From 412586ace672c5ea8b82b25fc5f635728e077990 Mon Sep 17 00:00:00 2001
From: Björn Mattsson <bjorn@sunet.se>
Date: Fri, 18 Mar 2022 13:01:36 +0100
Subject: SWAMID-654, Added AL1/2 to idp.nordu.net

---
 swamid-2.0/idp.nordu.net-idp-shibboleth.xml | 96 ++++++++++++++++-------------
 1 file changed, 52 insertions(+), 44 deletions(-)

diff --git a/swamid-2.0/idp.nordu.net-idp-shibboleth.xml b/swamid-2.0/idp.nordu.net-idp-shibboleth.xml
index 853f318b..ad08c1c5 100644
--- a/swamid-2.0/idp.nordu.net-idp-shibboleth.xml
+++ b/swamid-2.0/idp.nordu.net-idp-shibboleth.xml
@@ -4,9 +4,15 @@
     <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2014-03-17T15:32:29Z">
       <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
     </mdrpi:RegistrationInfo>
+    <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
+      <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+        <samla:AttributeValue>http://www.swamid.se/policy/assurance/al1</samla:AttributeValue>
+        <samla:AttributeValue>http://www.swamid.se/policy/assurance/al2</samla:AttributeValue>
+      </samla:Attribute>
+    </mdattr:EntityAttributes>
   </md:Extensions>
-  <IDPSSODescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol" errorURL="https://error.swamid.se/?errorurl_code=ERRORURL_CODE&amp;errorurl_ts=ERRORURL_TS&amp;errorurl_rp=ERRORURL_RP&amp;errorurl_tid=ERRORURL_TID&amp;errorurl_ctx=ERRORURL_CTX&amp;entityid=https://idp.nordu.net/idp/shibboleth">
-    <Extensions>
+  <md:IDPSSODescriptor protocolSupportEnumeration="urn:mace:shibboleth:1.0 urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol" errorURL="https://error.swamid.se/?errorurl_code=ERRORURL_CODE&amp;errorurl_ts=ERRORURL_TS&amp;errorurl_rp=ERRORURL_RP&amp;errorurl_tid=ERRORURL_TID&amp;errorurl_ctx=ERRORURL_CTX&amp;entityid=https://idp.nordu.net/idp/shibboleth">
+    <md:Extensions>
       <shibmd:Scope regexp="false">nordu.net</shibmd:Scope>
       <mdui:UIInfo>
         <mdui:DisplayName xml:lang="sv">NORDUnet</mdui:DisplayName>
@@ -19,8 +25,8 @@
       <mdui:DiscoHints>
         <mdui:DomainHint>nordu.net</mdui:DomainHint>
       </mdui:DiscoHints>
-    </Extensions>
-    <KeyDescriptor>
+    </md:Extensions>
+    <md:KeyDescriptor>
       <ds:KeyInfo>
         <ds:X509Data>
           <ds:X509Certificate>
@@ -45,21 +51,21 @@ JiNCTXH29oP8kWBEBVaDxrDIrfDv53VjURS+KXqpBLjsuVE=
                     </ds:X509Certificate>
         </ds:X509Data>
       </ds:KeyInfo>
-    </KeyDescriptor>
-    <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.nordu.net:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
-    <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.nordu.net:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
-    <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
-    <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
-    <SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.nordu.net/idp/profile/Shibboleth/SSO"/>
-    <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.nordu.net/idp/profile/SAML2/POST/SSO"/>
-    <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.nordu.net/idp/profile/SAML2/POST-SimpleSign/SSO"/>
-    <SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.nordu.net/idp/profile/SAML2/Redirect/SSO"/>
-  </IDPSSODescriptor>
-  <AttributeAuthorityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">
-    <Extensions>
+    </md:KeyDescriptor>
+    <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.nordu.net:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
+    <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.nordu.net:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
+    <md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat>
+    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
+    <md:SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.nordu.net/idp/profile/Shibboleth/SSO"/>
