From c2ba89f4bdb528ca4cb85bf0f03217a0b7ace6ce Mon Sep 17 00:00:00 2001
From: Björn Mattsson <bjorn@sunet.se>
Date: Tue, 26 Nov 2024 14:35:24 +0100
Subject: Added https://refeds.org/entity-selection-profile + DiscoveryResponse

---
 .../metadata.lab.swamid.se-shibboleth.xml          | 41 ++++++++++++++--------
 1 file changed, 26 insertions(+), 15 deletions(-)

diff --git a/metadata/swamid-2.0/metadata.lab.swamid.se-shibboleth.xml b/metadata/swamid-2.0/metadata.lab.swamid.se-shibboleth.xml
index e88a6670..152585e7 100644
--- a/metadata/swamid-2.0/metadata.lab.swamid.se-shibboleth.xml
+++ b/metadata/swamid-2.0/metadata.lab.swamid.se-shibboleth.xml
@@ -1,9 +1,6 @@
 <?xml version="1.0" encoding="UTF-8"?>
 <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute" xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://metadata.lab.swamid.se/shibboleth">
   <md:Extensions>
-    <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2021-10-26T09:33:57Z">
-      <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
-    </mdrpi:RegistrationInfo>
     <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
     <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
     <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
@@ -20,24 +17,40 @@
     <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
     <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
     <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
+    <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2021-10-26T09:33:57Z">
+      <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
+    </mdrpi:RegistrationInfo>
     <mdattr:EntityAttributes>
-      <samla:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category">
+      <samla:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
         <samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
         <samla:AttributeValue>https://refeds.org/category/personalized</samla:AttributeValue>
       </samla:Attribute>
+      <samla:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="https://refeds.org/entity-selection-profile">
+        <samla:AttributeValue>W3siZW50aXR5SUQiOiAiaHR0cHM6Ly9tZXRhZGF0YS5sYWIuc3dhbWlkLnNlL3NoaWJib2xldGgiLCAicHJvZmlsZXMiOiB7InN3YW1pZC1vbmx5IjogeyJzdHJpY3QiOiB0cnVlLCAiZW50aXRpZXMiOiBbeyJzZWxlY3QiOiAiaHR0cDovL3d3dy5zd2FtaWQuc2UvIiwgIm1hdGNoIjogInJlZ2lzdHJhdGlvbkF1dGhvcml0eSIsICJpbmNsdWRlIjogdHJ1ZX1dfX19LHsic3dhbWlkK2VkdWdhaW4iOiB7InN0cmljdCI6IHRydWUsICJlbnRpdGllcyI6IFt7InNlbGVjdCI6ICJmaWxlOi8vL29wdC9weWZmL21ldGFkYXRhL29wZW5hdGhlbnMueG1sIiwgIm1hdGNoIjogIm1kX3NvdXJjZSIsICJpbmNsdWRlIjogZmFsc2V9XX19XQ==</samla:AttributeValue>
+      </samla:Attribute>
     </mdattr:EntityAttributes>
   </md:Extensions>
   <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
     <md:Extensions>
+      <init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://metadata.lab.swamid.se/Shibboleth.sso/Login"/>
+      <idpdisc:DiscoveryResponse Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://metadata.lab.swamid.se/Shibboleth.sso/Login" index="1"/>
+      <init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://metadata.lab.swamid.se/Shibboleth.sso/DS/seamless-access"/>
+      <idpdisc:DiscoveryResponse Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://metadata.lab.swamid.se/Shibboleth.sso/DS/seamless-access" index="2"/>
+      <init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://metadata.lab.swamid.se/Shibboleth.sso/DS/thiss.io"/>
+      <idpdisc:DiscoveryResponse Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://metadata.lab.swamid.se/Shibboleth.sso/DS/thiss.io" index="3"/>
+      <init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://metadata.lab.swamid.se/Shibboleth.sso/DS/swamid-qa"/>
+      <idpdisc:DiscoveryResponse Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://metadata.lab.swamid.se/Shibboleth.sso/DS/swamid-qa" index="4"/>
