diff options
Diffstat (limited to 'swamid-interfederations-2.0/gidp.geant.net.xml')
-rw-r--r-- | swamid-interfederations-2.0/gidp.geant.net.xml | 130 |
1 files changed, 38 insertions, 92 deletions
diff --git a/swamid-interfederations-2.0/gidp.geant.net.xml b/swamid-interfederations-2.0/gidp.geant.net.xml index 6db4290b..7eb2b294 100644 --- a/swamid-interfederations-2.0/gidp.geant.net.xml +++ b/swamid-interfederations-2.0/gidp.geant.net.xml @@ -1,102 +1,48 @@ <?xml version="1.0" encoding="UTF-8"?> -<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://gidp.geant.net"> - <!-- - This is a "GEANT Identity Provider" simpleSAMLphp IdP for Delivery of Advanced Network Technology to Europe Limited. - --> - <Extensions> - <mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="http://ukfederation.org.uk" registrationInstant="2014-05-14T11:50:00Z"> - <mdrpi:RegistrationPolicy xml:lang="en">http://ukfederation.org.uk/doc/mdrps-20130902</mdrpi:RegistrationPolicy> +<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://gidp.geant.net/sp/module.php/saml/sp/metadata.php/default-sp"> + <md:Extensions> + <mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="http://www.swamid.se/"> + <mdrpi:RegistrationPolicy xml:lang="en">http://www.swamid.se/download/18.248ad5af12aa8136533800012293/SWAMID+Metadata+Registration+Practice+Statement-20110714.pdf</mdrpi:RegistrationPolicy> </mdrpi:RegistrationInfo> - </Extensions> - <IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> - <Extensions> - <shibmd:Scope xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" regexp="false">gidp.geant.net</shibmd:Scope> - <mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui"> - <mdui:DisplayName xml:lang="en">GEANT Identity Provider</mdui:DisplayName> - <mdui:Logo height="69" width="199">https://www.edugain.org/GIdP.png</mdui:Logo> - </mdui:UIInfo> - </Extensions> - <KeyDescriptor use="signing"> + </md:Extensions> + <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"> + <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> - <ds:X509Certificate> - MIIEkzCCA3ugAwIBAgIRAMu+xHPPachtpqZqP5LsTqswDQYJKoZIhvcNAQEFBQAw - NjELMAkGA1UEBhMCTkwxDzANBgNVBAoTBlRFUkVOQTEWMBQGA1UEAxMNVEVSRU5B - IFNTTCBDQTAeFw0xMzEyMTMwMDAwMDBaFw0xNjEyMTIyMzU5NTlaMDwxITAfBgNV - BAsTGERvbWFpbiBDb250cm9sIFZhbGlkYXRlZDEXMBUGA1UEAxMOZ2lkcC5nZWFu - dC5uZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDGyGX8egmFqg1S - BpnwdMh7Gwco3avst57R/6TTgnGeajqjk5q7E6kzT33UHXG37kXJehuA2NBIhwoo - S8vBpMfsdhgj1ta98d9VdpjM84vJI8qj5zdOV1t+rQ1RejXxla5Fp0Rpj7BoKFye - WQ/vKrdk/G9rhpZS8DiIKqmNtkakxigm9aGse5r3zaYE6rb2Pb7VXBGkEVq96s5v - Z/iN6eGWfGy28XopRKboHpjVdR/AkyMARfFd1qLtGh3OddXykKgkwbKfYY3sKUYK - rqoeq1J6vF3KYYc1WlHuldnW0X+YjskiwX40USuZklxbv2mXublmhk1H5IgN7F2D - X8jJ124bAgMBAAGjggGUMIIBkDAfBgNVHSMEGDAWgBQMvZNoDPPeq6NJays3V0fq - kOO57TAdBgNVHQ4EFgQUCsQex91m+Wk7E+C4/38Sf3T80yAwDgYDVR0PAQH/BAQD - AgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMC - MCIGA1UdIAQbMBkwDQYLKwYBBAGyMQECAh0wCAYGZ4EMAQIBMDoGA1UdHwQzMDEw - L6AtoCuGKWh0dHA6Ly9jcmwudGNzLnRlcmVuYS5vcmcvVEVSRU5BU1NMQ0EuY3Js - MG0GCCsGAQUFBwEBBGEwXzA1BggrBgEFBQcwAoYpaHR0cDovL2NydC50Y3MudGVy - ZW5hLm9yZy9URVJFTkFTU0xDQS5jcnQwJgYIKwYBBQUHMAGGGmh0dHA6Ly9vY3Nw - LnRjcy50ZXJlbmEub3JnMEIGA1UdEQQ7MDmCDmdpZHAuZ2VhbnQubmV0ghNwcm9k - LWdpZHAuZ2VhbnQubmV0ghJ1YXQtZ2lkcC5nZWFudC5uZXQwDQYJKoZIhvcNAQEF - BQADggEBAB3iJ9REvIWq6OkRaiGMBN5wrH8RY0QulseOufbf7Cclx58+Y5hqf+bZ - 1gNQQfGQB8wFw2HaHg/X7RyHA6GRPgjz2w6hLQqI5aWdoKpF26jSbfnQ0Ia+Ko6J - 9JTawaCJzEqDOYO0vfdK19sOtouZoMpFyj5IGKUhJQfnXl4IxRAKbxOsdmZnlKfC - MHfKZ3Hkd137e5Vl6PPCD1SgKKyxklGL7kvUJLaI5H+fmyUZhYdLkabuViam16ok - ulsPPNORMXuSAaPbctgKJYdjK3D608c8SiZpm3hV/XBMYgDBb5NBTq3UZBbUsYRm - dDPF827oNvkbCcANbb1YmRBmFHWFe+E= - </ds:X509Certificate> + <ds:X509Certificate>MIIFUzCCBDugAwIBAgIRAOipFX0RJIRenc077AEf/TMwDQYJKoZIhvcNAQEFBQAwNjELMAkGA1UEBhMCTkwxDzANBgNVBAoTBlRFUkVOQTEWMBQGA1UEAxMNVEVSRU5BIFNTTCBDQTAeFw0xMDEyMjIwMDAwMDBaFw0xMzEyMjEyMzU5NTlaMIHwMRswGQYDVQQDExJ3d3cuZ2lkcC5nZWFudC5uZXQxHDAaBgNVBAMTE2lkcDIuZ2lkcC5nZWFudC5uZXQxHDAaBgNVBAMTE2lkcDEuZ2lkcC5nZWFudC5uZXQxCzAJBgNVBAYTAkdCMRcwFQYDVQQIEw5DYW1icmlkZ2VzaGlyZTESMBAGA1UEBxMJQ2FtYnJpZGdlMUIwQAYDVQQKEzlEZWxpdmVyeSBvZiBBZHZhbmNlZCBOZXR3b3JrIFRlY2hub2xvZ3kgdG8gRXVyb3BlIExpbWl0ZWQxFzAVBgNVBAMTDmdpZHAuZ2VhbnQubmV0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxshl/HoJhaoNUgaZ8HTIexsHKN2r7Lee0f+k04Jxnmo6o5OauxOpM0991B1xt+5FyXobgNjQSIcKKEvLwaTH7HYYI9bWvfHfVXaYzPOLySPKo+c3Tldbfq0NUXo18ZWuRadEaY+waChcnlkP7yq3ZPxva4aWUvA4iCqpjbZGpMYoJvWhrHua982mBOq29j2+1VwRpBFaverOb2f4jenhlnxstvF6KUSm6B6Y1XUfwJMjAEXxXdai7RodznXV8pCoJMGyn2GN7ClGCq6qHqtSerxdymGHNVpR7pXZ1tF/mI7JIsF+NFErmZJcW79pl7m5ZoZNR+SIDexdg1/IydduGwIDAQABo4IBnzCCAZswHwYDVR0jBBgwFoAUDL2TaAzz3qujSWsrN1dH6pDjue0wHQYDVR0OBBYEFArEHsfdZvlpOxPguP9/En90/NMgMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAYBgNVHSAEETAPMA0GCysGAQQBsjEBAgIdMDoGA1UdHwQzMDEwL6AtoCuGKWh0dHA6Ly9jcmwudGNzLnRlcmVuYS5vcmcvVEVSRU5BU1NMQ0EuY3JsMG0GCCsGAQUFBwEBBGEwXzA1BggrBgEFBQcwAoYpaHR0cDovL2NydC50Y3MudGVyZW5hLm9yZy9URVJFTkFTU0xDQS5jcnQwJgYIKwYBBQUHMAGGGmh0dHA6Ly9vY3NwLnRjcy50ZXJlbmEub3JnMFcGA1UdEQRQME6CDmdpZHAuZ2VhbnQubmV0ghNpZHAxLmdpZHAuZ2VhbnQubmV0ghNpZHAyLmdpZHAuZ2VhbnQubmV0ghJ3d3cuZ2lkcC5nZWFudC5uZXQwDQYJKoZIhvcNAQEFBQADggEBAH56nltzImiMVOv5DJxcTo2cpGBWPO+OI7S1Ns76cS6PzWbkm/zjPPZI871Pfgw6n3Q3V3Kpc48hRyx3WPH/9nk+YnFEUjkjaRCzeWR6A2oYSb83iI2n/33+E2AmyZ1FX5E1nfxRtSBLYyHPdXYQ6A/TN4qtm/9QHrbcISPEQJwvJn4/BOQDrvsjZDJeq7Srrr2An//RpNdC9cA4wU+m0oJPbPHGl32ENO6JVK7gJPYw2WBDER1SMwAEThtUthQyZhp1z6jA/hoeHfM4QR2/mT458LpRXs1c5VGAeC+4pjfJ4skXAU17Nq+ut8+fJMjjQSXOpv10kS2jNq2XfPmN+K4=</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="encryption"> + </md:KeyDescriptor> + <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> - <ds:X509Certificate> - MIIEkzCCA3ugAwIBAgIRAMu+xHPPachtpqZqP5LsTqswDQYJKoZIhvcNAQEFBQAw - NjELMAkGA1UEBhMCTkwxDzANBgNVBAoTBlRFUkVOQTEWMBQGA1UEAxMNVEVSRU5B - IFNTTCBDQTAeFw0xMzEyMTMwMDAwMDBaFw0xNjEyMTIyMzU5NTlaMDwxITAfBgNV - BAsTGERvbWFpbiBDb250cm9sIFZhbGlkYXRlZDEXMBUGA1UEAxMOZ2lkcC5nZWFu - dC5uZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDGyGX8egmFqg1S - BpnwdMh7Gwco3avst57R/6TTgnGeajqjk5q7E6kzT33UHXG37kXJehuA2NBIhwoo - S8vBpMfsdhgj1ta98d9VdpjM84vJI8qj5zdOV1t+rQ1RejXxla5Fp0Rpj7BoKFye - WQ/vKrdk/G9rhpZS8DiIKqmNtkakxigm9aGse5r3zaYE6rb2Pb7VXBGkEVq96s5v - Z/iN6eGWfGy28XopRKboHpjVdR/AkyMARfFd1qLtGh3OddXykKgkwbKfYY3sKUYK - rqoeq1J6vF3KYYc1WlHuldnW0X+YjskiwX40USuZklxbv2mXublmhk1H5IgN7F2D - X8jJ124bAgMBAAGjggGUMIIBkDAfBgNVHSMEGDAWgBQMvZNoDPPeq6NJays3V0fq - kOO57TAdBgNVHQ4EFgQUCsQex91m+Wk7E+C4/38Sf3T80yAwDgYDVR0PAQH/BAQD - AgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMC - MCIGA1UdIAQbMBkwDQYLKwYBBAGyMQECAh0wCAYGZ4EMAQIBMDoGA1UdHwQzMDEw - L6AtoCuGKWh0dHA6Ly9jcmwudGNzLnRlcmVuYS5vcmcvVEVSRU5BU1NMQ0EuY3Js - MG0GCCsGAQUFBwEBBGEwXzA1BggrBgEFBQcwAoYpaHR0cDovL2NydC50Y3MudGVy - ZW5hLm9yZy9URVJFTkFTU0xDQS5jcnQwJgYIKwYBBQUHMAGGGmh0dHA6Ly9vY3Nw - LnRjcy50ZXJlbmEub3JnMEIGA1UdEQQ7MDmCDmdpZHAuZ2VhbnQubmV0ghNwcm9k - LWdpZHAuZ2VhbnQubmV0ghJ1YXQtZ2lkcC5nZWFudC5uZXQwDQYJKoZIhvcNAQEF - BQADggEBAB3iJ9REvIWq6OkRaiGMBN5wrH8RY0QulseOufbf7Cclx58+Y5hqf+bZ - 1gNQQfGQB8wFw2HaHg/X7RyHA6GRPgjz2w6hLQqI5aWdoKpF26jSbfnQ0Ia+Ko6J - 9JTawaCJzEqDOYO0vfdK19sOtouZoMpFyj5IGKUhJQfnXl4IxRAKbxOsdmZnlKfC - MHfKZ3Hkd137e5Vl6PPCD1SgKKyxklGL7kvUJLaI5H+fmyUZhYdLkabuViam16ok - ulsPPNORMXuSAaPbctgKJYdjK3D608c8SiZpm3hV/XBMYgDBb5NBTq3UZBbUsYRm - dDPF827oNvkbCcANbb1YmRBmFHWFe+E= - </ds:X509Certificate> + <ds:X509Certificate>MIIFUzCCBDugAwIBAgIRAOipFX0RJIRenc077AEf/TMwDQYJKoZIhvcNAQEFBQAwNjELMAkGA1UEBhMCTkwxDzANBgNVBAoTBlRFUkVOQTEWMBQGA1UEAxMNVEVSRU5BIFNTTCBDQTAeFw0xMDEyMjIwMDAwMDBaFw0xMzEyMjEyMzU5NTlaMIHwMRswGQYDVQQDExJ3d3cuZ2lkcC5nZWFudC5uZXQxHDAaBgNVBAMTE2lkcDIuZ2lkcC5nZWFudC5uZXQxHDAaBgNVBAMTE2lkcDEuZ2lkcC5nZWFudC5uZXQxCzAJBgNVBAYTAkdCMRcwFQYDVQQIEw5DYW1icmlkZ2VzaGlyZTESMBAGA1UEBxMJQ2FtYnJpZGdlMUIwQAYDVQQKEzlEZWxpdmVyeSBvZiBBZHZhbmNlZCBOZXR3b3JrIFRlY2hub2xvZ3kgdG8gRXVyb3BlIExpbWl0ZWQxFzAVBgNVBAMTDmdpZHAuZ2VhbnQubmV0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAxshl/HoJhaoNUgaZ8HTIexsHKN2r7Lee0f+k04Jxnmo6o5OauxOpM0991B1xt+5FyXobgNjQSIcKKEvLwaTH7HYYI9bWvfHfVXaYzPOLySPKo+c3Tldbfq0NUXo18ZWuRadEaY+waChcnlkP7yq3ZPxva4aWUvA4iCqpjbZGpMYoJvWhrHua982mBOq29j2+1VwRpBFaverOb2f4jenhlnxstvF6KUSm6B6Y1XUfwJMjAEXxXdai7RodznXV8pCoJMGyn2GN7ClGCq6qHqtSerxdymGHNVpR7pXZ1tF/mI7JIsF+NFErmZJcW79pl7m5ZoZNR+SIDexdg1/IydduGwIDAQABo4IBnzCCAZswHwYDVR0jBBgwFoAUDL2TaAzz3qujSWsrN1dH6pDjue0wHQYDVR0OBBYEFArEHsfdZvlpOxPguP9/En90/NMgMA4GA1UdDwEB/wQEAwIFoDAMBgNVHRMBAf8EAjAAMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEFBQcDAjAYBgNVHSAEETAPMA0GCysGAQQBsjEBAgIdMDoGA1UdHwQzMDEwL6AtoCuGKWh0dHA6Ly9jcmwudGNzLnRlcmVuYS5vcmcvVEVSRU5BU1NMQ0EuY3JsMG0GCCsGAQUFBwEBBGEwXzA1BggrBgEFBQcwAoYpaHR0cDovL2NydC50Y3MudGVyZW5hLm9yZy9URVJFTkFTU0xDQS5jcnQwJgYIKwYBBQUHMAGGGmh0dHA6Ly9vY3NwLnRjcy50ZXJlbmEub3JnMFcGA1UdEQRQME6CDmdpZHAuZ2VhbnQubmV0ghNpZHAxLmdpZHAuZ2VhbnQubmV0ghNpZHAyLmdpZHAuZ2VhbnQubmV0ghJ3d3cuZ2lkcC5nZWFudC5uZXQwDQYJKoZIhvcNAQEFBQADggEBAH56nltzImiMVOv5DJxcTo2cpGBWPO+OI7S1Ns76cS6PzWbkm/zjPPZI871Pfgw6n3Q3V3Kpc48hRyx3WPH/9nk+YnFEUjkjaRCzeWR6A2oYSb83iI2n/33+E2AmyZ1FX5E1nfxRtSBLYyHPdXYQ6A/TN4qtm/9QHrbcISPEQJwvJn4/BOQDrvsjZDJeq7Srrr2An//RpNdC9cA4wU+m0oJPbPHGl32ENO6JVK7gJPYw2WBDER1SMwAEThtUthQyZhp1z6jA/hoeHfM4QR2/mT458LpRXs1c5VGAeC+4pjfJ4skXAU17Nq+ut8+fJMjjQSXOpv10kS2jNq2XfPmN+K4=</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> - </KeyDescriptor> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://gidp.geant.net/simplesamlphp/saml2/idp/SingleLogoutService.php"/> - <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat> - <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://gidp.geant.net/simplesamlphp/saml2/idp/SSOService.php"/> - </IDPSSODescriptor> - <Organization> - <OrganizationName xml:lang="en">Delivery of Advanced Network Technology to Europe Limited</OrganizationName> - <OrganizationDisplayName xml:lang="en">GEANT Identity Provider</OrganizationDisplayName> - <OrganizationURL xml:lang="en">http://www.geant.net/</OrganizationURL> - </Organization> - <ContactPerson