<?xml version="1.0" encoding="UTF-8"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://idp.asu.cas.cz/idp/shibboleth"> <md:Extensions> <mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="http://www.eduid.cz/" registrationInstant="2013-08-23T10:20:01Z"> <mdrpi:RegistrationPolicy xml:lang="en">http://www.eduid.cz/wiki/_media/en/eduid/policy/policy_eduid_en-1_1.pdf</mdrpi:RegistrationPolicy> <mdrpi:RegistrationPolicy xml:lang="cs">http://www.eduid.cz/wiki/_media/eduid/policy/policy_eduid_cz-1_1-3.pdf</mdrpi:RegistrationPolicy> </mdrpi:RegistrationInfo> <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"> <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> <saml:AttributeValue>http://eduid.cz/uri/idp-group/avcr</saml:AttributeValue> </saml:Attribute> </mdattr:EntityAttributes> </md:Extensions> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0"> <md:Extensions> <eduidmd:RepublishRequest xmlns:eduidmd="http://eduid.cz/schema/metadata/1.0"> <eduidmd:RepublishTarget>http://edugain.org/</eduidmd:RepublishTarget> </eduidmd:RepublishRequest> <shibmd:Scope xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" regexp="false">asu.cas.cz</shibmd:Scope> <mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui"> <mdui:DisplayName xml:lang="en">Astronomical Institute of the Czech Academy of Sciences</mdui:DisplayName> <mdui:DisplayName xml:lang="cs">Astronomický ústav Akademie věd České Republiky</mdui:DisplayName> <mdui:Description xml:lang="en">Identity Provider for employees of Astronomical Institute of the Czech Academy of Sciences.</mdui:Description> <mdui:Description xml:lang="cs">Identity Provider pro zaměstnance Astronomického ústavu Akademie věd České Republiky.</mdui:Description> <mdui:Logo height="40" width="99">https://idp.asu.cas.cz/logo-asu_99_40.png</mdui:Logo> <mdui:Logo height="76" width="187">https://idp.asu.cas.cz/logo-asu_187_76.png</mdui:Logo> </mdui:UIInfo> </md:Extensions> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate> MIIDJDCCAgygAwIBAgIVANrv5WGUsquQhfjq0eTxVi20NsReMA0GCSqGSIb3DQEB CwUAMBkxFzAVBgNVBAMMDmlkcC5hc3UuY2FzLmN6MB4XDTE1MDcyMzA5MDgzMloX DTM1MDcyMzA5MDgzMlowGTEXMBUGA1UEAwwOaWRwLmFzdS5jYXMuY3owggEiMA0G CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDtgoG22mEK+lNwgVWg+1wUkii+TLrW g5CO0r/WOODmehK4kkyM/jfKeyNHp3na2KgSIVcJprguPYZ9Yhg1UU5h4TgNCEeB qZcJwbNNSC0lLKHvbStR7FrMiSgtnQEcghM67DvGfN88xgdUzS2DNW3Z+dCPi/AI GcVlzcaITsp9Ho1SUBu5uPKeCLtZ+BbuSKfekw9+vhtIdm4cK6456wNnXWGjXM2J wI/wShdKY5oYG5bUO9Mj2Dxq+aV6EQLMkRLSZ9LE04sYalOKIyt+LDEzmyqwVmz1 SXb5HkA46RoWZgdIex+YIF9NasCsXwv9dyM5mvvpuqUpmhW+9LN22G9lAgMBAAGj YzBhMB0GA1UdDgQWBBT3XNIHand3OlDfGi4BptalsTc9WDBABgNVHREEOTA3gg5p ZHAuYXN1LmNhcy5jeoYlaHR0cHM6Ly9pZHAuYXN1LmNhcy5jei9pZHAvc2hpYmJv bGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAnZHWNtaZVfZEqU6af5xuULlBNUlGIh4O uMZeSbDu9pnVV0VDoIQxO+JUYXkdQduzLR564oyK/zhWKZg06f4YrsXWtkeXT3KN