+      <init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://metadata.lab.swamid.se/Shibboleth.sso/DS/fidus"/>
+      <idpdisc:DiscoveryResponse Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://metadata.lab.swamid.se/Shibboleth.sso/DS/fidus" index="5"/>
       <mdui:UIInfo>
-        <mdui:DisplayName xml:lang="sv">SWAMID Metadatahanterare - lab</mdui:DisplayName>
-        <mdui:DisplayName xml:lang="en">SWAMID Metdata admin tool - lab</mdui:DisplayName>
-        <mdui:Description xml:lang="sv">Detta är en tjänst för att hantera metadata för entiteter i SWAMID.</mdui:Description>
         <mdui:Description xml:lang="en">This is a service for handling Metdadata for entities in SWAMID.</mdui:Description>
-        <mdui:InformationURL xml:lang="sv">https://metadata.swamid.se/</mdui:InformationURL>
+        <mdui:Description xml:lang="sv">Detta är en tjänst för att hantera metadata för entiteter i SWAMID.</mdui:Description>
+        <mdui:DisplayName xml:lang="en">SWAMID Metdata admin tool - lab</mdui:DisplayName>
+        <mdui:DisplayName xml:lang="sv">SWAMID Metadatahanterare - lab</mdui:DisplayName>
         <mdui:InformationURL xml:lang="en">https://metadata.swamid.se/</mdui:InformationURL>
-        <mdui:Logo height="115" width="100" xml:lang="en">https://metadata.swamid.se/swamid-logo-2-100x115.png</mdui:Logo>
-        <mdui:Logo height="115" width="100" xml:lang="sv">https://metadata.swamid.se/swamid-logo-2-100x115.png</mdui:Logo>
+        <mdui:InformationURL xml:lang="sv">https://metadata.swamid.se/</mdui:InformationURL>
+        <mdui:Logo xml:lang="en" height="115" width="100">https://metadata.swamid.se/swamid-logo-2-100x115.png</mdui:Logo>
+        <mdui:Logo xml:lang="sv" height="115" width="100">https://metadata.swamid.se/swamid-logo-2-100x115.png</mdui:Logo>
         <mdui:PrivacyStatementURL xml:lang="en">https://wiki.sunet.se/display/SWAMID/SWAMID+Metadata+admin+tool+-+Privacy+Policy?showLanguage=en_GB</mdui:PrivacyStatementURL>
         <mdui:PrivacyStatementURL xml:lang="sv">https://wiki.sunet.se/display/SWAMID/SWAMID+Metadata+admin+tool+-+Privacy+Policy?showLanguage=sv_SE</mdui:PrivacyStatementURL>
       </mdui:UIInfo>
@@ -68,8 +81,7 @@ pwRIZ1RSyXCZSAEl4Kb1Lz7mweWM0EsbtbMwkBzGtrbuuZeKg62zeuhrULO5VApF
 +oHbeQGNKiylDlRvAJ574PniPjyXrblslswJN9D4scsHrsHyMzZdXSjkTjOQsrk5
 Oci1lgWUvMVEcDRNEkVzxGHW7N7QkOkEd6ggHAdcAerExVqU7GSSFJy2N2V10CtQ
 KxzjFS087+e1KGbtHGTycSxW5WPse8m4YCPlv/PIEx7ongx1ydgwf+QJp61SKcUX
-NAu5oleTjvQwQw==
-</ds:X509Certificate>
+NAu5oleTjvQwQw==</ds:X509Certificate>
         </ds:X509Data>
       </ds:KeyInfo>
     </md:KeyDescriptor>
@@ -99,8 +111,7 @@ oLFmecKG72DXKHKiHUbVH0sLVh8qen+3PcBSPvtrBCUyD7vS34VV8yajJo5A3Ogz
 3ZblFfrla2DZKC/HUCDOydqiXh2I8Ltt8HN7exgbrLqbsF+xUqolQv/pCaAIZq1U
 vAsVSDYSdq0zuDb+nrAtPLYAA51OwFmpO6rlMRwbVoxNfi0oegWWgxTOnK2VctBd
 2AQGKekuU96Nc8bJOxHFD7mO1iTmvORamB/Ibxle1ieOqz7+JJefAZ5l3/oOWHig
-q6dUsY0AZixwYw==
-</ds:X509Certificate>
+q6dUsY0AZixwYw==</ds:X509Certificate>
         </ds:X509Data>
       </ds:KeyInfo>
       <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
@@ -126,9 +137,9 @@ q6dUsY0AZixwYw==
       <md:ServiceName xml:lang="en">Metadata admin for SWAMID</md:ServiceName>
       <md:ServiceName xml:lang="sv">Metadata admin for SWAMID</md:ServiceName>
       <md:RequestedAttribute FriendlyName="eduPersonAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
-      <md:RequestedAttribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
       <md:RequestedAttribute FriendlyName="eduPersonAssurance" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
       <md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
+      <md:RequestedAttribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
       <md:RequestedAttribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
       <md:RequestedAttribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
       <md:RequestedAttribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
-- 
cgit v1.2.3