summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBjörn Mattsson <bjorn@sunet.se>2024-09-02 09:09:54 +0200
committerBjörn Mattsson <bjorn@sunet.se>2024-09-02 09:09:54 +0200
commit192ca8eb7edd0de18327b556d001c8075b0788b7 (patch)
tree6b29380d23ef9e1778a236399259ea9449e23d34
parent24d46b743f587d71899284f21a62c169c569801d (diff)
SWAMID-4453 Sirtfi för Ladokmd-2024-09-02-v02
-rw-r--r--metadata/swamid-2.0/dev-idp-lab.utv.ladok.se-proxy-sp-metadata.xml.xml4
-rw-r--r--metadata/swamid-2.0/dev-idp.utv.ladok.se-proxy-sp-metadata.xml.xml4
-rw-r--r--metadata/swamid-2.0/integratorsportal.ladok.se-saml2-metadata-.xml8
-rw-r--r--metadata/swamid-2.0/jenkins-infra.utv.ladok.se-securityRealm-finishLogin.xml6
-rw-r--r--metadata/swamid-2.0/jenkins-stage.utv.ladok.se-securityRealm-finishLogin.xml6
-rw-r--r--metadata/swamid-2.0/jenkins.led.ladok.se-securityRealm-finishLogin.xml6
-rw-r--r--metadata/swamid-2.0/jenkins.utv.ladok.se-securityRealm-finishLogin.xml6
-rw-r--r--metadata/swamid-2.0/sonarqube.infra.utv.ladok.se-saml.xml6
-rw-r--r--metadata/swamid-2.0/support-idp.led.ladok.se-proxy-sp-metadata.xml.xml4
-rw-r--r--metadata/swamid-edugain/ladok3.its.umu.se-shibboleth.xml8
10 files changed, 48 insertions, 10 deletions
diff --git a/metadata/swamid-2.0/dev-idp-lab.utv.ladok.se-proxy-sp-metadata.xml.xml b/metadata/swamid-2.0/dev-idp-lab.utv.ladok.se-proxy-sp-metadata.xml.xml
index 02acdc8e..3c1f5cce 100644
--- a/metadata/swamid-2.0/dev-idp-lab.utv.ladok.se-proxy-sp-metadata.xml.xml
+++ b/metadata/swamid-2.0/dev-idp-lab.utv.ladok.se-proxy-sp-metadata.xml.xml
@@ -8,6 +8,10 @@
<samla:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
</samla:Attribute>
+ <samla:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>https://refeds.org/sirtfi2</samla:AttributeValue>
+ <samla:AttributeValue>https://refeds.org/sirtfi</samla:AttributeValue>
+ </samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
<md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" AuthnRequestsSigned="false" WantAssertionsSigned="false">
diff --git a/metadata/swamid-2.0/dev-idp.utv.ladok.se-proxy-sp-metadata.xml.xml b/metadata/swamid-2.0/dev-idp.utv.ladok.se-proxy-sp-metadata.xml.xml
index 70812eeb..b288bfb0 100644
--- a/metadata/swamid-2.0/dev-idp.utv.ladok.se-proxy-sp-metadata.xml.xml
+++ b/metadata/swamid-2.0/dev-idp.utv.ladok.se-proxy-sp-metadata.xml.xml
@@ -8,6 +8,10 @@
<samla:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
</samla:Attribute>
+ <samla:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>https://refeds.org/sirtfi2</samla:AttributeValue>
+ <samla:AttributeValue>https://refeds.org/sirtfi</samla:AttributeValue>
+ </samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
<md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" AuthnRequestsSigned="false" WantAssertionsSigned="false">
diff --git a/metadata/swamid-2.0/integratorsportal.ladok.se-saml2-metadata-.xml b/metadata/swamid-2.0/integratorsportal.ladok.se-saml2-metadata-.xml
index 61103e98..f7922784 100644
--- a/metadata/swamid-2.0/integratorsportal.ladok.se-saml2-metadata-.xml
+++ b/metadata/swamid-2.0/integratorsportal.ladok.se-saml2-metadata-.xml
@@ -6,6 +6,10 @@
<samla:AttributeValue xsi:type="xs:string">http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
<samla:AttributeValue>https://refeds.org/category/code-of-conduct/v2</samla:AttributeValue>
</samla:Attribute>
+ <samla:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>https://refeds.org/sirtfi2</samla:AttributeValue>
+ <samla:AttributeValue>https://refeds.org/sirtfi</samla:AttributeValue>
+ </samla:Attribute>
</mdattr:EntityAttributes>
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#md5"/>
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#ripemd160"/>
@@ -43,8 +47,8 @@
<mdui:PrivacyStatementURL xml:lang="en">https://ladok.se/transfer-of-personal-data-to-ladok-when-using-federated-login</mdui:PrivacyStatementURL>
<mdui:Description xml:lang="en">Ladok is a central service for study administration aimed at students and study administrative staff at higher education institutions in Sweden.</mdui:Description>
<mdui:Description xml:lang="sv">Ladok är en central tjänst för studieadministration riktad till studenter och studieadministrativ personal på universitet och högskolor i Sverige.</mdui:Description>
- <mdui:Logo xml:lang="en" height="98" width="96">https://www.start.ladok.se/logo/ladok_en.png</mdui:Logo>
