blob: 31af7f5d5ae5f11b0131e4799c0a4e6ec0757106 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
|
<?xml version="1.0" encoding="UTF-8"?>
<!--
This is example metadata only. Do *NOT* supply it as is without review,
and do *NOT* provide it in real time to your partners.
-->
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute" xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" entityID="https://wireguard.lan.kth.se/shibboleth">
<md:Extensions>
<mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2022-08-24T12:14:05Z">
<mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/>
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/>
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
<alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/>
<alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
<alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/>
<mdattr:EntityAttributes>
<samla:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<samla:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</samla:AttributeValue>
</samla:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
<md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
<init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://wireguard-1.lan.kth.se/Shibboleth.sso/Login"/>
<idpdisc:DiscoveryResponse Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://wireguard-1.lan.kth.se/Shibboleth.sso/Login" index="1"/>
<mdui:UIInfo>
<mdui:DisplayName xml:lang="en">Wireguard</mdui:DisplayName>
<mdui:Description xml:lang="en">Wireguard</mdui:Description>
<mdui:Keywords xml:lang="en">Wireguard</mdui:Keywords>
<mdui:InformationURL xml:lang="en">https://www.lan.kth.se/vpn/vpn.html</mdui:InformationURL>
<mdui:PrivacyStatementURL xml:lang="en">https://intra.kth.se/en/it/natverk/regler-policys/policy-for-hantering-av-personuppgifter-inom-ramen-for-identitetsutgivaren-identity-provider-idp-som-faststallts-av-kungliga-tekniska-hogskolan-1.924071</mdui:PrivacyStatementURL>
<mdui:DisplayName xml:lang="sv">Wireguard</mdui:DisplayName>
<mdui:Description xml:lang="sv">Wireguard</mdui:Description>
<mdui:Keywords xml:lang="sv">Wireguard</mdui:Keywords>
<mdui:PrivacyStatementURL xml:lang="sv">https://intra.kth.se/it/natverk/regler-policys/policy-for-hantering-av-personuppgifter-inom-ramen-for-identitetsutgivaren-identity-provider-idp-som-faststallts-av-kungliga-tekniska-hogskolan-1.924071</mdui:PrivacyStatementURL>
<mdui:InformationURL xml:lang="sv">https://www.lan.kth.se/vpn/vpn.html</mdui:InformationURL>
</mdui:UIInfo>
</md:Extensions>
<md:KeyDescriptor use="signing">
<ds:KeyInfo>
<ds:KeyName>wireguard-1.lan.kth.se</ds:KeyName>
<ds:X509Data>
<ds:X509SubjectName>CN=wireguard-1.lan.kth.se</ds:X509SubjectName>
<ds:X509Certificate>MIIEFDCCAnygAwIBAgIURpdWd5Gzc7XaimvJXtWw2BlupFYwDQYJKoZIhvcNAQEL
