summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBjörn Mattsson <bjorn@sunet.se>2022-04-29 16:53:29 +0200
committerBjörn Mattsson <bjorn@sunet.se>2022-04-29 16:53:29 +0200
commit9ce08954853a32527dc5ff16af41d78bd70c6a0d (patch)
tree6a2a7491fe239e27b5fafe7d4788924f0f87b986
parent8674b663bde8cbd4d2705c1f4e6d040827e1ecb5 (diff)
SWAMID-882, 885 – 886 Updated kontrollpanelen.sunet.se, graylog.sunet.se, misp.cert.sunet.se
-rw-r--r--swamid-2.0/graylog.sunet.se-shibboleth.xml45
-rw-r--r--swamid-2.0/kontrollpanelen.sunet.se-shibboleth.xml20
-rw-r--r--swamid-2.0/misp.cert.sunet.se-shibboleth.xml43
3 files changed, 101 insertions, 7 deletions
diff --git a/swamid-2.0/graylog.sunet.se-shibboleth.xml b/swamid-2.0/graylog.sunet.se-shibboleth.xml
index 05131cdd..857c466c 100644
--- a/swamid-2.0/graylog.sunet.se-shibboleth.xml
+++ b/swamid-2.0/graylog.sunet.se-shibboleth.xml
@@ -26,8 +26,7 @@ and do *NOT* provide it in real time to your partners.
<alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
<mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
<samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category">
- <samla:AttributeValue>http://www.swamid.se/category/nren-service</samla:AttributeValue>
- <samla:AttributeValue>http://www.swamid.se/category/research-and-education</samla:AttributeValue>
+ <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
</samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
@@ -40,6 +39,10 @@ and do *NOT* provide it in real time to your partners.
<mdui:DisplayName xml:lang="en">Graylog</mdui:DisplayName>
<mdui:Description xml:lang="sv">En loggtjänst hos SUNET</mdui:Description>
<mdui:Description xml:lang="en">A logging service at SUNET</mdui:Description>
+ <mdui:InformationURL xml:lang="en">https://wiki.sunet.se/display/SUNETCERT/Graylog</mdui:InformationURL>
+ <mdui:InformationURL xml:lang="sv">https://wiki.sunet.se/display/SUNETCERT/Graylog</mdui:InformationURL>
+ <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+Graylog+when+using+federated+login</mdui:PrivacyStatementURL>
+ <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+Graylog+when+using+federated+login</mdui:PrivacyStatementURL>
</mdui:UIInfo>
</md:Extensions>
<md:KeyDescriptor>
@@ -86,10 +89,42 @@ x642c5iHKr2d/SOMA05pL7Qz4RB2fDIgmPg6VzglrkKBYVHUIi3a1j5dBA==
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://graylog.sunet.se/Shibboleth.sso/SAML2/ECP" index="3"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://graylog.sunet.se/Shibboleth.sso/SAML/POST" index="4"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://graylog.sunet.se/Shibboleth.sso/SAML/Artifact" index="5"/>
+ <md:AttributeConsumingService index="1">
+ <md:ServiceName xml:lang="en">Graylog Logservice</md:ServiceName>
+ <md:ServiceName xml:lang="sv">Graylog Loggtjänst</md:ServiceName>
+ <md:RequestedAttribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ </md:AttributeConsumingService>
</md:SPSSODescriptor>
+ <md:Organization>
+ <md:OrganizationName xml:lang="en">Swedish University Network</md:OrganizationName>
+ <md:OrganizationName xml:lang="sv">Svenska Universitetsdatornätverket</md:OrganizationName>
+ <md:OrganizationDisplayName xml:lang="en">SUNET</md:OrganizationDisplayName>
+ <md:OrganizationDisplayName xml:lang="sv">SUNET</md:OrganizationDisplayName>
+ <md:OrganizationURL xml:lang="en">https://www.sunet.se</md:OrganizationURL>
+ <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL>
+ </md:Organization>
<md:ContactPerson contactType="administrative">
