From 6347fc9f1de045c9220ab3561e0a0f97a4f659fa Mon Sep 17 00:00:00 2001
From: Paul Scott <paul.scott@kau.se>
Date: Tue, 6 Apr 2021 13:14:27 +0000
Subject: SWAMID-187 partial resolve, publish staging SP first

---
 swamid-2.0/mittkau-stage.sai.kau.se-shibboleth.xml | 117 +++++++++++++++++++++
 swamid-edugain-sp-1.0.mxml                         |   2 +-
 swamid-sp-2.0.mxml                                 |   1 +
 3 files changed, 119 insertions(+), 1 deletion(-)
 create mode 100644 swamid-2.0/mittkau-stage.sai.kau.se-shibboleth.xml

diff --git a/swamid-2.0/mittkau-stage.sai.kau.se-shibboleth.xml b/swamid-2.0/mittkau-stage.sai.kau.se-shibboleth.xml
new file mode 100644
index 00000000..ebd7ff21
--- /dev/null
+++ b/swamid-2.0/mittkau-stage.sai.kau.se-shibboleth.xml
@@ -0,0 +1,117 @@
+<?xml version="1.0" encoding="UTF-8"?>
+<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://mittkau-stage.sai.kau.se/shibboleth">
+  <md:Extensions>
+    <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/">
+      <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
+    </mdrpi:RegistrationInfo>
+    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
+    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
+    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
+    <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
+    <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
+    <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
+    <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
+      <samla:Attribute xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category">
+        <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
+      </samla:Attribute>
+    </mdattr:EntityAttributes>
+  </md:Extensions>
+  <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
+    <md:Extensions>
+      <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://mittkau-stage.sai.kau.se/Shibboleth.sso/Login"/>
+      <mdui:UIInfo>
+        <mdui:DisplayName xml:lang="sv">Mitt Kau (staging)</mdui:DisplayName>
+        <mdui:DisplayName xml:lang="en">My Kau (staging)</mdui:DisplayName>
+        <mdui:Description xml:lang="sv">Mitt Kau är en personlig digital tjänst för dig som är student vid Karlstads universitet.</mdui:Description>
+        <mdui:Description xml:lang="en">My Kau is a personalised digital service for students at Karlstad University.</mdui:Description>
+        <mdui:InformationURL xml:lang="sv">https://mittkau-stage.sai.kau.se/login/sv</mdui:InformationURL>
+        <mdui:InformationURL xml:lang="en">https://mittkau-stage.sai.kau.se/login/en</mdui:InformationURL>
+        <mdui:PrivacyStatementURL xml:lang="sv">https://mittkau-stage.sai.kau.se/login/policy/sv</mdui:PrivacyStatementURL>
+        <mdui:PrivacyStatementURL xml:lang="en">https://mittkau-stage.sai.kau.se/login/policy/en</mdui:PrivacyStatementURL>
+      </mdui:UIInfo>
+    </md:Extensions>
+    <md:KeyDescriptor>
+      <ds:KeyInfo>
+        <ds:KeyName>mittkau-stage.sai.kau.se</ds:KeyName>
+        <ds:X509Data>
+          <ds:X509SubjectName>CN=mittkau-stage.sai.kau.se</ds:X509SubjectName>
+          <ds:X509Certificate>MIIEGjCCAoKgAwIBAgIUdZUNL2GsfWyFpbXrZ3CGimyxe7kwDQYJKoZIhvcNAQEL
+BQAwIzEhMB8GA1UEAxMYbWl0dGthdS1zdGFnZS5zYWkua2F1LnNlMB4XDTIwMDMy
+NzEyMjE0OFoXDTMwMDMyNTEyMjE0OFowIzEhMB8GA1UEAxMYbWl0dGthdS1zdGFn
+ZS5zYWkua2F1LnNlMIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKCAYEAs8Bc
+3HAJ6k7QsqoNxZG6m1SzKDjDd42LOHg2O6sbvgGcNspvWfLpnUW8zA3xZNsxcA2e
+/CBbLnrEi6cGOtemK3KsSkxJqAxILsTxROmdV3py6sWjX5OxVGJK19tQ58YD6Pen
+OFoPfRrh1Hnc660Nsn2cSu0Tq/vQqDcCrf2pv3wqYwLcXIFB8LTKBKb06i1Wv6K3
+Ulobu/CHhFRkFtzZqT+s/jJsuyXjhnjXBhD2JpPsmhVIx08PRFPZ6NCKbSeLtzSv
+cDOn55GFOJ8duoiLcZJYB+Ka6WEtIrYDzaJE34T46f/jc9M1TawQyXGmdqcREMjJ
+dgsDq9Lfr7035Scbfo7E08q/7da2h0mxcB/Yge5mHWwEtLgOB1h8KSz1b6y+3dXq
+cdhKHfUy8NaWeonceMcGeYUEZfMErZypdvvN8mG1Z2bs5/foMPB8YIlVrtadvOta
+JrvtiJQZjEn0usab+GMBEuoxzE/3T9zZZ8liO4L4yanKSsXDiOdChsAJKYszAgMB
+AAGjRjBEMCMGA1UdEQQcMBqCGG1pdHRrYXUtc3RhZ2Uuc2FpLmthdS5zZTAdBgNV
+HQ4EFgQU/PUDT6YmcrAR0nseSCOXl3RurpowDQYJKoZIhvcNAQELBQADggGBAI0y
+1IzkxQ48DLpLJucq70fAP3H3/Lxd6tOcjvJZOLCvWekZX9gPr9j6o0v9VlEiyseS
+AM9fVQi63aEVVCm4JEY6B7pcC/zaYRCKg3kaN9fdHCOLB7k7u/6yCZrAXqMbzIpv
+kGhfw9GwD6WPqL+oGmcUWXxeVDqHLe59vedNtKfV5E382hCSdMqrWz+gI9sQM+5H
+V3MTsV5TAN2nYZI79+4VnCmJaMJnSN6fNaRLBf0O0UWDAtOC+hGUga5p+M8jHfqY
+bxhX5LVIWz45N+jJ+NfXRgWq3GD7BsqNhnOhOHuoF1kY6wipTRdyY9foSDHH6ns6
+Lm96czxFMrbtCP4FAEXzQlX3v8Ph4W9q+x4+Z9a3w5RgEkreI/Mz3hfuJEKrVXEe
