diff options
-rw-r--r-- | swamid-2.0/idp.ths.se-idp-shibboleth.xml | 92 |
1 files changed, 48 insertions, 44 deletions
diff --git a/swamid-2.0/idp.ths.se-idp-shibboleth.xml b/swamid-2.0/idp.ths.se-idp-shibboleth.xml index b841ced3..25a68080 100644 --- a/swamid-2.0/idp.ths.se-idp-shibboleth.xml +++ b/swamid-2.0/idp.ths.se-idp-shibboleth.xml @@ -9,10 +9,14 @@ <samla:AttributeValue>http://refeds.org/category/research-and-scholarship</samla:AttributeValue> <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue> </samla:Attribute> + <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <samla:AttributeValue>http://www.swamid.se/policy/assurance/al1</samla:AttributeValue> + <samla:AttributeValue>http://www.swamid.se/policy/assurance/al2</samla:AttributeValue> + </samla:Attribute> </mdattr:EntityAttributes> </md:Extensions> - <IDPSSODescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0" errorURL="https://idp.ths.se/idp/error/ERRORURL_CODE.html"> - <Extensions> + <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0" errorURL="https://idp.ths.se/idp/error/ERRORURL_CODE.html"> + <md:Extensions> <shibmd:Scope regexp="false">ths.se</shibmd:Scope> <shibmd:Scope regexp="false">ehs.se</shibmd:Scope> <mdui:UIInfo> @@ -22,8 +26,8 @@ <mdui:Description xml:lang="en">Identity Provider for University College Stockholm</mdui:Description> <mdui:Logo height="100" width="100">https://idp.ths.se/idp/images/ehs_100x100.png</mdui:Logo> </mdui:UIInfo> - </Extensions> - <KeyDescriptor use="signing"> + </md:Extensions> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -47,8 +51,8 @@ GPrwUbfYjDaDH2pZjUisQoVv15w0sWPt </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="signing"> + </md:KeyDescriptor> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -72,8 +76,8 @@ WvXwtq5B+PQLjb42BmhBA59C06dCNyiJdYcGt6eqPFaGizjdLH/QTQkeD5v8ik2k </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="encryption"> + </md:KeyDescriptor> + <md:KeyDescriptor use="encryption"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -97,21 +101,21 @@ xAdB19mh1plahNrAaEfu6Ldetyz9iulY </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ths.se:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/> - <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ths.se:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/> - <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat> - <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat> - <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.ths.se/idp/profile/Shibboleth/SSO"/> - <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.ths.se/idp/profile/SAML2/POST/SSO"/> - <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.ths.se/idp/profile/SAML2/Redirect/SSO"/> - </IDPSSODescriptor> - <AttributeAuthorityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol"> - <Extensions> + </md:KeyDescriptor> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ths.se:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ths.se:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/> + <md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat> + <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> + <md:SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.ths.se/idp/profile/Shibboleth/SSO"/> + <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.ths.se/idp/profile/SAML2/POST/SSO"/> + <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.ths.se/idp/profile/SAML2/Redirect/SSO"/> + </md:IDPSSODescriptor> + <md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol"> + <md:Extensions> <shibmd:Scope regexp="false">ths.se</shibmd:Scope> <shibmd:Scope regexp="false">ehs.se</shibmd:Scope> - </Extensions> - <KeyDescriptor use="signing"> + </md:Extensions> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -135,8 +139,8 @@ GPrwUbfYjDaDH2pZjUisQoVv15w0sWPt </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="signing"> + </md:KeyDescriptor> + <md:KeyDescriptor use="signing"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -160,8 +164,8 @@ WvXwtq5B+PQLjb42BmhBA59C06dCNyiJdYcGt6eqPFaGizjdLH/QTQkeD5v8ik2k </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="encryption"> + </md:KeyDescriptor> + <md:KeyDescriptor use="encryption"> <ds:KeyInfo> <ds:X509Data> <ds:X509Certificate> @@ -185,23 +189,23 @@ xAdB19mh1plahNrAaEfu6Ldetyz9iulY </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ths.se:8443/idp/profile/SAML1/SOAP/AttributeQuery"/> - </AttributeAuthorityDescriptor> - <Organization xmlns="urn:oasis:names:tc:SAML:2.0:metadata"> - <OrganizationName xml:lang="en">THS</OrganizationName> - <OrganizationDisplayName xml:lang="sv">Enskilda Högskolan Stockholm</OrganizationDisplayName> - <OrganizationDisplayName xml:lang="en">University College Stockholm</OrganizationDisplayName> - <OrganizationURL xml:lang="en">http://www.ths.se/english</OrganizationURL> - <OrganizationURL xml:lang="sv">http://www.ths.se</OrganizationURL> - </Organization> - <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="administrative"> - <GivenName>Owe</GivenName> - <SurName>Kennerberg</SurName> - <EmailAddress>mailto:owe.kennerberg@ths.se</EmailAddress> - </ContactPerson> - <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="technical"> - <GivenName>Support</GivenName> - <EmailAddress>mailto:support@ehs.se</EmailAddress> - </ContactPerson> + </md:KeyDescriptor> + <md:AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ths.se:8443/idp/profile/SAML1/SOAP/AttributeQuery"/> + </md:AttributeAuthorityDescriptor> + <md:Organization> + <md:OrganizationName xml:lang="en">THS</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="sv">Enskilda Högskolan Stockholm</md:OrganizationDisplayName> + <md:OrganizationDisplayName xml:lang="en">University College Stockholm</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="en">http://www.ths.se/english</md:OrganizationURL> + <md:OrganizationURL xml:lang="sv">http://www.ths.se</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="administrative"> + <md:GivenName>Owe</md:GivenName> + <md:SurName>Kennerberg</md:SurName> + <md:EmailAddress>mailto:owe.kennerberg@ths.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="technical"> + <md:GivenName>Support</md:GivenName> + <md:EmailAddress>mailto:support@ehs.se</md:EmailAddress> + </md:ContactPerson> </md:EntityDescriptor> |