lang="en">https://www.sunet.se/en</md:OrganizationURL>
+ </md:Organization>
+ <md:ContactPerson contactType="technical">
+ <md:GivenName>Sunet NOC</md:GivenName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="support">
+ <md:GivenName>Sunet NOC</md:GivenName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
+ <md:GivenName>Sunet NOC</md:GivenName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="administrative">
+ <md:GivenName>Ernst Widerberg</md:GivenName>
+ <md:EmailAddress>mailto:ernst@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+</md:EntityDescriptor>
diff --git a/swamid-2.0/vr-ni.cnaas.sunet.se.xml b/swamid-2.0/vr-ni.cnaas.sunet.se.xml
new file mode 100644
index 00000000..eb9e1aeb
--- /dev/null
+++ b/swamid-2.0/vr-ni.cnaas.sunet.se.xml
@@ -0,0 +1,122 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://vr-ni.cnaas.sunet.se">
+ <md:Extensions>
+ <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2022-04-11T16:19:28Z">
+ <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
+ </mdrpi:RegistrationInfo>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
+ <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
+ <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
+ </samla:Attribute>
+ </mdattr:EntityAttributes>
+ </md:Extensions>
+ <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
+ <md:Extensions>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/DS/Login"/>
+ <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/DS/Login" index="1"/>
+ <mdui:UIInfo>
+ <mdui:DisplayName xml:lang="sv">CnaaS VR NI</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="en">CnaaS VR NI</mdui:DisplayName>
+ <mdui:Description xml:lang="sv">Inventariesystem för CnaaS på VR.</mdui:Description>
+ <mdui:Description xml:lang="en">Inventory system for CnaaS at VR.</mdui:Description>
+ <mdui:InformationURL xml:lang="sv">https://portal.nordu.net/display/NI/NORDUnet+Network+Inventory</mdui:InformationURL>
+ <mdui:InformationURL xml:lang="en">https://portal.nordu.net/display/NI/NORDUnet+Network+Inventory</mdui:InformationURL>
+ <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+NI+when+using+federated+login</mdui:PrivacyStatementURL>
+ <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+NI+when+using+federated+login</mdui:PrivacyStatementURL>
+ </mdui:UIInfo>
+ </md:Extensions>
+ <md:KeyDescriptor>
+ <ds:KeyInfo>
+ <ds:KeyName>https://vr-ni.cnaas.sunet.se</ds:KeyName>
+ <ds:X509Data>
+ <ds:X509SubjectName>CN=https://vr-ni.cnaas.sunet.se</ds:X509SubjectName>
+ <ds:X509Certificate>MIIEJjCCAo6gAwIBAgIUYWAjSMMdXQ1j4oqlWf/OUQLzwKMwDQYJKoZIhvcNAQEL
+BQAwJzElMCMGA1UEAxMcaHR0cHM6Ly92ci1uaS5jbmFhcy5zdW5ldC5zZTAeFw0y
+MjA0MTEwODQ1MDJaFw0zMjA0MDgwODQ1MDJaMCcxJTAjBgNVBAMTHGh0dHBzOi8v
+dnItbmkuY25hYXMuc3VuZXQuc2UwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGK
+AoIBgQDRLeAbIF0T2MeSZ8+hR92K2C/EaLU3i7PCrtqiT0z4QKj0E1o07dIB0YU7
+duzVseuk81FpdbhT3gqooj4NA+qLK7HM5X5rzk4fNoXFrytubNA62yXeTGpd//8B
+bontiw/yfqH774CUMEbSxZeZ2dzgSo8ckERDiG2SG4F30v/jLMCqjDkQQDcF5Y2u
+x45kF16BG3uZQv3M010ZrHedf0AM1BTCGndWfajCoMq9ouPsVsG+P0KMiGdiTzj+
+GQMkJJqfYmlUGNrLEeRuuVIHcvG3diSdkD5j2l3uMHE1Cd+ckVgoKw7VW7CJVBEO
+HNyBGwA9RRcRRDrloi9qEs5hp2A/XDhPUeOdgmlwOzR3cKS0wpdvcdcyebeewKRm
