diff options
-rw-r--r-- | swamid-2.0/vr-graylog.cnaas.sunet.se.xml | 122 | ||||
-rw-r--r-- | swamid-2.0/vr-nav.cnaas.sunet.se.xml | 122 | ||||
-rw-r--r-- | swamid-2.0/vr-ni.cnaas.sunet.se.xml | 122 | ||||
-rw-r--r-- | swamid-sp-2.0.mxml | 3 |
4 files changed, 369 insertions, 0 deletions
diff --git a/swamid-2.0/vr-graylog.cnaas.sunet.se.xml b/swamid-2.0/vr-graylog.cnaas.sunet.se.xml new file mode 100644 index 00000000..9d60095f --- /dev/null +++ b/swamid-2.0/vr-graylog.cnaas.sunet.se.xml @@ -0,0 +1,122 @@ +<?xml version="1.0" encoding="UTF-8"?> +<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://vr-graylog.cnaas.sunet.se"> + <md:Extensions> + <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2022-04-11T16:19:27Z"> + <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy> + </mdrpi:RegistrationInfo> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/> + <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"> + <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue> + </samla:Attribute> + </mdattr:EntityAttributes> + </md:Extensions> + <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> + <md:Extensions> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/DS/Login"/> + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/DS/Login" index="1"/> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="sv">CnaaS VR Graylog</mdui:DisplayName> + <mdui:DisplayName xml:lang="en">CnaaS VR Graylog</mdui:DisplayName> + <mdui:Description xml:lang="sv">Loggsystem för CnaaS på VR.</mdui:Description> + <mdui:Description xml:lang="en">Logging system for CnaaS at VR.</mdui:Description> + <mdui:InformationURL xml:lang="sv">https://www.graylog.org</mdui:InformationURL> + <mdui:InformationURL xml:lang="en">https://www.graylog.org</mdui:InformationURL> + <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+Graylog+when+using+federated+login</mdui:PrivacyStatementURL> + <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+Graylog+when+using+federated+login</mdui:PrivacyStatementURL> + </mdui:UIInfo> + </md:Extensions> + <md:KeyDescriptor> + <ds:KeyInfo> + <ds:KeyName>https://vr-graylog.cnaas.sunet.se</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=https://vr-graylog.cnaas.sunet.se</ds:X509SubjectName> + <ds:X509Certificate>MIIENTCCAp2gAwIBAgIUc+OWQ/HvMHq60VytGy8LurM8nsAwDQYJKoZIhvcNAQEL +BQAwLDEqMCgGA1UEAxMhaHR0cHM6Ly92ci1ncmF5bG9nLmNuYWFzLnN1bmV0LnNl +MB4XDTIyMDQxMTA4Mjc1MFoXDTMyMDQwODA4Mjc1MFowLDEqMCgGA1UEAxMhaHR0 +cHM6Ly92ci1ncmF5bG9nLmNuYWFzLnN1bmV0LnNlMIIBojANBgkqhkiG9w0BAQEF +AAOCAY8AMIIBigKCAYEAxUQNmSbDLJxjyMNiTXtuuBiJ2ZXiG4e306N3exjRGaft +Ozu3XbpDd8ctLD9bJ/Mq7XJjZwBOg4IBBwqtDqJan2tzjy0uuI3rYA+q0WpNEOre +5IdNa2DO2ZuD6BwGv4/V4aYYYd3fUfOhnpYnW+ouNysvD2B9g5fxG8K6Wi9mvMW1 +w6SNQlbOx5wXi9D8wbCO/YzCqNS9pbz7Ctv4VdzB49p/CuBvDUWD83zEyDzv1vAc +mrvMWEdpo0u5fos5O8zpn3bYyzuOyLPCBNQy5vXCg9zqOEhBy+DUpt7qzLGelyM4 +zSSsHcEnKqL3AHuF7OP1uBPrd2xbF52xodi4LktZE0gDEVznWsjepBWEI626JhYG +Dqt4wFsRfPucV1iP4ROGD/wK7zmHhm3ThHdb8PqvNIL4CKQeKBBef77kuoGT5L4V +5BLhihr7e/6rUFSDDwzP4+4Y2FdEeu/cKbZ6h7aLT87cgdNz1Y0L1M4h876E4PhL +PkGlqQiaF2rGdRhliO41AgMBAAGjTzBNMCwGA1UdEQQlMCOCIWh0dHBzOi8vdnIt +Z3JheWxvZy5jbmFhcy5zdW5ldC5zZTAdBgNVHQ4EFgQU/TH99+zMyvk/5KWzb1vS +0oJ+5L4wDQYJKoZIhvcNAQELBQADggGBAKEaUcToKkEfcgt+XASaOUKSxUI1xrEm +xSpTNI1J6S5sdaGge5UWdBwAbLnyoScwXJpynX/4vQGCGnq9hxmcTzHyaKd8pbYR +AoA97W8/RytVYpOgc+IabC4VzW1lXtkKR0tX9S2TuFuDaXl6rSyM4WV7DKRXXhXr +0OLf0gaFXxaqK0UuF0y3Tc21KMGja1u6K1flpUaCxbaJR5rEUNhEHc+PU0ltqxks +OlalzJLd2J5XT4JWfovkF7ZxHLEIHqSNzkSDizIWMucfweDgG6ZA6MMrUZZoAISN +Y0bzDNFTbM5Ic4M9jBqXpMRtLv/4gzM8iFCF3XRpPJuOJIWZFKaJHop1D7OZC67I +8cqdaNYI5WyhGCsvjDa32BWcyrkegDi79+Wt8qXaGCsItKnpIo9Aj/Sys3gCKDCZ +XSVWRG272Kd+EAB3DXH4RBBSItGTWFiGro5Rj72UxQ+Me6zaVVfmbTljEQNqw7Bd +k/NdOp8HphaQKtlQnK7oGfZdAZkhCMWQBg== +</ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> + </md:KeyDescriptor> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/Artifact/SOAP" index="1"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/SLO/SOAP"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/SLO/Redirect"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/SLO/POST"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/SLO/Artifact"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-graylog.cnaas.sunet.se/Shibboleth.sso/SAML2/POST" index="1"/> + <md:AttributeConsumingService index="1"> + <md:ServiceName xml:lang="sv">CnaaS VR Graylog</md:ServiceName> + <md:ServiceName xml:lang="en">CnaaS VR Graylog</md:ServiceName> + <md:RequestedAttribute FriendlyName="eduPersonAssurance" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + </md:AttributeConsumingService> + </md:SPSSODescriptor> + <md:Organization> + <md:OrganizationName xml:lang="sv">Sunet</md:OrganizationName> + <md:OrganizationName xml:lang="en">Sunet</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="en">Sunet</md:OrganizationDisplayName> + <md:OrganizationDisplayName xml:lang="sv">Sunet</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL> + <md:OrganizationURL xml:lang="en">https://www.sunet.se/en</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="technical"> + <md:GivenName>Sunet NOC</md:GivenName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="support"> + <md:GivenName>Sunet NOC</md:GivenName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security"> + <md:GivenName>Sunet NOC</md:GivenName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="administrative"> + <md:GivenName>Ernst Widerberg</md:GivenName> + <md:EmailAddress>mailto:ernst@sunet.se</md:EmailAddress> + </md:ContactPerson> +</md:EntityDescriptor> diff --git a/swamid-2.0/vr-nav.cnaas.sunet.se.xml b/swamid-2.0/vr-nav.cnaas.sunet.se.xml new file mode 100644 index 00000000..a9cee193 --- /dev/null +++ b/swamid-2.0/vr-nav.cnaas.sunet.se.xml @@ -0,0 +1,122 @@ +<?xml version="1.0" encoding="UTF-8"?> +<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://vr-nav.cnaas.sunet.se"> + <md:Extensions> + <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2022-04-11T16:19:27Z"> + <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy> + </mdrpi:RegistrationInfo> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/> + <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"> + <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue> + </samla:Attribute> + </mdattr:EntityAttributes> + </md:Extensions> + <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> + <md:Extensions> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/DS/Login"/> + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/DS/Login" index="1"/> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="sv">CnaaS VR NAV</mdui:DisplayName> + <mdui:DisplayName xml:lang="en">CnaaS VR NAV</mdui:DisplayName> + <mdui:Description xml:lang="sv">Nätverksövervakningssystem för CnaaS på VR.