summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorBjörn Mattsson <Bjorn.Mattsson@bth.se>2020-08-26 11:42:01 +0200
committerBjörn Mattsson <Bjorn.Mattsson@bth.se>2020-08-26 11:42:01 +0200
commitb6bfe70a6e6b41e866e93140b97ebd471ad194ae (patch)
tree31593e1df989eb7b8d089ef4335b927e9312af10
parent87513bc41a8ac6534994d26b0b34749ef888084d (diff)
Resolves SWAMID-3239
-rw-r--r--swamid-2.0/mailfilter.sunet.se-shibboleth.xml108
1 files changed, 47 insertions, 61 deletions
diff --git a/swamid-2.0/mailfilter.sunet.se-shibboleth.xml b/swamid-2.0/mailfilter.sunet.se-shibboleth.xml
index 15007782..464bcb44 100644
--- a/swamid-2.0/mailfilter.sunet.se-shibboleth.xml
+++ b/swamid-2.0/mailfilter.sunet.se-shibboleth.xml
@@ -10,72 +10,65 @@
<samla:AttributeValue>http://www.swamid.se/category/research-and-education</samla:AttributeValue>
</samla:Attribute>
</mdattr:EntityAttributes>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
+ <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
+ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
</md:Extensions>
<md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol">
<md:Extensions>
- <DiscoveryResponse xmlns="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://mailfilter.sunet.se/Shibboleth.sso/DS/ds.sunet.se" index="1"/>
- <DiscoveryResponse xmlns="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://mailfilter.sunet.se/Shibboleth.sso/DS/ds.swamid.se" index="1"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://mailfilter.sunet.se/Shibboleth.sso/Login/idp.nordu.net"/>
+ <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://mailfilter.sunet.se/Shibboleth.sso/DS/others"/>
+ <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://mailfilter.sunet.se/Shibboleth.sso/DS/others" index="1"/>
</md:Extensions>
- <md:KeyDescriptor use="signing">
+ <md:KeyDescriptor>
<ds:KeyInfo>
<ds:KeyName>mailfilter.sunet.se</ds:KeyName>
<ds:X509Data>
<ds:X509SubjectName>CN=mailfilter.sunet.se</ds:X509SubjectName>
- <ds:X509IssuerSerial>
- <ds:X509IssuerName>CN=mailfilter.sunet.se</ds:X509IssuerName>
- <ds:X509SerialNumber>11414469578012237281</ds:X509SerialNumber>
- </ds:X509IssuerSerial>
- <ds:X509Certificate>MIIDADCCAeigAwIBAgIJAJ5oV5rQ7B3hMA0GCSqGSIb3DQEBBQUAMB4xHDAaBgNV
-BAMTE21haWxmaWx0ZXIuc3VuZXQuc2UwHhcNMTAwODI2MTk0NDIyWhcNMjAwODIz
-MTk0NDIyWjAeMRwwGgYDVQQDExNtYWlsZmlsdGVyLnN1bmV0LnNlMIIBIjANBgkq
-hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuwGz7eWqtVCW3Be28I+IPpODVQDPQIwi