- <mdui:Logo xml:lang="sv" height="98" width="96">https://www.start.ladok.se/logo/ladok_sv.png</mdui:Logo>
+ <mdui:Logo xml:lang="en" height="64" width="64">https://www.start.ladok.se/logo/ladok_en.png</mdui:Logo>
+ <mdui:Logo xml:lang="sv" height="64" width="64">https://www.start.ladok.se/logo/ladok_sv.png</mdui:Logo>
</mdui:UIInfo>
</md:Extensions>
<md:KeyDescriptor use="signing">
diff --git a/metadata/swamid-2.0/jenkins-infra.utv.ladok.se-securityRealm-finishLogin.xml b/metadata/swamid-2.0/jenkins-infra.utv.ladok.se-securityRealm-finishLogin.xml
index a16775b9..ee88bbc9 100644
--- a/metadata/swamid-2.0/jenkins-infra.utv.ladok.se-securityRealm-finishLogin.xml
+++ b/metadata/swamid-2.0/jenkins-infra.utv.ladok.se-securityRealm-finishLogin.xml
@@ -25,9 +25,13 @@
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
<samla:AttributeValue>https://refeds.org/category/personalized</samla:AttributeValue>
</samla:Attribute>
+ <samla:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>https://refeds.org/sirtfi</samla:AttributeValue>
+ <samla:AttributeValue>https://refeds.org/sirtfi2</samla:AttributeValue>
+ </samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
- <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.0:protocol urn:oasis:names:tc:SAML:1.1:protocol">
+ <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
<init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://jenkins-infra.utv.ladok.se/securityRealm/finishLogin"/>
<mdui:UIInfo>
diff --git a/metadata/swamid-2.0/jenkins-stage.utv.ladok.se-securityRealm-finishLogin.xml b/metadata/swamid-2.0/jenkins-stage.utv.ladok.se-securityRealm-finishLogin.xml
index 617ad098..5eee9a3c 100644
--- a/metadata/swamid-2.0/jenkins-stage.utv.ladok.se-securityRealm-finishLogin.xml
+++ b/metadata/swamid-2.0/jenkins-stage.utv.ladok.se-securityRealm-finishLogin.xml
@@ -22,12 +22,16 @@
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
<samla:AttributeValue>https://refeds.org/category/personalized</samla:AttributeValue>
</samla:Attribute>
+ <samla:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>https://refeds.org/sirtfi2</samla:AttributeValue>
+ <samla:AttributeValue>https://refeds.org/sirtfi</samla:AttributeValue>
+ </samla:Attribute>
</mdattr:EntityAttributes>
<mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2023-12-21T06:48:38Z">
<mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
</md:Extensions>
- <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.0:protocol urn:oasis:names:tc:SAML:1.1:protocol">
+ <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
<init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://jenkins-stage.utv.ladok.se/securityRealm/finishLogin"/>
<mdui:UIInfo>
diff --git a/metadata/swamid-2.0/jenkins.led.ladok.se-securityRealm-finishLogin.xml b/metadata/swamid-2.0/jenkins.led.ladok.se-securityRealm-finishLogin.xml
index 3f885634..ab206da7 100644
--- a/metadata/swamid-2.0/jenkins.led.ladok.se-securityRealm-finishLogin.xml
+++ b/metadata/swamid-2.0/jenkins.led.ladok.se-securityRealm-finishLogin.xml
@@ -25,9 +25,13 @@
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
<samla:AttributeValue>https://refeds.org/category/personalized</samla:AttributeValue>
</samla:Attribute>
+ <samla:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>https://refeds.org/sirtfi</samla:AttributeValue>
+ <samla:AttributeValue>https://refeds.org/sirtfi2</samla:AttributeValue>
+ </samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
- <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.0:protocol urn:oasis:names:tc:SAML:1.1:protocol">
+ <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
<init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://jenkins.led.ladok.se/securityRealm/finishLogin"/>
<mdui:UIInfo>
diff --git a/metadata/swamid-2.0/jenkins.utv.ladok.se-securityRealm-finishLogin.xml b/metadata/swamid-2.0/jenkins.utv.ladok.se-securityRealm-finishLogin.xml
index 4356a8f6..36bbadd1 100644
--- a/metadata/swamid-2.0/jenkins.utv.ladok.se-securityRealm-finishLogin.xml
+++ b/metadata/swamid-2.0/jenkins.utv.ladok.se-securityRealm-finishLogin.xml
@@ -22,12 +22,16 @@
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
<samla:AttributeValue>https://refeds.org/category/personalized</samla:AttributeValue>
</samla:Attribute>
+ <samla:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>https://refeds.org/sirtfi</samla:AttributeValue>