contactType="support"> - <GivenName>eduGAIN OT</GivenName> - <EmailAddress>mailto:edugain-ot@geant.net</EmailAddress> - </ContactPerson> - <ContactPerson contactType="technical"> - <GivenName>eduGAIN OT</GivenName> - <EmailAddress>mailto:edugain-ot@geant.net</EmailAddress> - </ContactPerson> -</EntityDescriptor> + </md:KeyDescriptor> + <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://gidp.geant.net/sp/module.php/saml/sp/saml2-logout.php/default-sp"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://gidp.geant.net/sp/module.php/saml/sp/saml2-acs.php/default-sp" index="0"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://gidp.geant.net/sp/module.php/saml/sp/saml1-acs.php/default-sp" index="1"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://gidp.geant.net/sp/module.php/saml/sp/saml2-acs.php/default-sp" index="2"/> + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://gidp.geant.net/sp/module.php/saml/sp/saml1-acs.php/default-sp/artifact" index="3"/> + <md:AttributeConsumingService index="0"> + <md:ServiceName xml:lang="en">GEANT SP Proxy</md:ServiceName> + <md:RequestedAttribute FriendlyName="email" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:RequestedAttribute FriendlyName="eduPersonAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="false"/> + <md:RequestedAttribute FriendlyName="eduPersonTargetedID" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:RequestedAttribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> + <md:RequestedAttribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="false"/> + <md:RequestedAttribute FriendlyName="commonName" Name="urn:oid:2.5.4.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="false"/> + <md:RequestedAttribute FriendlyName="schacHomeOrganization" Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="false"/> + <md:RequestedAttribute FriendlyName="schacHomeOrganizationType" Name="urn:oid:1.3.6.1.4.1.25178.1.2.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="false"/> + </md:AttributeConsumingService> + </md:SPSSODescriptor> + <md:Organization> + <md:OrganizationName xml:lang="en">GEANT</md:OrganizationName> + <md:OrganizationDisplayName xml:lang="en">GEANT</md:OrganizationDisplayName> + <md:OrganizationURL xml:lang="en">http://www.geant.net</md:OrganizationURL> + </md:Organization> + <md:ContactPerson contactType="technical"> + <md:EmailAddress>edugain-ot@geant.net</md:EmailAddress> + </md:ContactPerson> +</md:EntityDescriptor> |