</mdui:Description> + <mdui:Description xml:lang="en">Network monitoring system for CnaaS at VR.</mdui:Description> + <mdui:InformationURL xml:lang="sv">https://nav.uninett.no</mdui:InformationURL> + <mdui:InformationURL xml:lang="en">https://nav.uninett.no</mdui:InformationURL> + <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+NAV+when+using+federated+login</mdui:PrivacyStatementURL> + <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+NAV+when+using+federated+login</mdui:PrivacyStatementURL> + </mdui:UIInfo> + </md:Extensions> + <md:KeyDescriptor> + <ds:KeyInfo> + <ds:KeyName>https://vr-nav.cnaas.sunet.se</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=https://vr-nav.cnaas.sunet.se</ds:X509SubjectName> + <ds:X509Certificate>MIIEKTCCApGgAwIBAgIUPJvDSw/6kkN19HuLaHc//PEwHRgwDQYJKoZIhvcNAQEL +BQAwKDEmMCQGA1UEAxMdaHR0cHM6Ly92ci1uYXYuY25hYXMuc3VuZXQuc2UwHhcN +MjIwNDExMDgzNjU3WhcNMzIwNDA4MDgzNjU3WjAoMSYwJAYDVQQDEx1odHRwczov +L3ZyLW5hdi5jbmFhcy5zdW5ldC5zZTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCC +AYoCggGBAMnGGaBocrpOyWQOU1s9uxGqmNR/nUMYg2RA6lRDeAa90NLO0ZZb7xaO +VJ2Z/piyey8c0eg0x6ZbzscOXN9iLMLotcv3iAOfmJIb11+XaTOWT9QXlBpooLBL +2SQuIHv0B+KcQDy8I+PbvKpXQhH4yV7eS61FX5+27M2oYcA7xurqxv1O6SOVSAxr +TWGpZ6zCu4hETQKRNdn74VTODMxHj8JLGZdbuv8CpwVAqMwhn9DN18Wx5qqmocx2 +radjrkT4NppHgpaZbDgmmwEBSaSyZHU6fBT4CcP5av6LImPpzCeSqz+8zPdpUH0/ +tuYpxc446GCC6Y4veFcHsLiQDGXqryiSOzlxSJad07QcnifR1VnWrnR5XVvN7eir +WTwxkyC5ZiBNMk+JORidcyWVlRcnpLtJ6PhXRWI6vGFnhAysHkcwBkPMC2iwv9Wy +yWYlAlBvR/7mB+eCoY/u+TFfBkCkaOElILpTwswlfUyh7UUzkCBf/5yEyyksedSG +/uyv4JW9tQIDAQABo0swSTAoBgNVHREEITAfgh1odHRwczovL3ZyLW5hdi5jbmFh +cy5zdW5ldC5zZTAdBgNVHQ4EFgQUgC0pSR5awu3XBFEOjrn72b24wggwDQYJKoZI +hvcNAQELBQADggGBAMM8/Winiri0dPikLF5i1BInCQ3L1HGpmQ/dHx+S/p4pvHDZ +rxARCKgpR1+x8DTrRmkXfm0SAo+REc1Lh+0IDsR2V5rtmuTzFUrurV4E4hTlkBfH +TmScQZ+9yxm2xnVmnrriVf75nhlbQ5JS5q0cPJJ0rsyAQ3fJRMrrOZMCGpsOaSeD +8jE77dG63B7lXZ9fjs7IH5QwawJBJFvNvNyyj6aP0VRU4yf1QWDVJQvlEtAgph53 +OMZ99tu3W1DxMsBWnwROe2UieHc6LicOLeQmzHOTQDy9R9k1M2x5hLCB/12BJaqm +81bnqv0gOuo0dkDSKyEk9HUNLdS0JdzTKzK6/saSZe5Fh1jvEDf5xVq9tF+nwJnO +zWuhvm/aPGyyG7H97A0vDFvJmTrRx+H/D9hZdaDLZn8MbjfVvLVA3KCzft/bJKHn +v6lGtuS06TpiAR+VqxrLpKOhx5zWHAqNFaEIWV3Ga2w7pCAr8i5WWystz1WibTLE +bctpP7CAUeaP0UPPrg== +</ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> + </md:KeyDescriptor> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/Artifact/SOAP" index="1"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/SLO/SOAP"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/SLO/Redirect"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/SLO/POST"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/SLO/Artifact"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-nav.cnaas.sunet.se/Shibboleth.sso/SAML2/POST" index="1"/> + <md:AttributeConsumingService index="1"> + <md:ServiceName xml:lang="sv">CnaaS VR NAV</md:ServiceName> + <md:ServiceName xml:lang="en">CnaaS VR NAV</md:ServiceName> + <md:RequestedAttribute FriendlyName="eduPersonAssurance" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + </md:AttributeConsumingService> + </md:SPSSODescriptor> + <md:Organization> + <md:OrganizationName xml:lang="sv">Sunet</md:OrganizationName> + <md:OrganizationName xml:lang="en">Sunet</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="en">Sunet</md:OrganizationDisplayName> + <md:OrganizationDisplayName