+ <samla:AttributeValue>https://refeds.org/sirtfi2</samla:AttributeValue>
+ </samla:Attribute>
</mdattr:EntityAttributes>
<mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2024-08-01T14:07:23Z">
<mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
</md:Extensions>
- <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.0:protocol urn:oasis:names:tc:SAML:1.1:protocol">
+ <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
<init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://jenkins.utv.ladok.se/securityRealm/finishLogin"/>
<mdui:UIInfo>
diff --git a/metadata/swamid-2.0/sonarqube.infra.utv.ladok.se-saml.xml b/metadata/swamid-2.0/sonarqube.infra.utv.ladok.se-saml.xml
index 8295c4ea..d239e2f7 100644
--- a/metadata/swamid-2.0/sonarqube.infra.utv.ladok.se-saml.xml
+++ b/metadata/swamid-2.0/sonarqube.infra.utv.ladok.se-saml.xml
@@ -24,9 +24,13 @@
<samla:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<samla:AttributeValue>https://refeds.org/category/personalized</samla:AttributeValue>
</samla:Attribute>
+ <samla:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>https://refeds.org/sirtfi2</samla:AttributeValue>
+ <samla:AttributeValue>https://refeds.org/sirtfi</samla:AttributeValue>
+ </samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
- <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.0:protocol urn:oasis:names:tc:SAML:1.1:protocol">
+ <md:SPSSODescriptor AuthnRequestsSigned="false" WantAssertionsSigned="false" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
<init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://jenkins-infra.utv.ladok.se/securityRealm/finishLogin"/>
<mdui:UIInfo>
diff --git a/metadata/swamid-2.0/support-idp.led.ladok.se-proxy-sp-metadata.xml.xml b/metadata/swamid-2.0/support-idp.led.ladok.se-proxy-sp-metadata.xml.xml
index 7022e633..92f54d8d 100644
--- a/metadata/swamid-2.0/support-idp.led.ladok.se-proxy-sp-metadata.xml.xml
+++ b/metadata/swamid-2.0/support-idp.led.ladok.se-proxy-sp-metadata.xml.xml
@@ -8,6 +8,10 @@
<samla:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
</samla:Attribute>
+ <samla:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>https://refeds.org/sirtfi2</samla:AttributeValue>
+ <samla:AttributeValue>https://refeds.org/sirtfi</samla:AttributeValue>
+ </samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
<md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" AuthnRequestsSigned="false" WantAssertionsSigned="false">
diff --git a/metadata/swamid-edugain/ladok3.its.umu.se-shibboleth.xml b/metadata/swamid-edugain/ladok3.its.umu.se-shibboleth.xml
index 6c9edf1e..a8c8e42a 100644
--- a/metadata/swamid-edugain/ladok3.its.umu.se-shibboleth.xml
+++ b/metadata/swamid-edugain/ladok3.its.umu.se-shibboleth.xml
@@ -25,9 +25,13 @@
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
<samla:AttributeValue>https://refeds.org/category/personalized</samla:AttributeValue>
</samla:Attribute>
+ <samla:Attribute Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>https://refeds.org/sirtfi</samla:AttributeValue>
+ <samla:AttributeValue>https://refeds.org/sirtfi2</samla:AttributeValue>
+ </samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
- <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol">
+ <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
<init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://ladok3.its.umu.se/Shibboleth.sso/Login"/>
<idpdisc:DiscoveryResponse Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://ladok3.its.umu.se/Shibboleth.sso/Login" index="1"/>
@@ -93,8 +97,6 @@ vqX2O1UUS1leSB8AnvrsfuoKlZQQKgsrokXQTEo=</ds:X509Certificate>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://ladok3.its.umu.se/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://ladok3.its.umu.se/Shibboleth.sso/SAML2/Artifact" index="3"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://ladok3.its.umu.se/Shibboleth.sso/SAML2/ECP" index="4"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://ladok3.its.umu.se/Shibboleth.sso/SAML/POST" index="5"/>
- <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://ladok3.its.umu.se/Shibboleth.sso/SAML/Artifact" index="6"/>
<md:AttributeConsumingService index="1">
<md:ServiceName xml:lang="en">ladok3.its.umu.se login</md:ServiceName>
<md:ServiceName xml:lang="sv">Inloggning ladok3.its.umu.se</md:ServiceName>