summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBjörn Mattsson <bjorn@sunet.se>2023-06-14 22:17:51 +0200
committerBjörn Mattsson <bjorn@sunet.se>2023-06-14 22:17:51 +0200
commit3dcc2afffbf17f5ea65387fe9b749185d1090e0b (patch)
treee304f014891cfeb77aa136b757fef7e51917cabd
parent3bc7bbfecd016e6b1e5263fb1bde08d408802ecb (diff)
SUNETOPS-1684 Ny OIDC proxy för elementmd-2023-06-14-v04
-rw-r--r--metadata/swamid-2.0/matrix-test-idp-proxy.sunet.se-sp.xml96
-rw-r--r--metadata/swamid-sp-2.0.mxml1
2 files changed, 97 insertions, 0 deletions
diff --git a/metadata/swamid-2.0/matrix-test-idp-proxy.sunet.se-sp.xml b/metadata/swamid-2.0/matrix-test-idp-proxy.sunet.se-sp.xml
new file mode 100644
index 00000000..2fb6c872
--- /dev/null
+++ b/metadata/swamid-2.0/matrix-test-idp-proxy.sunet.se-sp.xml
@@ -0,0 +1,96 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute" xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://matrix-test-idp-proxy.sunet.se/sp">
+ <md:Extensions>
+ <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2023-06-14T22:17:07Z">
+ <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
+ </mdrpi:RegistrationInfo>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#md5"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#ripemd160"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-md5"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-ripemd160"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha224"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
+ <mdattr:EntityAttributes>
+ <samla:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+ <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
+ </samla:Attribute>
+ </mdattr:EntityAttributes>
+ </md:Extensions>
+ <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" AuthnRequestsSigned="false" WantAssertionsSigned="false">
+ <md:Extensions>
+ <idpdisc:DiscoveryResponse Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://matrix-test-idp-proxy.sunet.se/Saml2SP/disco" index="1"/>
+ <mdui:UIInfo>
+ <mdui:Description xml:lang="en">Matrix service run by SUNET</mdui:Description>
+ <mdui:Description xml:lang="sv">Matrix tjänst hos SUNET</mdui:Description>
+ <mdui:DisplayName xml:lang="en">SUNET Matrix</mdui:DisplayName>
+ <mdui:DisplayName xml:lang="sv">SUNET Matrix</mdui:DisplayName>
+ <mdui:InformationURL xml:lang="en">https://wiki.sunet.se/display/SUNETCERT/MISP</mdui:InformationURL>
+ <mdui:InformationURL xml:lang="sv">https://wiki.sunet.se/display/SUNETCERT/MISP</mdui:InformationURL>
+ <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/SUNETCERT/Data+Protection+Code+of+Conduct</mdui:PrivacyStatementURL>
+ <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/SUNETCERT/Data+Protection+Code+of+Conduct</mdui:PrivacyStatementURL>
+ </mdui:UIInfo>
+ </md:Extensions>
+ <md:KeyDescriptor use="signing">
+ <ds:KeyInfo>
+ <ds:X509Data>