- <md:GivenName>Fredrik</md:GivenName>
- <md:SurName>Pettai</md:SurName>
- <md:EmailAddress>mailto:pettai@nordu.net</md:EmailAddress>
+ <md:Company>SUNET</md:Company>
+ <md:GivenName>Network</md:GivenName>
+ <md:SurName>Operations</md:SurName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="technical">
+ <md:Company>SUNET</md:Company>
+ <md:GivenName>Network</md:GivenName>
+ <md:SurName>Operations</md:SurName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="support">
+ <md:Company>SUNET</md:Company>
+ <md:GivenName>Network</md:GivenName>
+ <md:SurName>Operations</md:SurName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
+ <md:GivenName>Security Response Team</md:GivenName>
+ <md:EmailAddress>mailto:abuse@sunet.se</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
diff --git a/swamid-2.0/kontrollpanelen.sunet.se-shibboleth.xml b/swamid-2.0/kontrollpanelen.sunet.se-shibboleth.xml
index 1e908120..28b3d3f8 100644
--- a/swamid-2.0/kontrollpanelen.sunet.se-shibboleth.xml
+++ b/swamid-2.0/kontrollpanelen.sunet.se-shibboleth.xml
@@ -23,6 +23,7 @@
<mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
<samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category">
<samla:AttributeValue>http://refeds.org/category/research-and-scholarship</samla:AttributeValue>
+ <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
</samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
@@ -35,6 +36,10 @@
<mdui:DisplayName xml:lang="en">Mailfilter-ng Control panel</mdui:DisplayName>
<mdui:Description xml:lang="sv">Mailfilter-ng, AntiSpam tjänst hos SUNET</mdui:Description>
<mdui:Description xml:lang="en">Mailfilter-ng, antispam service at SUNET</mdui:Description>
+ <mdui:InformationURL xml:lang="en">https://www.sunet.se/services/sakerhet/mailfilter</mdui:InformationURL>
+ <mdui:InformationURL xml:lang="sv">https://www.sunet.se/services/sakerhet/mailfilter</mdui:InformationURL>
+ <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/Mailfilter/Data+Protection+Code+of+Conduct</mdui:PrivacyStatementURL>
+ <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/Mailfilter/Data+Protection+Code+of+Conduct</mdui:PrivacyStatementURL>
</mdui:UIInfo>
</md:Extensions>
<md:KeyDescriptor>
@@ -87,7 +92,22 @@ iwGo/TqTT5u0WBmEbv41WKYpqfeaOw8wGnkg8qSarChrIBXNJkfZmxAz8P6Xp0Ig
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://kontrollpanelen.sunet.se/Shibboleth.sso/SAML2/ECP" index="4"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://kontrollpanelen.sunet.se/Shibboleth.sso/SAML/POST" index="5"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://kontrollpanelen.sunet.se/Shibboleth.sso/SAML/Artifact" index="6"/>
+ <md:AttributeConsumingService index="1">
+ <md:ServiceName xml:lang="en">Halon MSUI</md:ServiceName>
+ <md:ServiceName xml:lang="sv">Halon Kontrollpanel</md:ServiceName>
+ <md:RequestedAttribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ </md:AttributeConsumingService>
</md:SPSSODescriptor>
+ <md:Organization>
+ <md:OrganizationName xml:lang="en">Swedish University Network</md:OrganizationName>
+ <md:OrganizationName xml:lang="sv">Svenska Universitetsdatornätverket</md:OrganizationName>
+ <md:OrganizationDisplayName xml:lang="en">SUNET</md:OrganizationDisplayName>
+ <md:OrganizationDisplayName xml:lang="sv">SUNET</md:OrganizationDisplayName>
+ <md:OrganizationURL xml:lang="en">https://www.sunet.se</md:OrganizationURL>
+ <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL>
+ </md:Organization>
<md:ContactPerson contactType="administrative">
<md:Company>SUNET</md:Company>
<md:GivenName>Network</md:GivenName>
diff --git a/swamid-2.0/misp.cert.sunet.se-shibboleth.xml b/swamid-2.0/misp.cert.sunet.se-shibboleth.xml
index 1ebfdc59..2a26611a 100644
--- a/swamid-2.0/misp.cert.sunet.se-shibboleth.xml
+++ b/swamid-2.0/misp.cert.sunet.se-shibboleth.xml
@@ -22,8 +22,7 @@
<alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
<mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
<samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category">
- <samla:AttributeValue>http://www.swamid.se/category/nren-service</samla:AttributeValue>
- <samla:AttributeValue>http://www.swamid.se/category/research-and-education</samla:AttributeValue>
+ <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
</samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
@@ -36,6 +35,10 @@
<mdui:DisplayName xml:lang="en">SUNET MISP</mdui:DisplayName>
<mdui:Description xml:lang="sv">MISP tjänst hos SUNET</mdui:Description>
<mdui:Description xml:lang="en">MISP service run by SUNET</mdui:Description>
+ <mdui:InformationURL xml:lang="en">https://wiki.sunet.se/display/SUNETCERT/MISP</mdui:InformationURL>
+ <mdui:InformationURL xml:lang="sv">https://wiki.sunet.se/display/SUNETCERT/MISP</mdui:InformationURL>
+ <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/SUNETCERT/Data+Protection+Code+of+Conduct</mdui:PrivacyStatementURL>
+ <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/SUNETCERT/Data+Protection+Code+of+Conduct</mdui:PrivacyStatementURL>
</mdui:UIInfo>
</md:Extensions>
<md:KeyDescriptor>
@@ -87,5 +90,41 @@ pVHC0z9N3EFKt9RGKKG/Jbk4mSpbYCU=
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://misp.cert.sunet.se/Shibboleth.sso/SAML2/ECP" index="3"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://misp.cert.sunet.se/Shibboleth.sso/SAML/POST" index="4"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://misp.cert.sunet.se/Shibboleth.sso/SAML/Artifact" index="5"/>
+ <md:AttributeConsumingService index="1">
+ <md:ServiceName xml:lang="en">CIRCL MISP</md:ServiceName>
+ <md:ServiceName xml:lang="sv">CIRCL MISP</md:ServiceName>
+ <md:RequestedAttribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ </md:AttributeConsumingService>
</md:SPSSODescriptor>
+ <md:Organization>
+ <md:OrganizationName xml:lang="en">Swedish University Network</md:OrganizationName>
+ <md:OrganizationName xml:lang="sv">Svenska Universitetsdatornätverket</md:OrganizationName>
+ <md:OrganizationDisplayName xml:lang="en">SUNET</md:OrganizationDisplayName>
+ <md:OrganizationDisplayName xml:lang="sv">SUNET</md:OrganizationDisplayName>
+ <md:OrganizationURL xml:lang="en">https://www.sunet.se</md:OrganizationURL>
+ <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL>
+ </md:Organization>
+ <md:ContactPerson contactType="administrative">
+ <md:Company>SUNET</md:Company>
+ <md:GivenName>Security Response Team</md:GivenName>
+ <md:EmailAddress>mailto:cert@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="technical">
+ <md:Company>SUNET</md:Company>
+ <md:GivenName>Security Response Team</md:GivenName>
+ <md:EmailAddress>mailto:cert@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="support">
+ <md:Company>SUNET</md:Company>
+ <md:GivenName>Network</md:GivenName>
+ <md:SurName>Operations</md:SurName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
+ <md:Company>SUNET</md:Company>
+ <md:GivenName>Security Response Team</md:GivenName>
+ <md:EmailAddress>mailto:abuse@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
</md:EntityDescriptor>