mFpVLGCOvbaD27h0hqv2CiioBcG2gAQ/t5rtU3iQCgaSqU8FP476zBh8dBVCB/xv jdMW+fZSfndHznmHrVjnhwMqaPgNOM45vkuwZeT0WZuhAhNXcCw3AGGrB8W4nmNd dsQVYrfF/KF/LG3HI3nCPWbe7vSKzdRidotQof3ZpVx/+mhM2xQu5PPAJKvT5TyO k7HbFDf0m9+/4WILNVLYF8L10+Gg2NSrdovl9NkyiEYi8udx9G9zvw== </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate> MIIDJDCCAgygAwIBAgIVAJdNb/Rhko4nwYw+ygi1hua8ErgsMA0GCSqGSIb3DQEB CwUAMBkxFzAVBgNVBAMMDmlkcC5hc3UuY2FzLmN6MB4XDTE1MDcyMzA5MDgzMVoX DTM1MDcyMzA5MDgzMVowGTEXMBUGA1UEAwwOaWRwLmFzdS5jYXMuY3owggEiMA0G CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC9FHZ+PdNss6t/V4/KurzMsMHp1Zoq l07jPffg5B8B1NqlLacljuvRFS8B+sGZeQQWa9HtDzxBSrlemoc9EdmC3N5QQ5+F 1giiFJosgEd0in3h5NilYEfmovc+SLoPoLfQj21kAGLP0bMMW3wa8rl3oGTtPmJ8 9jAc1FX6u6p3g61jeREidhMylO6GtbREhL6hXKqiyglR0zWjZCYfQCzF392lyyeQ nMJqI4oKREGSN27MX1YIhplnkV3amGcH/sqMjdStcYFqJc5+h/6X9iFWHFohqLpF rIYeVePQhbj1VDPIPUqyVBeGlsk+xpzKnSnbDsaYh/MhFJXnmn6rEbTvAgMBAAGj YzBhMB0GA1UdDgQWBBRWbgeUKb4C9ZnYCV4qpFnILVSyHjBABgNVHREEOTA3gg5p ZHAuYXN1LmNhcy5jeoYlaHR0cHM6Ly9pZHAuYXN1LmNhcy5jei9pZHAvc2hpYmJv bGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAJd0Z2rahGuNgnK/+H3ohx7fLvpGeW2ne BhSVrBFTr5zVHOrfkrZvdnpV0CI65T00lYRWpIkqAN8aEJujjJXsE0kEagFM/ap8 mQB9CZwbEKXCU7vGyoRcegrZZl3srZ62YwxfLRJjAK3DSgKM0BtMSff1rJE2K8+L VQqEbFfPqunsbacUA1zF4HZ3ceJQNKzIFYuFTpp+1i5RZN/+28zwNQj1XlCJ8+fN 5KC/z5C4Kfg6PKnx5A0EJAr6Dk8afdoj6UO92/t+GF7Devsohpe2excLJ3zVJKWN 0mIfCxb1hPlXsnaFfv/ekGZcz+JHqpHyEAXEUwLhqy97bRlPjKMFSQ== </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate> MIIDIzCCAgugAwIBAgIUHD3PnOGmtImskndM+6f3qKBHwkUwDQYJKoZIhvcNAQEL BQAwGTEXMBUGA1UEAwwOaWRwLmFzdS5jYXMuY3owHhcNMTUwNzIzMDkwODMyWhcN MzUwNzIzMDkwODMyWjAZMRcwFQYDVQQDDA5pZHAuYXN1LmNhcy5jejCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBALa+vR6ycaZQ3w7ropKE1MxxemCC4QIn jz5+Ch5gLNDyj4eIYQgvgGcS+cFzmht2oBiP4eeNyX2bNwcSerH0lANCpyBUNQOr jQMf0KwNgiUkkYy8Ii4CRGhcq6yhFxT6W/dx7NCx0tg44rFOLmpPXSBvZ0AepzmN hoaGihixtQxMSZ6VCA5oZP9E/nMgwv/PBgVHZ03Ip0djdcv2dSQyeXcCAXqcOdDf AQkH3aTwcLIWEJa2WdvoUTAzqgE0sKUbvDqIngP3zimFS2t2XSln1/2ThH67RQpJ 75cBdHlUU6w+a1dkBRg+0KORyt+QoqQgQx4vYmySDU2I/l1x5zQ7ma0CAwEAAaNj MGEwHQYDVR0OBBYEFGSRwgu2RzBPeQQ5AMgT+VMpnyHWMEAGA1UdEQQ5MDeCDmlk cC5hc3UuY2FzLmN6hiVodHRwczovL2lkcC5hc3UuY2FzLmN6L2lkcC9zaGliYm9s ZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQCva6u3xg7RFn+3lcwKfCSDU3o9WyLdPfuM VHydFjfIxxjlBOE4sMPAbFwTvlRi+TlZXgmJDBwv1UReC68Sik+3PjAYiLwclGP/ y0pSMmN1A1dFK/v1PrIeaZ/YZvnuh/k7IpVKX81Kg+qhkeh9eAxiLZi6Bdd3jB6r 4mdt/d/pPHbgkVj/qZCgBBYM0S3K/KyJcEU0ku0z447/TeGOUqDQoE7l5BNBLFi9 RLH/RkYhMb3hf89qLrOFgXCR3hAyX4xQAnyTZyxliYteSiGMfmLW6Mmr+MNaojx5 CuBQbcFvp2S6zogNWjt2678eGQSvtIIqAVNLzE9FpmksXm5Gyimt </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.asu.cas.cz:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/> <md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.asu.cas.cz:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.asu.cas.cz/idp/profile/SAML2/Redirect/SLO"/> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.asu.cas.cz/idp/profile/SAML2/POST/SLO"/> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.asu.cas.cz/idp/profile/SAML2/POST-SimpleSign/SLO"/> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.asu.cas.cz:8443/idp/profile/SAML2/SOAP/SLO"/> <md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat> <md:SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.asu.cas.cz/idp/profile/Shibboleth/SSO"/> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.asu.cas.cz/idp/profile/SAML2/POST/SSO"/> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.asu.cas.cz/idp/profile/SAML2/POST-SimpleSign/SSO"/> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.asu.cas.cz/idp/profile/SAML2/Redirect/SSO"/> </md:IDPSSODescriptor> <md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol"> <md:Extensions> <shibmd:Scope xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" regexp="false">asu.cas.cz</shibmd:Scope> </md:Extensions> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate> MIIDJDCCAgygAwIBAgIVANrv5WGUsquQhfjq0eTxVi20NsReMA0GCSqGSIb3DQEB CwUAMBkxFzAVBgNVBAMMDmlkcC5hc3UuY2FzLmN6MB4XDTE1MDcyMzA5MDgzMloX DTM1MDcyMzA5MDgzMlowGTEXMBUGA1UEAwwOaWRwLmFzdS5jYXMuY3owggEiMA0G CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDtgoG22mEK+lNwgVWg+1wUkii+TLrW g5CO0r/WOODmehK4kkyM/jfKeyNHp3na2KgSIVcJprguPYZ9Yhg1UU5h4TgNCEeB qZcJwbNNSC0lLKHvbStR7FrMiSgtnQEcghM67DvGfN88xgdUzS2DNW3Z+dCPi/AI GcVlzcaITsp9Ho1SUBu5uPKeCLtZ+BbuSKfekw9+vhtIdm4cK6456wNnXWGjXM2J wI/wShdKY5oYG5bUO9Mj2Dxq+aV6EQLMkRLSZ9LE04sYalOKIyt+LDEzmyqwVmz1 SXb5HkA46RoWZgdIex+YIF9NasCsXwv9dyM5mvvpuqUpmhW+9LN22G9lAgMBAAGj YzBhMB0GA1UdDgQWBBT3XNIHand3OlDfGi4BptalsTc9WDBABgNVHREEOTA3gg5p ZHAuYXN1LmNhcy5jeoYlaHR0cHM6Ly9pZHAuYXN1LmNhcy5jei9pZHAvc2hpYmJv bGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAnZHWNtaZVfZEqU6af5xuULlBNUlGIh4O uMZeSbDu9pnVV0VDoIQxO+JUYXkdQduzLR564oyK/zhWKZg06f4YrsXWtkeXT3KN mFpVLGCOvbaD27h0hqv2CiioBcG2gAQ/t5rtU3iQCgaSqU8FP476zBh8dBVCB/xv jdMW+fZSfndHznmHrVjnhwMqaPgNOM45vkuwZeT0WZuhAhNXcCw3AGGrB8W4nmNd dsQVYrfF/KF/LG3HI3nCPWbe7vSKzdRidotQof3ZpVx/+mhM2xQu5PPAJKvT5TyO k7HbFDf0m9+/4WILNVLYF8L10+Gg2NSrdovl9NkyiEYi8udx9G9zvw== </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate> MIIDJDCCAgygAwIBAgIVAJdNb/Rhko4nwYw+ygi1hua8ErgsMA0GCSqGSIb3DQEB CwUAMBkxFzAVBgNVBAMMDmlkcC5hc3UuY2FzLmN6MB4XDTE1MDcyMzA5MDgzMVoX DTM1MDcyMzA5MDgzMVowGTEXMBUGA1UEAwwOaWRwLmFzdS5jYXMuY3owggEiMA0G CSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC9FHZ+PdNss6t/V4/KurzMsMHp1Zoq l07jPffg5B8B1NqlLacljuvRFS8B+sGZeQQWa9HtDzxBSrlemoc9EdmC3N5QQ5+F 1giiFJosgEd0in3h5NilYEfmovc+SLoPoLfQj21kAGLP0bMMW3wa8rl3oGTtPmJ8 9jAc1FX6u6p3g61jeREidhMylO6GtbREhL6hXKqiyglR0zWjZCYfQCzF392lyyeQ nMJqI4oKREGSN27MX1YIhplnkV3amGcH/sqMjdStcYFqJc5+h/6X9iFWHFohqLpF