<?xml version="1.0" encoding="UTF-8"?> <md:EntityDescriptor xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://wayf.rcauth.eu/wayf/"> <md:Extensions> <mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="http://www.surfconext.nl/" registrationInstant="2016-08-22T16:00:00Z"> <mdrpi:RegistrationPolicy xml:lang="en">https://wiki.surfnet.nl/display/eduGAIN/EduGAIN</mdrpi:RegistrationPolicy> </mdrpi:RegistrationInfo> <mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute"> <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> <saml:AttributeValue>http://refeds.org/category/research-and-scholarship</saml:AttributeValue> </saml:Attribute> <saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> <saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xsi:type="xs:string">https://refeds.org/sirtfi</saml:AttributeValue> </saml:Attribute> </mdattr:EntityAttributes> </md:Extensions> <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol"> <md:Extensions> <mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui"> <mdui:DisplayName xml:lang="en">RCAuth Pilot Online CA</mdui:DisplayName> <mdui:Description xml:lang="en">RCAuth Pilot Online CA for providing end-user proxy certificates to Science Gateways and other portals</mdui:Description> <mdui:InformationURL xml:lang="en">https://rcauth.eu/</mdui:InformationURL> <mdui:PrivacyStatementURL xml:lang="en">https://rcauth.eu/privacy</mdui:PrivacyStatementURL> <mdui:Logo width="800" height="388">http://rcauth.eu/images/RCauth-eu-logo.gif</mdui:Logo> <mdui:Logo width="150" height="73">http://rcauth.eu/images/RCauth-eu-logo-150.gif</mdui:Logo> </mdui:UIInfo> </md:Extensions> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDXTCCAkWgAwIBAgIJALR+hWgxJuxKMA0GCSqGSIb3DQEBCwUAMEUxEjAQBgoJkiaJk/IsZAEZFgJldTEWMBQGCgmSJomT8ixkARkWBnJjYXV0aDEXMBUGA1UEAwwOd2F5Zi5yY2F1dGguZXUwHhcNMTYwNjA5MTgzOTM3WhcNMzYwNzA5MTgzOTM3WjBFMRIwEAYKCZImiZPyLGQBGRYCZXUxFjAUBgoJkiaJk/IsZAEZFgZyY2F1dGgxFzAVBgNVBAMMDndheWYucmNhdXRoLmV1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvkp3v+IvRB/XTYpjjemICUba6w7R8UL3lIk3FSoYs0v/JcztpajiCbHdExGPUTckbFO3GY4YcoPcQH2NPzN37FQs8JuYpv+CTim+g43CIMW1nnZDQWxpeRGTl7Ih3sTY40MgQRhNUGtnJBHBCUFs8Yq9IDuljxhLMgZljUnUll5xFQjnBOcWsvtr6Z4vALSp7QkB15VqTkIVHzSq/iAvIcYGwWFt93xcdNRGQbTZ6bubp1MEGJxSA3+frBPE1Ee7geXpizY/gRUdTO+kj2dgqR+Jp1djwUIdcKvGDQf8Af9HUEPxRJdDef7TtoVbQsOoPJflzK+3tuQ5NAYGXZ2KYwIDAQABo1AwTjAdBgNVHQ4EFgQULHuCZRg2SEtDnLGxnCCVK57lA7UwHwYDVR0jBBgwFoAULHuCZRg2SEtDnLGxnCCVK57lA7UwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAQs8kXtotbAnEj1qZVls319nM1ES5cCY0e430HFJ7iF0mBDRyAGmuwnPrDcvHMFHALO2Gmj6WYcqNMSERjcACqTm700Qmz8RVnM2z1WoTQ0A65Xn4HKcy4lBppHtms5y/YaI9quBPynLIbd5jFLEakBidpoE/+kGwwov7067chebew61KArggd7SJnO5Y/35cdNF6PxilfXAdhSe5IZpKQptdYZ0mBS0mdcV6TDoH5pr2bVMJuggmRhQsSRW/H1x28krGyweGRFMohf5QEYogaEXig2QHcVT1pa3DIwgy9LJ803mEYYlf+ajnD/xXqyUV7qvZN8l6+p9Iob3SBEYOXQ==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDXTCCAkWgAwIBAgIJALR+hWgxJuxKMA0GCSqGSIb3DQEBCwUAMEUxEjAQBgoJkiaJk/IsZAEZFgJldTEWMBQGCgmSJomT8ixkARkWBnJjYXV0aDEXMBUGA1UEAwwOd2F5Zi5yY2F1dGguZXUwHhcNMTYwNjA5MTgzOTM3WhcNMzYwNzA5MTgzOTM3WjBFMRIwEAYKCZImiZPyLGQBGRYCZXUxFjAUBgoJkiaJk/IsZAEZFgZyY2F1dGgxFzAVBgNVBAMMDndheWYucmNhdXRoLmV1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvkp3v+IvRB/XTYpjjemICUba6w7R8UL3lIk3FSoYs0v/JcztpajiCbHdExGPUTckbFO3GY4YcoPcQH2NPzN37FQs8JuYpv+CTim+g43CIMW1nnZDQWxpeRGTl7Ih3sTY40MgQRhNUGtnJBHBCUFs8Yq9IDuljxhLMgZljUnUll5xFQjnBOcWsvtr6Z4vALSp7QkB15VqTkIVHzSq/iAvIcYGwWFt93xcdNRGQbTZ6bubp1MEGJxSA3+frBPE1Ee7geXpizY/gRUdTO+kj2dgqR+Jp1djwUIdcKvGDQf8Af9HUEPxRJdDef7TtoVbQsOoPJflzK+3tuQ5NAYGXZ2KYwIDAQABo1AwTjAdBgNVHQ4EFgQULHuCZRg2SEtDnLGxnCCVK57lA7UwHwYDVR0jBBgwFoAULHuCZRg2SEtDnLGxnCCVK57lA7UwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAQs8kXtotbAnEj1qZVls319nM1ES5cCY0e430HFJ7iF0mBDRyAGmuwnPrDcvHMFHALO2Gmj6WYcqNMSERjcACqTm700Qmz8RVnM2z1WoTQ0A65Xn4HKcy4lBppHtms5y/YaI9quBPynLIbd5jFLEakBidpoE/+kGwwov7067chebew61KArggd7SJnO5Y/35cdNF6PxilfXAdhSe5IZpKQptdYZ0mBS0mdcV6TDoH5pr2bVMJuggmRhQsSRW/H1x28krGyweGRFMohf5QEYogaEXig2QHcVT1pa3DIwgy9LJ803mEYYlf+ajnD/xXqyUV7qvZN8l6+p9Iob3SBEYOXQ==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://wayf.rcauth.eu/wayf/module.php/saml/sp/saml2-logout.php/default-sp"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://wayf.rcauth.eu/wayf/module.php/saml/sp/saml2-acs.php/default-sp" index="0"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://wayf.rcauth.eu/wayf/module.php/saml/sp/saml1-acs.php/default-sp" index="1"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://wayf.rcauth.eu/wayf/module.php/saml/sp/saml2-acs.php/default-sp" index="2"/> <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://wayf.rcauth.eu/wayf/module.php/saml/sp/saml1-acs.php/default-sp/artifact" index="3"/> <md:AttributeConsumingService index="0"> <md:ServiceName xml:lang="en">RCAuth.eu WAYF</md:ServiceName> <md:ServiceDescription xml:lang="en">RCAuth Pilot Online CA for providing end-user proxy certificates to Science Gateways and other portals</md:ServiceDescription> <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonPrincipalName"/> <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.13" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonUniqueId"/> <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonTargetedID"/> <md:RequestedAttribute Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="displayName"/> <md:RequestedAttribute Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="givenName"/> <md:RequestedAttribute Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="sn"/> <md:RequestedAttribute Name="urn:oid:2.5.4.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="cn"/> <md:RequestedAttribute Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="mail"/> <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonAssurance"/> <md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="schacHomeOrganization"/> </md:AttributeConsumingService> </md:SPSSODescriptor> <md:Organization> <md:OrganizationName xml:lang="en">Nikhef</md:OrganizationName> <md:OrganizationDisplayName xml:lang="en">Nikhef</md:OrganizationDisplayName> <md:OrganizationURL xml:lang="en">http://www.nikhef.nl</md:OrganizationURL> </md:Organization> <md:ContactPerson contactType="administrative"> <md:Company>RCAuth</md:Company> <md:GivenName>Operator</md:GivenName> <md:EmailAddress>ca@rcauth.eu</md:EmailAddress> </md:ContactPerson> <md:ContactPerson contactType="support"> <md:Company>RCAuth</md:Company> <md:GivenName>Operator</md:GivenName> <md:EmailAddress>ca@rcauth.eu</md:EmailAddress> </md:ContactPerson> <md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security"> <md:Company>Nikhef</md:Company> <md:GivenName>CSIRT</md:GivenName> <md:EmailAddress>security@nikhef.nl</md:EmailAddress> <md:TelephoneNumber>+31205925090</md:TelephoneNumber> </md:ContactPerson> <md:ContactPerson contactType="technical"> <md:GivenName>Operator</md:GivenName> <md:EmailAddress>ca@rcauth.eu</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>