diff options
-rw-r--r-- | swamid-2.0/disp-ci.su.se-shibboleth.sso.xml | 94 | ||||
-rw-r--r-- | swamid-2.0/disp.su.se-shibboleth.sso.xml | 93 | ||||
-rw-r--r-- | swamid-sp-2.0.mxml | 2 |
3 files changed, 189 insertions, 0 deletions
diff --git a/swamid-2.0/disp-ci.su.se-shibboleth.sso.xml b/swamid-2.0/disp-ci.su.se-shibboleth.sso.xml new file mode 100644 index 00000000..99362c75 --- /dev/null +++ b/swamid-2.0/disp-ci.su.se-shibboleth.sso.xml @@ -0,0 +1,94 @@ +<?xml version="1.0" encoding="UTF-8"?> +<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://disp-ci.su.se/Shibboleth.sso"> + <md:Extensions> + <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/"> + <mdrpi:RegistrationPolicy xml:lang="en">https://www.sunet.se/wp-content/uploads/2016/08/SWAMID-Metadata-Registration-Practice-Statement-v2.pdf</mdrpi:RegistrationPolicy> + </mdrpi:RegistrationInfo> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/> + </md:Extensions> + <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> + <md:Extensions> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://disp-dev-app11.it.su.se/Shibboleth.sso/SWAMID"/> + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://disp-dev-app11.it.su.se/Shibboleth.sso/SWAMID" index="1"/> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://disp-dev-app11.it.su.se/Shibboleth.sso/WAYF/idp.it.su.se"/> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://disp-dev-app11.it.su.se/Shibboleth.sso/WAYF/idp-test.it.su.se"/> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="en">d-ISP</mdui:DisplayName> + <mdui:DisplayName xml:lang="sv">d-ISP</mdui:DisplayName> + <mdui:Description xml:lang="en">Individual study plans for doctoral students at Stockholm University</mdui:Description> + <mdui:Description xml:lang="sv">Individuella studieplaner för doktorander på Stockholms universitet</mdui:Description> + </mdui:UIInfo> + </md:Extensions> + <md:KeyDescriptor> + <ds:KeyInfo> + <ds:KeyName>disp-dev-app11.it.su.se</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=disp-dev-app11.it.su.se</ds:X509SubjectName> + <ds:X509Certificate>MIIEDDCCAnSgAwIBAgIJANWshIWGLnVOMA0GCSqGSIb3DQEBCwUAMCIxIDAeBgNV +BAMTF2Rpc3AtZGV2LWFwcDExLml0LnN1LnNlMB4XDTE5MDkzMDA4Mjk0N1oXDTI5 +MDkyNzA4Mjk0N1owIjEgMB4GA1UEAxMXZGlzcC1kZXYtYXBwMTEuaXQuc3Uuc2Uw +ggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQC723RnvF1I8f95vH2WHPca +q66Ik8RDS7QF8URHps4SRHVGnzVZ3ajA+wOUCLQnpdB9uXbFjbpXYGjBJofef0Yq +rQDsBbhlgBLW26N8nGBaW6srXHrMriTc8RBU6YLMFLdZvni9psAVAqFkJphGjW9b +F4v1O1MAybqaDGDeHNbVXNZvaQ3Ouf8j8fSRsNNcn16QTAA10S9F1ZqHCFwVpPh9 +e5BKH2k/J/BQWKPoe6cGqp0LttpYeVumcj5elQAhD3SUpRhuUocVY5xQ6KK4XHHI +eqIHJXGjjCL+gvcFJEol6PL5O7/PF1KlkUnipjZO+EIVqXD8YaGYoR71X8MypKGZ +FHgyy/l/geRS9GHzaviPTrVsOBzuRoaVyYKkqysuH4GHHHQtF4pppXRLep1dPUH4 +gAuFCkh5Nehx4AMdAVGlVluHJJ2LVc2I1/JaBwDAAqTJvyiYb4+Tt/Rvt2afDzRW +Go2i71LykYZnCASDoerG+O70Tv35TOKNlxbArs0ons8CAwEAAaNFMEMwIgYDVR0R +BBswGYIXZGlzcC1kZXYtYXBwMTEuaXQuc3Uuc2UwHQYDVR0OBBYEFHkXnaglp0yj +qsaq7zkgeANj+o1kMA0GCSqGSIb3DQEBCwUAA4IBgQBQ4ANJnsVQ0RUJbsn9b9Dn +NKDcPiWHVpmQanrxdiS3SWgQDnMYzkpeHJD4LjNQaxBnMefsekvsyfP5XjLBYLIA +oJpauxjB9JacpZtnCtK4CKIPrVtLoX6BSEdiOR+qAAoHSpEs4REA62oAaJ1FtsJ4 +w8J7NDaYoJ+j/iBC3xGbayoW3e8spupRNC04YG1nkilA204tKiPxV19nidvFqvtD +P66JrbGkGfqbdtu3brn//HTbGG40GBPoZX8yRryZ1wqrFg2iF4gwaog//QotROvX +r8fEpF5Ve/RBt1biQOWOoteMxsyYulpUgVlXmJVFWMVKe2LZ4afBbNdPmxPmFvFL +MG4Xdb+gwflwP2qurW6UiTdJIF8s3tUTnk5YW4XCVMu2WeOEWL/FSHgqMXwR2v0f +Ju3xhw0X2wgXtqPjXoFHDFhr0WOgE96d3RpYkdPUa++HZ+JoEkxawOtQGnueuXvv +0suQ9s3ztg3VoaVPG3yfc2Yn+9JZ8Zj9Ux2rZuwpCt4= +</ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> + </md:KeyDescriptor> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://disp-dev-app11.it.su.se/Shibboleth.sso/SLO/SOAP"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://disp-dev-app11.it.su.se/Shibboleth.sso/SLO/Redirect"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://disp-dev-app11.it.su.se/Shibboleth.sso/SLO/POST"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://disp-dev-app11.it.su.se/Shibboleth.sso/SLO/Artifact"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://disp-dev-app11.it.su.se/Shibboleth.sso/SAML2/POST" index="1"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://disp-dev-app11.it.su.se/Shibboleth.sso/SAML2/Artifact" index="3"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://disp-dev-app11.it.su.se/Shibboleth.sso/SAML2/ECP" index="4"/> + </md:SPSSODescriptor> + <md:Organization> + <md:OrganizationName xml:lang="en">SU</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="en">Stockholms Universitet</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="en">https://www.su.se</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="technical"> + <md:SurName>IT-avdelningen</md:SurName> + <md:EmailAddress>mailto:helpdesk@su.se</md:EmailAddress> + </md:ContactPerson> +</md:EntityDescriptor> diff --git a/swamid-2.0/disp.su.se-shibboleth.sso.xml b/swamid-2.0/disp.su.se-shibboleth.sso.xml new file mode 100644 index 00000000..0be002a1 --- /dev/null +++ b/swamid-2.0/disp.su.se-shibboleth.sso.xml @@ -0,0 +1,93 @@ +<?xml version="1.0" encoding="UTF-8"?> +<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://disp.su.se/Shibboleth.sso"> + <md:Extensions> + <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/"> + <mdrpi:RegistrationPolicy xml:lang="en">https://www.sunet.se/wp-content/uploads/2016/08/SWAMID-Metadata-Registration-Practice-Statement-v2.pdf</mdrpi:RegistrationPolicy> + </mdrpi:RegistrationInfo> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/> + </md:Extensions> + <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> + <md:Extensions> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://disp-prod-app01.it.su.se/Shibboleth.sso/SWAMID"/> + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://disp-prod-app01.it.su.se/Shibboleth.sso/SWAMID" index="1"/> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://disp-prod-app01.it.su.se/Shibboleth.sso/WAYF/idp.it.su.se"/> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="en">d-ISP</mdui:DisplayName> + <mdui:DisplayName xml:lang="sv">d-ISP</mdui:DisplayName> + <mdui:Description xml:lang="en">Individual study plans for doctoral students at Stockholm University</mdui:Description> + <mdui:Description xml:lang="sv">Individuella studieplaner för doktorander på Stockholms universitet</mdui:Description> + </mdui:UIInfo> + </md:Extensions> + <md:KeyDescriptor> + <ds:KeyInfo> + <ds:KeyName>disp-prod-app01.it.su.se</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=disp-prod-app01.it.su.se</ds:X509SubjectName> + <ds:X509Certificate>MIIEDzCCAnegAwIBAgIJALaYBzqlywMfMA0GCSqGSIb3DQEBCwUAMCMxITAfBgNV +BAMTGGRpc3AtcHJvZC1hcHAwMS5pdC5zdS5zZTAeFw0xOTExMjAxMzA4NDFaFw0y +OTExMTcxMzA4NDFaMCMxITAfBgNVBAMTGGRpc3AtcHJvZC1hcHAwMS5pdC5zdS5z +ZTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAMGJPoR4ZDlWvQH0s7qN ++9ofNZZylLhV6+Curg4sAJd5/+sii1ewDud33Itob1x7GpSlIMC9X+Aji4RUYCl0 +QGULq+fXq9BJyAbU81MlfFGKoOoCYxawLKx20saCbKErpvOvXbhAfpSPhjgr03RZ +znEGGzIpJ2Pf+nRn5HbqlQeGzbId9p2DXJRQ0fqQOAIJLyPT7PdXSJ7VhSSneNa9 +h8nWR4Vz53UMXYvwvW4fbtitiooChv9HkLvwlawF1sFFkIRBqIX1ke7cHly5RmfA +PAMijub+uehmeJdKAL9hZecU+JOnuH2UztZRqsjl0wu654U1akcR1Y3jZtTTus9p +nXIPxCnZEmGyBktiwn+0G244FOQTIs6we3hl60X0o6YdYL4KOzvJgAN5FcZqY4+I +uLpgwtgcU0FaS81vo23HGJT1fOS3YH9j3hhd7eNgJHr1AFHHt0P1rElVUsba0b0I +388sEtLbkHtxfeX/boixp8OAkaW90vM5Cmjfazas8t0PkQIDAQABo0YwRDAjBgNV +HREEHDAaghhkaXNwLXByb2QtYXBwMDEuaXQuc3Uuc2UwHQYDVR0OBBYEFDMVAeGb +Szgs0eoToLEWUCY6NK/8MA0GCSqGSIb3DQEBCwUAA4IBgQBD+OQPLh0EmEMRv1wA +ozbwblb6x3k4hBnr5Z8bumZVFc6MPu47om/csklq54a1ZKCi1sMmrQG2JmZiSOzf +ezPlNrnhMABe4OscVMhjlggu7LgaVkzr2nl29+hXK09lnbCma2nTL6gcXz3I2ezb +2moCG8aXC5y5TmdSu14MTTMt/vkAUoCXrM3jDSuUWl7Un32HCJCrw05i01CnoE/q +NLMBIfnJOYZLLI8Ik0KdQDjKn54ikUup1/DF5BH7SMQPAyijlA0/mv+wImXGqqBb +qE3TmsgroboQCNoXqP24pprY9deXLZFMaLly9zeIOJNr0C0+vcPm7igxeh8BVepM +RzYQnNH4Uit94t5daJCNjayag8FQDlLHAAidJ6qMcXOepbqzYr3KWOD2NHPdlfUP +f1VDftjb1NYsqqV06zANx5VGuOZlrsYsFieWQL2A0Ny0Y+HFISGIShdFp0P7QFin +5IOLEXUgBpDBwWn+3Tz0zusoEq1ZXKf/8xNLYyFjpCIoAmE= +</ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> + </md:KeyDescriptor> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://disp-prod-app01.it.su.se/Shibboleth.sso/SLO/SOAP"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://disp-prod-app01.it.su.se/Shibboleth.sso/SLO/Redirect"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://disp-prod-app01.it.su.se/Shibboleth.sso/SLO/POST"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://disp-prod-app01.it.su.se/Shibboleth.sso/SLO/Artifact"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://disp-prod-app01.it.su.se/Shibboleth.sso/SAML2/POST" index="1"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://disp-prod-app01.it.su.se/Shibboleth.sso/SAML2/Artifact" index="3"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://disp-prod-app01.it.su.se/Shibboleth.sso/SAML2/ECP" index="4"/> + </md:SPSSODescriptor> + <md:Organization> + <md:OrganizationName xml:lang="en">SU</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="en">Stockholms Universitet</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="en">https://www.su.se</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="technical"> + <md:SurName>IT-avdelningen</md:SurName> + <md:EmailAddress>mailto:helpdesk@su.se</md:EmailAddress> + </md:ContactPerson> +</md:EntityDescriptor> diff --git a/swamid-sp-2.0.mxml b/swamid-sp-2.0.mxml index d04484c5..ef5762d8 100644 --- a/swamid-sp-2.0.mxml +++ b/swamid-sp-2.0.mxml @@ -656,4 +656,6 @@ <xi:include href="swamid-2.0/lmdl756.cs.lth.se-shibboleth.xml"/> <xi:include href="swamid-2.0/sri-test.sunet.se-api-saml2-metadata.xml"/> <xi:include href="swamid-2.0/disp-dev.su.se-shibboleth.sso.xml"/> + <xi:include href="swamid-2.0/disp-ci.su.se-shibboleth.sso.xml"/> + <xi:include href="swamid-2.0/disp.su.se-shibboleth.sso.xml"/> </md:EntitiesDescriptor> |