+8iL+O8Caq4yqDdYNxjXTstE6uZ8V0YWLGHeDxKyBpB/wIlAji1EAngwkzDF/HO4R
+ZK/M7YeL72aWWsxTyEeUsP2+h7H+mf4ejQzfbvZycOKV6i/OiRaQYUHxEoL3ca3L
+9DZV6icCAwEAAaNKMEgwJwYDVR0RBCAwHoIcaHR0cHM6Ly92ci1uaS5jbmFhcy5z
+dW5ldC5zZTAdBgNVHQ4EFgQUI9v9bJZZ+puRHChav1gJNysYE8gwDQYJKoZIhvcN
+AQELBQADggGBAHaivtnDowTbTwpzEg1LjbLpLTaFOKg4pgH6zQUB42RLocL1smZW
+r3OW1cbBg6ilZicLtdTf+Ob9sxorrQjSDZwZwVpa+2lD8SKAF/geU1vNEmdwSKpf
++ZTw/p1dL7dpagTaDvurnHmdXYJhJN7FMmVMnKHaMM5Nwx7JiBZIle8dXhVo6WP6
+zATE3n8tY9br+nnpVWuBr3BpQnzTzQfFBwKaYTLUzJNwm2o2DbKJEYXmEfPB67CW
+HjzPWh06MJp/NPClizEv9fwIGl2W52qT83sYVvHmb38DN8lfunfha9XxnUXGOx9o
+4SCE0Rcw1JxqNEmi8TiLHwgzjei/I9KeS0vZAcLcXVyhyUCXQ4uiqzpddBEcY88g
+aYy3zGthph1a6y4dCqMx6a5Jl8dt5K1nZ3TCzpE5VRHqf7xk2VwfIFTpkFsg723d
+ox4VOB6xX60h7X4G/Olwmcks4VB2oc7ocGRz9+0fy85gqRLKsRv8Jh4dAA5B7bT9
+evNq8iUcag9HrQ==
+</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
+ </md:KeyDescriptor>
+ <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/Artifact/SOAP" index="1"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/SLO/SOAP"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/SLO/Redirect"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/SLO/POST"/>
+ <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/SLO/Artifact"/>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/SAML2/POST" index="1"/>
+ <md:AttributeConsumingService index="1">
+ <md:ServiceName xml:lang="sv">CnaaS VR NI</md:ServiceName>
+ <md:ServiceName xml:lang="en">CnaaS VR NI</md:ServiceName>
+ <md:RequestedAttribute FriendlyName="eduPersonAssurance" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ </md:AttributeConsumingService>
+ </md:SPSSODescriptor>
+ <md:Organization>
+ <md:OrganizationName xml:lang="sv">Sunet</md:OrganizationName>
+ <md:OrganizationName xml:lang="en">Sunet</md:OrganizationName>
+ <md:OrganizationDisplayName xml:lang="en">Sunet</md:OrganizationDisplayName>
+ <md:OrganizationDisplayName xml:lang="sv">Sunet</md:OrganizationDisplayName>
+ <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL>
+ <md:OrganizationURL xml:lang="en">https://www.sunet.se/en</md:OrganizationURL>
+ </md:Organization>
+ <md:ContactPerson contactType="technical">
+ <md:GivenName>Sunet NOC</md:GivenName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="support">
+ <md:GivenName>Sunet NOC</md:GivenName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
+ <md:GivenName>Sunet NOC</md:GivenName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="administrative">
+ <md:GivenName>Ernst Widerberg</md:GivenName>
+ <md:EmailAddress>mailto:ernst@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+</md:EntityDescriptor>
diff --git a/swamid-sp-2.0.mxml b/swamid-sp-2.0.mxml
index 45ea2a7d..74d48457 100644
--- a/swamid-sp-2.0.mxml
+++ b/swamid-sp-2.0.mxml
@@ -710,4 +710,7 @@
<xi:include href="swamid-2.0/verify.sunet.se-shibboleth.xml"/>
<xi:include href="swamid-2.0/test-examensansokan.portal.chalmers.se-ny.xml"/>
<xi:include href="swamid-2.0/confluence-dev.its.umu.se-shibboleth.xml"/>
+ <xi:include href="swamid-2.0/vr-ni.cnaas.sunet.se.xml"/>
+ <xi:include href="swamid-2.0/vr-graylog.cnaas.sunet.se.xml"/>
+ <xi:include href="swamid-2.0/vr-nav.cnaas.sunet.se.xml"/>
</md:EntitiesDescriptor>