+    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.nordu.net/idp/profile/SAML2/POST/SSO"/>
+    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.nordu.net/idp/profile/SAML2/POST-SimpleSign/SSO"/>
+    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.nordu.net/idp/profile/SAML2/Redirect/SSO"/>
+  </md:IDPSSODescriptor>
+  <md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">
+    <md:Extensions>
       <shibmd:Scope regexp="false">nordu.net</shibmd:Scope>
-    </Extensions>
-    <KeyDescriptor>
+    </md:Extensions>
+    <md:KeyDescriptor>
       <ds:KeyInfo>
         <ds:X509Data>
           <ds:X509Certificate>
@@ -84,30 +90,32 @@ JiNCTXH29oP8kWBEBVaDxrDIrfDv53VjURS+KXqpBLjsuVE=
                     </ds:X509Certificate>
         </ds:X509Data>
       </ds:KeyInfo>
-    </KeyDescriptor>
-    <AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.nordu.net:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
-    <AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.nordu.net:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>
-    <NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
-    <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
-  </AttributeAuthorityDescriptor>
-  <Organization xmlns="urn:oasis:names:tc:SAML:2.0:metadata">
-    <OrganizationName xml:lang="en">NORDUnet</OrganizationName>
-    <OrganizationDisplayName xml:lang="sv">NORDUnet</OrganizationDisplayName>
-    <OrganizationDisplayName xml:lang="en">NORDUnet</OrganizationDisplayName>
-    <OrganizationURL xml:lang="en">http://www.nordu.net</OrganizationURL>
-  </Organization>
-  <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="administrative">
-    <Company>NORDUnet</Company>
-    <SurName>noc@nordu.net</SurName>
-    <EmailAddress>mailto:noc@nordu.net</EmailAddress>
-  </ContactPerson>
-  <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="technical">
-    <Company>NORDUnet</Company>
-    <EmailAddress>mailto:noc@nordu.net</EmailAddress>
-  </ContactPerson>
-  <ContactPerson xmlns="urn:oasis:names:tc:SAML:2.0:metadata" contactType="support">
-    <Company>NORDUnet</Company>
-    <SurName>NUNOC</SurName>
-    <EmailAddress>mailto:noc@nordu.net</EmailAddress>
-  </ContactPerson>
+    </md:KeyDescriptor>
+    <md:AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.nordu.net:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
+    <md:AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.nordu.net:8443/idp/profile/SAML2/SOAP/AttributeQuery"/>
+    <md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat>
+    <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
+  </md:AttributeAuthorityDescriptor>
+  <md:Organization>
+    <md:OrganizationName xml:lang="en">NORDUnet</md:OrganizationName>
+    <md:OrganizationName xml:lang="sv">NORDUnet</md:OrganizationName>
+    <md:OrganizationDisplayName xml:lang="sv">NORDUnet</md:OrganizationDisplayName>
+    <md:OrganizationDisplayName xml:lang="en">NORDUnet</md:OrganizationDisplayName>
+    <md:OrganizationURL xml:lang="en">http://www.nordu.net</md:OrganizationURL>
+    <md:OrganizationURL xml:lang="sv">http://www.nordu.net</md:OrganizationURL>
+  </md:Organization>
+  <md:ContactPerson contactType="administrative">
+    <md:Company>NORDUnet</md:Company>
+    <md:SurName>noc@nordu.net</md:SurName>
+    <md:EmailAddress>mailto:noc@nordu.net</md:EmailAddress>
+  </md:ContactPerson>
+  <md:ContactPerson contactType="technical">
+    <md:Company>NORDUnet</md:Company>
+    <md:EmailAddress>mailto:noc@nordu.net</md:EmailAddress>
+  </md:ContactPerson>
+  <md:ContactPerson contactType="support">
+    <md:Company>NORDUnet</md:Company>
+    <md:SurName>NUNOC</md:SurName>
+    <md:EmailAddress>mailto:noc@nordu.net</md:EmailAddress>
+  </md:ContactPerson>
 </md:EntityDescriptor>
-- 
cgit v1.2.3