xml:lang="sv">Sunet</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL> + <md:OrganizationURL xml:lang="en">https://www.sunet.se/en</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="technical"> + <md:GivenName>Sunet NOC</md:GivenName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="support"> + <md:GivenName>Sunet NOC</md:GivenName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security"> + <md:GivenName>Sunet NOC</md:GivenName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="administrative"> + <md:GivenName>Ernst Widerberg</md:GivenName> + <md:EmailAddress>mailto:ernst@sunet.se</md:EmailAddress> + </md:ContactPerson> +</md:EntityDescriptor> diff --git a/swamid-2.0/vr-ni.cnaas.sunet.se.xml b/swamid-2.0/vr-ni.cnaas.sunet.se.xml new file mode 100644 index 00000000..eb9e1aeb --- /dev/null +++ b/swamid-2.0/vr-ni.cnaas.sunet.se.xml @@ -0,0 +1,122 @@ +<?xml version="1.0" encoding="UTF-8"?> +<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://vr-ni.cnaas.sunet.se"> + <md:Extensions> + <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2022-04-11T16:19:28Z"> + <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy> + </mdrpi:RegistrationInfo> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/> + <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"> + <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue> + </samla:Attribute> + </mdattr:EntityAttributes> + </md:Extensions> + <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> + <md:Extensions> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/DS/Login"/> + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/DS/Login" index="1"/> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="sv">CnaaS VR NI</mdui:DisplayName> + <mdui:DisplayName xml:lang="en">CnaaS VR NI</mdui:DisplayName> + <mdui:Description xml:lang="sv">Inventariesystem för CnaaS på VR.</mdui:Description> + <mdui:Description xml:lang="en">Inventory system for CnaaS at VR.</mdui:Description> + <mdui:InformationURL xml:lang="sv">https://portal.nordu.net/display/NI/NORDUnet+Network+Inventory</mdui:InformationURL> + <mdui:InformationURL xml:lang="en">https://portal.nordu.net/display/NI/NORDUnet+Network+Inventory</mdui:InformationURL> + <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+NI+when+using+federated+login</mdui:PrivacyStatementURL> + <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/CNaaS/Transfer+of+personal+data+to+CnaaS+NI+when+using+federated+login</mdui:PrivacyStatementURL> + </mdui:UIInfo> + </md:Extensions> + <md:KeyDescriptor> + <ds:KeyInfo> + <ds:KeyName>https://vr-ni.cnaas.sunet.se</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=https://vr-ni.cnaas.sunet.se</ds:X509SubjectName> + <ds:X509Certificate>MIIEJjCCAo6gAwIBAgIUYWAjSMMdXQ1j4oqlWf/OUQLzwKMwDQYJKoZIhvcNAQEL +BQAwJzElMCMGA1UEAxMcaHR0cHM6Ly92ci1uaS5jbmFhcy5zdW5ldC5zZTAeFw0y +MjA0MTEwODQ1MDJaFw0zMjA0MDgwODQ1MDJaMCcxJTAjBgNVBAMTHGh0dHBzOi8v +dnItbmkuY25hYXMuc3VuZXQuc2UwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGK +AoIBgQDRLeAbIF0T2MeSZ8+hR92K2C/EaLU3i7PCrtqiT0z4QKj0E1o07dIB0YU7 +duzVseuk81FpdbhT3gqooj4NA+qLK7HM5X5rzk4fNoXFrytubNA62yXeTGpd//8B +bontiw/yfqH774CUMEbSxZeZ2dzgSo8ckERDiG2SG4F30v/jLMCqjDkQQDcF5Y2u +x45kF16BG3uZQv3M010ZrHedf0AM1BTCGndWfajCoMq9ouPsVsG+P0KMiGdiTzj+ +GQMkJJqfYmlUGNrLEeRuuVIHcvG3diSdkD5j2l3uMHE1Cd+ckVgoKw7VW7CJVBEO +HNyBGwA9RRcRRDrloi9qEs5hp2A/XDhPUeOdgmlwOzR3cKS0wpdvcdcyebeewKRm +8iL+O8Caq4yqDdYNxjXTstE6uZ8V0YWLGHeDxKyBpB/wIlAji1EAngwkzDF/HO4R +ZK/M7YeL72aWWsxTyEeUsP2+h7H+mf4ejQzfbvZycOKV6i/OiRaQYUHxEoL3ca3L +9DZV6icCAwEAAaNKMEgwJwYDVR0RBCAwHoIcaHR0cHM6Ly92ci1uaS5jbmFhcy5z +dW5ldC5zZTAdBgNVHQ4EFgQUI9v9bJZZ+puRHChav1gJNysYE8gwDQYJKoZIhvcN +AQELBQADggGBAHaivtnDowTbTwpzEg1LjbLpLTaFOKg4pgH6zQUB42RLocL1smZW +r3OW1cbBg6ilZicLtdTf+Ob9sxorrQjSDZwZwVpa+2lD8SKAF/geU1vNEmdwSKpf ++ZTw/p1dL7dpagTaDvurnHmdXYJhJN7FMmVMnKHaMM5Nwx7JiBZIle8dXhVo6WP6 +zATE3n8tY9br+nnpVWuBr3BpQnzTzQfFBwKaYTLUzJNwm2o2DbKJEYXmEfPB67CW +HjzPWh06MJp/NPClizEv9fwIGl2W52qT83sYVvHmb38DN8lfunfha9XxnUXGOx9o +4SCE0Rcw1JxqNEmi8TiLHwgzjei/I9KeS0vZAcLcXVyhyUCXQ4uiqzpddBEcY88g +aYy3zGthph1a6y4dCqMx6a5Jl8dt5K1nZ3TCzpE5VRHqf7xk2VwfIFTpkFsg723d +ox4VOB6xX60h7X4G/Olwmcks4VB2oc7ocGRz9+0fy85gqRLKsRv8Jh4dAA5B7bT9 +evNq8iUcag9HrQ== +</ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> + </md:KeyDescriptor> + <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/Artifact/SOAP" index="1"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/SLO/SOAP"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/SLO/Redirect"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/SLO/POST"/> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/SLO/Artifact"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://vr-ni.cnaas.sunet.se/Shibboleth.sso/SAML2/POST" index="1"/> + <md:AttributeConsumingService index="1"> + <md:ServiceName xml:lang="sv">CnaaS VR NI</md:ServiceName> + <md:ServiceName xml:lang="en">CnaaS VR NI</md:ServiceName> + <md:RequestedAttribute FriendlyName="eduPersonAssurance" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + </md:AttributeConsumingService> + </md:SPSSODescriptor> + <md:Organization> + <md:OrganizationName xml:lang="sv">Sunet</md:OrganizationName> + <md:OrganizationName xml:lang="en">Sunet</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="en">Sunet</md:OrganizationDisplayName> + <md:OrganizationDisplayName xml:lang="sv">Sunet</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="sv">https://www.sunet.se</md:OrganizationURL> + <md:OrganizationURL xml:lang="en">https://www.sunet.se/en</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="technical"> + <md:GivenName>Sunet NOC</md:GivenName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="support"> + <md:GivenName>Sunet NOC</md:GivenName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security"> + <md:GivenName>Sunet NOC</md:GivenName> + <md:EmailAddress>mailto:noc@sunet.se</md:EmailAddress> + </md:ContactPerson> + <md:ContactPerson contactType="administrative"> + <md:GivenName>Ernst Widerberg</md:GivenName> + <md:EmailAddress>mailto:ernst@sunet.se</md:EmailAddress> + </md:ContactPerson> +</md:EntityDescriptor> diff --git a/swamid-sp-2.0.mxml b/swamid-sp-2.0.mxml index 45ea2a7d..74d48457 100644 --- a/swamid-sp-2.0.mxml +++ b/swamid-sp-2.0.mxml @@ -710,4 +710,7 @@ <xi:include href="swamid-2.0/verify.sunet.se-shibboleth.xml"/> <xi:include href="swamid-2.0/test-examensansokan.portal.chalmers.se-ny.xml"/> <xi:include href="swamid-2.0/confluence-dev.its.umu.se-shibboleth.xml"/> + <xi:include href="swamid-2.0/vr-ni.cnaas.sunet.se.xml"/> + <xi:include href="swamid-2.0/vr-graylog.cnaas.sunet.se.xml"/> + <xi:include href="swamid-2.0/vr-nav.cnaas.sunet.se.xml"/> </md:EntitiesDescriptor> |