+ <ds:X509Certificate>MIIFEzCCAvugAwIBAgIUHrUCohPj1gunSezvCK7Ps+CtvZAwDQYJKoZIhvcNAQELBQAwGTEXMBUGA1UEAwwOc2F0b3NhX2JhY2tlbmQwHhcNMjMwNjE0MTQwNTQyWhcNMzMwNjExMTQwNTQyWjAZMRcwFQYDVQQDDA5zYXRvc2FfYmFja2VuZDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAMUGa8dvaJAloGjIMVQ9creiCEF0gcSxMccaYL0FhpPkTjFWzsjlZveLoiMsA4U5KyuzUdgSM2uyunsHXqb+t62aB/iGALcPAREk1COhgOoqiGNgz4M1oOrvzpKE9U2ofRfZASFbKSMyhoCSHADRysRwBQW4+6o7ujX//B1lBOhGmzC8UJfMDo2IQ/3IZqBWY543MNn3q3mADkqUXXlewBLgcKAm+7pXTykxZ4FPbj8VxQDLjZB1rgLagjg7NfA30lR1AY02+0OJOZW2ujGL9M5NISZ6YI3klnIfVsxX+so+UHQEw+mgDHQMbesS8I0cZaNv+qAkqxzCUVqkFaeDWhFMr4a8bDyR9aStF78ps+74i5Zy22LR67OdlwkI9a75u5UAVsCBVmbQDgVopg8T037WcC/nPHH0qzWxJGQ80AQahm3LRhLU1cb7VsErtyFGaLi1eBRKscdwyS+D5KNa2RZb5pL5Rl8tZaLrC7IzfCxW8I9SgDad7QvLLbBjIUmtos4eyBK67EEw8GsDnzPH2Eoe24gfn0AmJg8i7nNl8Z2KL0ua0p68EJyXrQ9VCqSx23JpqGrebDmHgTN/zhdykY+gN/BtpNT1YhtAbemAXp4wGHjEn6i/wHUXe6tNEDvrY5idOBdrFB+Ek5hC9sJixvly1PkQCdxpB6FwksRImSRnAgMBAAGjUzBRMB0GA1UdDgQWBBTaFM4BlNXJUX6Ki+QtQnW/f0TcXDAfBgNVHSMEGDAWgBTaFM4BlNXJUX6Ki+QtQnW/f0TcXDAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4ICAQAV1rLNb6nUU0apKmtd/MdfYcVusw+0vlLSxFSFRsHPkIkPva03BY9Y8iVrK45dQcLEwTqiOjhUPikXgll6jFjw48Je8ENYJIFsQslOJbh/NqdYmutNYj/MCQHc7/mviGNJXpXRJmTHEjcmsPmpQMQPYRTV503yPyue2N9nGHyOzblZbKLQUK1Nw/tNdTgM1Y738B4CjXI0KpN//arQBNrMCWAHjLtNTyhz6qUiJKCK1p3vCBC/4DrKqs3Xk5i1ky1Uzoj/0VV+WIJVv/voHhRaxuMeJv0zSWb5IFgujfwZCIQlVU9yU5JWL3ju0oaBHtkclG3Kl5owRRjKKHwcI4/Xb7OMIkULyj82haTIXYf0UBfX7JWtvnDHiK2QP/Oh1tlWqLek6qTMxP/DC94HARBuGdD3jjNQ3IaONLchGXkCBHot4u+I5eOVJgl2E0U+AZYvga8pOB1cWS40BoMwpzXx6j4+W2G3Uvej+Ob09PtHzOtQ/ZSFUqro6499bAhAJSxY3u/q+Duxd4c82q4MMKFdZ0iHxKQjK5WBmce4cK1E5B7N9oKsTiZEgWH6EJmEiZQCXGXos/qPYqJIR1/Mvtuq0lloCkNW2hs3cLkUYZou8sToZY1LpRa57NY/5nDICcugysw93979rXZb7B1M053R53E+9KL/gxZQY6LvbyN1AA==</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ </md:KeyDescriptor>
+ <md:KeyDescriptor use="encryption">
+ <ds:KeyInfo>
+ <ds:X509Data>
+ <ds:X509Certificate>MIIFEzCCAvugAwIBAgIUHrUCohPj1gunSezvCK7Ps+CtvZAwDQYJKoZIhvcNAQELBQAwGTEXMBUGA1UEAwwOc2F0b3NhX2JhY2tlbmQwHhcNMjMwNjE0MTQwNTQyWhcNMzMwNjExMTQwNTQyWjAZMRcwFQYDVQQDDA5zYXRvc2FfYmFja2VuZDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBAMUGa8dvaJAloGjIMVQ9creiCEF0gcSxMccaYL0FhpPkTjFWzsjlZveLoiMsA4U5KyuzUdgSM2uyunsHXqb+t62aB/iGALcPAREk1COhgOoqiGNgz4M1oOrvzpKE9U2ofRfZASFbKSMyhoCSHADRysRwBQW4+6o7ujX//B1lBOhGmzC8UJfMDo2IQ/3IZqBWY543MNn3q3mADkqUXXlewBLgcKAm+7pXTykxZ4FPbj8VxQDLjZB1rgLagjg7NfA30lR1AY02+0OJOZW2ujGL9M5NISZ6YI3klnIfVsxX+so+UHQEw+mgDHQMbesS8I0cZaNv+qAkqxzCUVqkFaeDWhFMr4a8bDyR9aStF78ps+74i5Zy22LR67OdlwkI9a75u5UAVsCBVmbQDgVopg8T037WcC/nPHH0qzWxJGQ80AQahm3LRhLU1cb7VsErtyFGaLi1eBRKscdwyS+D5KNa2RZb5pL5Rl8tZaLrC7IzfCxW8I9SgDad7QvLLbBjIUmtos4eyBK67EEw8GsDnzPH2Eoe24gfn0AmJg8i7nNl8Z2KL0ua0p68EJyXrQ9VCqSx23JpqGrebDmHgTN/zhdykY+gN/BtpNT1YhtAbemAXp4wGHjEn6i/wHUXe6tNEDvrY5idOBdrFB+Ek5hC9sJixvly1PkQCdxpB6FwksRImSRnAgMBAAGjUzBRMB0GA1UdDgQWBBTaFM4BlNXJUX6Ki+QtQnW/f0TcXDAfBgNVHSMEGDAWgBTaFM4BlNXJUX6Ki+QtQnW/f0TcXDAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4ICAQAV1rLNb6nUU0apKmtd/MdfYcVusw+0vlLSxFSFRsHPkIkPva03BY9Y8iVrK45dQcLEwTqiOjhUPikXgll6jFjw48Je8ENYJIFsQslOJbh/NqdYmutNYj/MCQHc7/mviGNJXpXRJmTHEjcmsPmpQMQPYRTV503yPyue2N9nGHyOzblZbKLQUK1Nw/tNdTgM1Y738B4CjXI0KpN//arQBNrMCWAHjLtNTyhz6qUiJKCK1p3vCBC/4DrKqs3Xk5i1ky1Uzoj/0VV+WIJVv/voHhRaxuMeJv0zSWb5IFgujfwZCIQlVU9yU5JWL3ju0oaBHtkclG3Kl5owRRjKKHwcI4/Xb7OMIkULyj82haTIXYf0UBfX7JWtvnDHiK2QP/Oh1tlWqLek6qTMxP/DC94HARBuGdD3jjNQ3IaONLchGXkCBHot4u+I5eOVJgl2E0U+AZYvga8pOB1cWS40BoMwpzXx6j4+W2G3Uvej+Ob09PtHzOtQ/ZSFUqro6499bAhAJSxY3u/q+Duxd4c82q4MMKFdZ0iHxKQjK5WBmce4cK1E5B7N9oKsTiZEgWH6EJmEiZQCXGXos/qPYqJIR1/Mvtuq0lloCkNW2hs3cLkUYZou8sToZY1LpRa57NY/5nDICcugysw93979rXZb7B1M053R53E+9KL/gxZQY6LvbyN1AA==</ds:X509Certificate>
+ </ds:X509Data>
+ </ds:KeyInfo>
+ </md:KeyDescriptor>
+ <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
+ <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://matrix-test-idp-proxy.sunet.se/Saml2SP/acs/post" index="1"/>
+ <md:AttributeConsumingService index="1">
+ <md:ServiceName xml:lang="en">CIRCL MISP</md:ServiceName>
+ <md:ServiceName xml:lang="sv">CIRCL MISP</md:ServiceName>
+ <md:RequestedAttribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ <md:RequestedAttribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+ </md:AttributeConsumingService>
+ </md:SPSSODescriptor>
+ <md:Organization>
+ <md:OrganizationName xml:lang="en">SUNET</md:OrganizationName>
+ <md:OrganizationName xml:lang="sv">Vetenskapsrådet</md:OrganizationName>
+ <md:OrganizationDisplayName xml:lang="en">SUNET</md:OrganizationDisplayName>
+ <md:OrganizationDisplayName xml:lang="sv">Sunet</md:OrganizationDisplayName>
+ <md:OrganizationURL xml:lang="en">https://sunet.se</md:OrganizationURL>
+ <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL>
+ </md:Organization>
+ <md:ContactPerson contactType="technical">
+ <md:GivenName>Technical</md:GivenName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="support">
+ <md:GivenName>Support</md:GivenName>
+ <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson contactType="administrative">
+ <md:GivenName>SUNET</md:GivenName>
+ <md:EmailAddress>mailto:info@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+ <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
+ <md:GivenName>Security Response Team</md:GivenName>
+ <md:EmailAddress>mailto:abuse@sunet.se</md:EmailAddress>
+ </md:ContactPerson>
+</md:EntityDescriptor>
diff --git a/metadata/swamid-sp-2.0.mxml b/metadata/swamid-sp-2.0.mxml
index 2a221d9e..60383063 100644
--- a/metadata/swamid-sp-2.0.mxml
+++ b/metadata/swamid-sp-2.0.mxml
@@ -221,6 +221,7 @@
<xi:include href="swamid-2.0/lu.test.instructure.com-saml2.xml"/>
<xi:include href="swamid-2.0/luvit.education.lu.se-shibboleth.xml"/>
<xi:include href="swamid-2.0/luvittest1.education.lu.se-shibboleth.xml"/>
+ <xi:include href="swamid-2.0/matrix-test-idp-proxy.sunet.se-sp.xml"/>
<xi:include href="swamid-2.0/mdu-graylog.cnaas.sunet.se.xml"/>
<xi:include href="swamid-2.0/mdu-nav.cnaas.sunet.se.xml"/>
<xi:include href="swamid-2.0/mdu-ni.cnaas.sunet.se.xml"/>