+MH2SlG4tjvp12kMG0ptstuaSbeYpKHquBSmoE8b4CtXwULysuCCvS5EDKjCxGYMn
+r5oR3PZ1N/zyDy6OeltFJzR7fMbuWay96SmHpd02qcEYYxGUdg0wiCliGU9lRw==
+</ds:X509Certificate>
+        </ds:X509Data>
+      </ds:KeyInfo>
+      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
+      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
+      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
+      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
+      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
+      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
+      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
+      <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
+      <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
+    </md:KeyDescriptor>
+    <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://mittkau-stage.sai.kau.se/Shibboleth.sso/Artifact/SOAP" index="1"/>
+    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://mittkau-stage.sai.kau.se/Shibboleth.sso/SLO/SOAP"/>
+    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://mittkau-stage.sai.kau.se/Shibboleth.sso/SLO/Redirect"/>
+    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://mittkau-stage.sai.kau.se/Shibboleth.sso/SLO/POST"/>
+    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://mittkau-stage.sai.kau.se/Shibboleth.sso/SLO/Artifact"/>
+    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://mittkau-stage.sai.kau.se/Shibboleth.sso/SAML2/POST" index="1"/>
+    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://mittkau-stage.sai.kau.se/Shibboleth.sso/SAML2/Artifact" index="2"/>
+    <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://mittkau-stage.sai.kau.se/Shibboleth.sso/SAML2/ECP" index="3"/>
+    <md:AttributeConsumingService index="1">
+      <md:ServiceName xml:lang="en">Mitt Kau (staging)</md:ServiceName>
+      <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+      <md:RequestedAttribute FriendlyName="norEduPersonNIN" Name="urn:oid:1.3.6.1.4.1.2428.90.1.5" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+    </md:AttributeConsumingService>
+  </md:SPSSODescriptor>
+  <md:Organization>
+    <md:OrganizationName xml:lang="en">KAU</md:OrganizationName>
+    <md:OrganizationName xml:lang="sv">KAU</md:OrganizationName>
+    <md:OrganizationDisplayName xml:lang="en">Karlstad University</md:OrganizationDisplayName>
+    <md:OrganizationDisplayName xml:lang="sv">Karlstads universitet</md:OrganizationDisplayName>
+    <md:OrganizationURL xml:lang="en">https://www.kau.se/en</md:OrganizationURL>
+    <md:OrganizationURL xml:lang="sv">https://www.kau.se</md:OrganizationURL>
+  </md:Organization>
+  <md:ContactPerson contactType="support">
+    <md:SurName>Mitt Kau</md:SurName>
+    <md:EmailAddress>mailto:mittkau@kau.se</md:EmailAddress>
+  </md:ContactPerson>
+  <md:ContactPerson contactType="administrative">
+    <md:SurName>Mitt Kau</md:SurName>
+    <md:EmailAddress>mailto:mittkau@kau.se</md:EmailAddress>
+  </md:ContactPerson>
+  <md:ContactPerson contactType="technical">
+    <md:SurName>IT department</md:SurName>
+    <md:EmailAddress>mailto:2525@kau.se</md:EmailAddress>
+  </md:ContactPerson>
+</md:EntityDescriptor>
diff --git a/swamid-edugain-sp-1.0.mxml b/swamid-edugain-sp-1.0.mxml
index a9a4281e..af24aa62 100644
--- a/swamid-edugain-sp-1.0.mxml
+++ b/swamid-edugain-sp-1.0.mxml
@@ -45,7 +45,7 @@
   <xi:include href="swamid-2.0/signservice.edusign.sunet.se-sigservice.xml"/>
   <xi:include href="swamid-2.0/crowd.sunet.se-shibboleth.xml"/>
   <xi:include href="swamid-2.0/nextcloud.fysik.su.se-swamidproxy-nextcloud.xml.xml"/>
-  <xi:include href="swamid-2.0/indico.fysik.su.se-shibboleth.sso.xml"/>
+  <xi:include href="swamid-2.0/indico.fysik.su.se-Shibboleth.sso.xml"/>
   <xi:include href="swamid-2.0/gdb.vr.se.xml"/>
   <xi:include href="swamid-2.0/gitlab.speech.humlab.umu.se.xml"/>
   <xi:include href="swamid-2.0/speech.humlab.umu.se.xml"/>
diff --git a/swamid-sp-2.0.mxml b/swamid-sp-2.0.mxml
index 0804c1f6..b3fc89ac 100644
--- a/swamid-sp-2.0.mxml
+++ b/swamid-sp-2.0.mxml
@@ -690,4 +690,5 @@
   <xi:include href="swamid-2.0/secure.ouriginal.com.xml"/>
   <xi:include href="swamid-2.0/expert.hubbletest.antagning.se-ecs-sp.xml"/>
   <xi:include href="swamid-2.0/eu1.itslearning.com-integrations-samlmetadata-saml2v2-extensions-2.xml"/>
+  <xi:include href="swamid-2.0/mittkau-stage.sai.kau.se-shibboleth.xml"/>
 </md:EntitiesDescriptor>
-- 
cgit v1.2.3