rIYeVePQhbj1VDPIPUqyVBeGlsk+xpzKnSnbDsaYh/MhFJXnmn6rEbTvAgMBAAGj YzBhMB0GA1UdDgQWBBRWbgeUKb4C9ZnYCV4qpFnILVSyHjBABgNVHREEOTA3gg5p ZHAuYXN1LmNhcy5jeoYlaHR0cHM6Ly9pZHAuYXN1LmNhcy5jei9pZHAvc2hpYmJv bGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAJd0Z2rahGuNgnK/+H3ohx7fLvpGeW2ne BhSVrBFTr5zVHOrfkrZvdnpV0CI65T00lYRWpIkqAN8aEJujjJXsE0kEagFM/ap8 mQB9CZwbEKXCU7vGyoRcegrZZl3srZ62YwxfLRJjAK3DSgKM0BtMSff1rJE2K8+L VQqEbFfPqunsbacUA1zF4HZ3ceJQNKzIFYuFTpp+1i5RZN/+28zwNQj1XlCJ8+fN 5KC/z5C4Kfg6PKnx5A0EJAr6Dk8afdoj6UO92/t+GF7Devsohpe2excLJ3zVJKWN 0mIfCxb1hPlXsnaFfv/ekGZcz+JHqpHyEAXEUwLhqy97bRlPjKMFSQ== </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate> MIIDIzCCAgugAwIBAgIUHD3PnOGmtImskndM+6f3qKBHwkUwDQYJKoZIhvcNAQEL BQAwGTEXMBUGA1UEAwwOaWRwLmFzdS5jYXMuY3owHhcNMTUwNzIzMDkwODMyWhcN MzUwNzIzMDkwODMyWjAZMRcwFQYDVQQDDA5pZHAuYXN1LmNhcy5jejCCASIwDQYJ KoZIhvcNAQEBBQADggEPADCCAQoCggEBALa+vR6ycaZQ3w7ropKE1MxxemCC4QIn jz5+Ch5gLNDyj4eIYQgvgGcS+cFzmht2oBiP4eeNyX2bNwcSerH0lANCpyBUNQOr jQMf0KwNgiUkkYy8Ii4CRGhcq6yhFxT6W/dx7NCx0tg44rFOLmpPXSBvZ0AepzmN hoaGihixtQxMSZ6VCA5oZP9E/nMgwv/PBgVHZ03Ip0djdcv2dSQyeXcCAXqcOdDf AQkH3aTwcLIWEJa2WdvoUTAzqgE0sKUbvDqIngP3zimFS2t2XSln1/2ThH67RQpJ 75cBdHlUU6w+a1dkBRg+0KORyt+QoqQgQx4vYmySDU2I/l1x5zQ7ma0CAwEAAaNj MGEwHQYDVR0OBBYEFGSRwgu2RzBPeQQ5AMgT+VMpnyHWMEAGA1UdEQQ5MDeCDmlk cC5hc3UuY2FzLmN6hiVodHRwczovL2lkcC5hc3UuY2FzLmN6L2lkcC9zaGliYm9s ZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQCva6u3xg7RFn+3lcwKfCSDU3o9WyLdPfuM VHydFjfIxxjlBOE4sMPAbFwTvlRi+TlZXgmJDBwv1UReC68Sik+3PjAYiLwclGP/ y0pSMmN1A1dFK/v1PrIeaZ/YZvnuh/k7IpVKX81Kg+qhkeh9eAxiLZi6Bdd3jB6r 4mdt/d/pPHbgkVj/qZCgBBYM0S3K/KyJcEU0ku0z447/TeGOUqDQoE7l5BNBLFi9 RLH/RkYhMb3hf89qLrOFgXCR3hAyX4xQAnyTZyxliYteSiGMfmLW6Mmr+MNaojx5 CuBQbcFvp2S6zogNWjt2678eGQSvtIIqAVNLzE9FpmksXm5Gyimt </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.asu.cas.cz:8443/idp/profile/SAML1/SOAP/AttributeQuery"/> <md:AttributeService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.asu.cas.cz:8443/idp/profile/SAML2/SOAP/AttributeQuery"/> </md:AttributeAuthorityDescriptor> <md:Organization> <md:OrganizationName xml:lang="en">Astronomical Institute of the CAS</md:OrganizationName> <md:OrganizationName xml:lang="cs">Astronomický ústav AVČR, v.v.i.</md:OrganizationName> <md:OrganizationDisplayName xml:lang="en">Astronomical institute of the Czech Academy of Sciences</md:OrganizationDisplayName> <md:OrganizationDisplayName xml:lang="cs">Astronomický ústav Akademie věd České republiky</md:OrganizationDisplayName> <md:OrganizationURL xml:lang="en">http://www.asu.cas.cz/en</md:OrganizationURL> <md:OrganizationURL xml:lang="cs">http://www.asu.cas.cz/</md:OrganizationURL> </md:Organization> <md:ContactPerson contactType="technical"> <md:GivenName>Petr</md:GivenName> <md:SurName>Ryšavý</md:SurName> <md:EmailAddress>petr.rysavy@asu.cas.cz</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>