-chEFFSJdlkF7c9XN806yVAaGvsOrnNaFUTM5h/Gc4Hak1A0puoLI1aMkyeA0sMWb
-Mi6owbVDrjXGoD4gAoC9AIhqfj0NtE8zGlbGsL0dezM68NJwIt2C30U1rzOfUS53
-rngSTvleQK0lnd8I2Sys+msN6kP+4N64A3IBg6A2AVZtaadB6fJIoxQrQOhU3N1U
-AfaK8TcLaclVC5PfiwuJuiSLM0RgMy68B0Fht0V6lUpdiBoF5nU4sKAVYjZz+ZHo
-pi6sntIe+FchSvmDXf7zqqLS/NQiM+bD65T/nvazAbtBIbKmWb817wIDAQABo0Ew
-PzAeBgNVHREEFzAVghNtYWlsZmlsdGVyLnN1bmV0LnNlMB0GA1UdDgQWBBQ+3/bs
-Sg4SKO4FCGqYge9BF2au7TANBgkqhkiG9w0BAQUFAAOCAQEAVxV3i2vePzZeSjyy
-/i7KiU62byrG6YVBpUnmuofRuNtrC0pvnEMlGYI93pqOuQOe0sw5CEweIIyeTfQ2
-7AlQPA3kiIyvG1mubSJH421oJWXt1GJD/RRH56uJtGUzOykEC350lwcQ3chnQauO
-TJuwybaXhBX3CiHaq2aUt4rLRCiY4q3i2n0x/K5h3YajaI1I/6kSmA/2i6N7kUM3
-ywk5dDSfqTd62MTtqC8hJXQj0pQlQ/9GBeoyE83uTSrPR+Fo3bcGPu6WPs3FeQY5
-EeerFHSYV6H0U7y47ZJcBMX2n4xZXMZbTYTlX1AHOYiU3y7I/ZCvSuZScFBK5Lk/
-KHCx/w==
-</ds:X509Certificate>
- </ds:X509Data>
- </ds:KeyInfo>
- </md:KeyDescriptor>
- <md:KeyDescriptor use="encryption">
- <ds:KeyInfo>
- <ds:KeyName>mailfilter.sunet.se</ds:KeyName>
- <ds:X509Data>
- <ds:X509SubjectName>CN=mailfilter.sunet.se</ds:X509SubjectName>
- <ds:X509IssuerSerial>
- <ds:X509IssuerName>CN=mailfilter.sunet.se</ds:X509IssuerName>
- <ds:X509SerialNumber>11414469578012237281</ds:X509SerialNumber>
- </ds:X509IssuerSerial>
- <ds:X509Certificate>MIIDADCCAeigAwIBAgIJAJ5oV5rQ7B3hMA0GCSqGSIb3DQEBBQUAMB4xHDAaBgNV
-BAMTE21haWxmaWx0ZXIuc3VuZXQuc2UwHhcNMTAwODI2MTk0NDIyWhcNMjAwODIz
-MTk0NDIyWjAeMRwwGgYDVQQDExNtYWlsZmlsdGVyLnN1bmV0LnNlMIIBIjANBgkq
-hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuwGz7eWqtVCW3Be28I+IPpODVQDPQIwi
-chEFFSJdlkF7c9XN806yVAaGvsOrnNaFUTM5h/Gc4Hak1A0puoLI1aMkyeA0sMWb
-Mi6owbVDrjXGoD4gAoC9AIhqfj0NtE8zGlbGsL0dezM68NJwIt2C30U1rzOfUS53
-rngSTvleQK0lnd8I2Sys+msN6kP+4N64A3IBg6A2AVZtaadB6fJIoxQrQOhU3N1U
-AfaK8TcLaclVC5PfiwuJuiSLM0RgMy68B0Fht0V6lUpdiBoF5nU4sKAVYjZz+ZHo
-pi6sntIe+FchSvmDXf7zqqLS/NQiM+bD65T/nvazAbtBIbKmWb817wIDAQABo0Ew
-PzAeBgNVHREEFzAVghNtYWlsZmlsdGVyLnN1bmV0LnNlMB0GA1UdDgQWBBQ+3/bs
-Sg4SKO4FCGqYge9BF2au7TANBgkqhkiG9w0BAQUFAAOCAQEAVxV3i2vePzZeSjyy
-/i7KiU62byrG6YVBpUnmuofRuNtrC0pvnEMlGYI93pqOuQOe0sw5CEweIIyeTfQ2
-7AlQPA3kiIyvG1mubSJH421oJWXt1GJD/RRH56uJtGUzOykEC350lwcQ3chnQauO
-TJuwybaXhBX3CiHaq2aUt4rLRCiY4q3i2n0x/K5h3YajaI1I/6kSmA/2i6N7kUM3
-ywk5dDSfqTd62MTtqC8hJXQj0pQlQ/9GBeoyE83uTSrPR+Fo3bcGPu6WPs3FeQY5
-EeerFHSYV6H0U7y47ZJcBMX2n4xZXMZbTYTlX1AHOYiU3y7I/ZCvSuZScFBK5Lk/
-KHCx/w==
+ <ds:X509Certificate>MIIDADCCAeigAwIBAgIJAIBoQ2cW2CZDMA0GCSqGSIb3DQEBBQUAMB4xHDAaBgNV
+BAMTE21haWxmaWx0ZXIuc3VuZXQuc2UwHhcNMjAwODI2MDkwNjM4WhcNMzAwODI0
+MDkwNjM4WjAeMRwwGgYDVQQDExNtYWlsZmlsdGVyLnN1bmV0LnNlMIIBIjANBgkq
+hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAuILSN55P/Iy5hQXLIsztrs9H4Jpd7Cw/
+rlmusSgkMYCmoCwhi5rHXMQKm5S/zZo362NkkOtEJOmNGsLgNLCflc2OjQghgD+N
+3yZWrwZY864j6Sk+XWC8u2lUfnFkimhXVTh5ZtP+9Z1LjoHJX1mVjIVj3WxUqEJE
+jgUHQhLq5DPXsoZziOrV2UKv927DyDpruBgf+WeWFFSHtL+ySszhZhb764lyGawT
+4Ci5aDYSEeYxQ9NH2K3YMx7uZYktTpPicznhafiLtJMqh2JAvV+RyEnucwYIbXs5
+Mh+ff2xM4AbRyBbP+IQQZC7GrM8t6R/zhJk/H7e5UuLZ6RxnDMxv2QIDAQABo0Ew
+PzAeBgNVHREEFzAVghNtYWlsZmlsdGVyLnN1bmV0LnNlMB0GA1UdDgQWBBS8DUk0
+61ugkmQZ6sc0c1HhNU6q+jANBgkqhkiG9w0BAQUFAAOCAQEAMv/zLzNCV9mCqYbl
+2UUA8+t7dL0WD6xwO6nVJ44v4L/Tt9A96lGdGXU64sFtdOpVnMmTPpGDBIXf6+B8
+ekUM0D/hibft4r/sV9+Er5xe4e4T+DjFFwQ1+n2gdv3479esjW4Qsq53YfC7a6mt
+6rtDT3F/fULCyCrd5ztjdDsxoQPpUuO4498ir+iJb2tmWpS7vMHrwKRKpR70Pm46
+sZ6Np0a+1IXRLJRfILZhaqW1195LOut4YockawY1cfBh14O5o3A/LXbDNFP3pJwv
+5jMtqXyBpgtmO1FQAKIKKfOTtqM1XiUfUpK46zLDO0ngnnsyYsT+eKHPfDgHa+Zk
+vI2YhQ==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
+ <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
</md:KeyDescriptor>
+ <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://mailfilter.sunet.se/Shibboleth.sso/Artifact/SOAP" index="1"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://mailfilter.sunet.se/Shibboleth.sso/SLO/SOAP"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://mailfilter.sunet.se/Shibboleth.sso/SLO/Redirect"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://mailfilter.sunet.se/Shibboleth.sso/SLO/POST"/>
@@ -90,12 +83,5 @@ KHCx/w==
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://mailfilter.sunet.se/Shibboleth.sso/SAML2/ECP" index="4"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://mailfilter.sunet.se/Shibboleth.sso/SAML/POST" index="5"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://mailfilter.sunet.se/Shibboleth.sso/SAML/Artifact" index="6"/>
- <md:AttributeConsumingService index="0">
- <md:ServiceName xml:lang="en">SUNET Mailfilter Service</md:ServiceName>
- <md:ServiceDescription xml:lang="en">SUNET Mailfilter Service</md:ServiceDescription>
- <md:RequestedAttribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:0.9.2342.19200300.100.1.3"/>
- <md:RequestedAttribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:2.5.4.42"/>
- <md:RequestedAttribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6"/>
- </md:AttributeConsumingService>
</md:SPSSODescriptor>
</md:EntityDescriptor>