BQAwITEfMB0GA1UEAxMWd2lyZWd1YXJkLTEubGFuLmt0aC5zZTAeFw0yMjA4MTYx
NDE0MDFaFw0zMjA4MTMxNDE0MDFaMCExHzAdBgNVBAMTFndpcmVndWFyZC0xLmxh
bi5rdGguc2UwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQC5kZTqJi+v
cjnTHS8qBSq1Peuav7Fq4T4bGMnaFEQA7FWchXkJ+iZ0ZS+Bb8Ooue49pURgzeqw
dVpjduv7wVnC6uZ1TyCFnb7i0WBWH/hxsunsg2qDWZkw/2TFoogxevgts5/Xqoqe
vVQSv4wPIjd1S/K54dO8TCvmZEMs8tkt435iyEr2wluS1PQPPOvHIOYxuXtlK9A3
lazhIWfUQu8GQeW59Lse12f/jhCWGB39tH1VObJersSqb6gEPe0Z5WhgOhyRp6Gi
d6uzF8QavKuelJkd98C7xHzWhvvKv43dAONlwAgyNeptJhDcLS9HDyS3AsN7TOYj
on22w3I8VUszVTyFGgSlcWn1K75TKK8ksIU2bFXCLsHkcx+6LWbLTGa90QhW/EtM
IXEVr61snoNAS6SSe923RscFV2gG+OV8sYcFg+1qUXjqgaAYqPLXQIc4CrKeqMYF
9JuhNdSOgSOIrcU3rmdBYyhwQSObJdzB8vPoQ3kmmQM/cztaDKJbclECAwEAAaNE
MEIwIQYDVR0RBBowGIIWd2lyZWd1YXJkLTEubGFuLmt0aC5zZTAdBgNVHQ4EFgQU
nUNTVqQ5dTXcWj/fNGNY0j36YdgwDQYJKoZIhvcNAQELBQADggGBAHrnSd99mXga
T7q2x2t2JPlSCXTxQ46pcoUHbnCt10kL7i5glWQeZyOERSrZva3dzk5zN6nl/lFM
MflmMqn+Z5BfrN1aQxvKirNrIhesJXlfqMMbxsFmbPDnMCXVlB4AUqFvF9QnyPtx
AbyKhPucoWgsZPLpFF8OqlIjv0KZKonIvn+AEk2F8JJaZgc07jrxFSTKBvCHEMCB
ZCgviC4rcu/AXjuuajto3XyBak1hSnFYUh2S1w+c9GFmiOxj/1hB7naY5f7dqZLl
ap0xAdPZ54t/gR5A2lll8kcAzLUPlB9DS4zj8tyERRWR/uUQ1EqEt4PzJyxW9xlK
KbMDL843FlYiFqjGtUWzDXQWyt5JwG6ffTltSa0JW6AoH5PU8+NSIPOcJNy/MK0o
MrqdXtMHC4jf6y0+MhY+ZgCllKHwDN4yRYVVK5HQ0UFqfFYuzzQRqy6SG1W+eN9p
XhLK9pCgT3PYX6ceCv8HMxO6Xk63NGnJ5uiKg/2YINVFFW3m9HQLrA==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo>
<ds:KeyName>wireguard-1.lan.kth.se</ds:KeyName>
<ds:X509Data>
<ds:X509SubjectName>CN=wireguard-1.lan.kth.se</ds:X509SubjectName>
<ds:X509Certificate>MIIEFDCCAnygAwIBAgIUbXbSu3S5oruZSOzhKJnkLpE9DYkwDQYJKoZIhvcNAQEL
BQAwITEfMB0GA1UEAxMWd2lyZWd1YXJkLTEubGFuLmt0aC5zZTAeFw0yMjA4MTYx
NDE0MDJaFw0zMjA4MTMxNDE0MDJaMCExHzAdBgNVBAMTFndpcmVndWFyZC0xLmxh
bi5rdGguc2UwggGiMA0GCSqGSIb3DQEBAQUAA4IBjwAwggGKAoIBgQCVQF14y3Rc
APzvYZZvgmkCpHvut4gMlYP6CiDZVHG2iSeyOAV7Ee1hW0AmafZahghWgaBUM/5/
GCwe6Jx5gYeJd+0226Wg/JnGyioVYS4eR9SPQ44WX6Ycq6CUerVLm+z0m3Gctu1X
m+U2jgs+iTeFaQaWDXcbBTjPMUGIj0NxYZNOFJeOZv96PD1j26KYJm8i3PBZIITT
uwaib/MXMb/GMxep+RRqsYSvQPy9bHEjE3zW8fkdYoIYrSAxOORoFMKDmCrn+gBJ
fTx/QM8/Oj9ouv787GsXvRx0zDgppbGnrN01GFHuxbEfAb6SXnDRK9rzCCZTv8kL
TA59cPEDrn2WhNOJQUH1avU3nkItj5zHKfIBJv0cHu2QO36+i6kvah/UMvvAjueP
Ux+uOOIk9xoo/RKO5+qzz4diuCIHPtvydback22gY5kCw0Hx+0b9AN614/dp1NBl
TJoZAZERZitrKjPwm8aiFxjR7EpEQrh7BxAJAiTe+aW311oeshx55rECAwEAAaNE
MEIwIQYDVR0RBBowGIIWd2lyZWd1YXJkLTEubGFuLmt0aC5zZTAdBgNVHQ4EFgQU
FuSc7GcH+CpaDluYWYRwEHMvyVAwDQYJKoZIhvcNAQELBQADggGBAGRc6TmQnjij
BvGkwBDCG1VUJewvfcShslOC1h/8UlFwok+Ll8t2s2eGRFGarklTjs+6+DRoufW5
ylQVkqhQqx4VdIfuEt83Bo4OAEDjtlO65CGFmUPTIMZ/+wf6ySvrE6cy+vJI8vRC
4OCiVg0NcRu/2pnEqGk/inG6J9B09MLmaszGJGhPn2re/btVpczEJFCthGQQXW/S
KNj8HTd+jqNQq75jl3hZL2nxpNf7E/3yq/dCCwoi6w1nHTI005i0+5bSLeX6hi9C
3hRAD4DMAsmrLqrKKgNectV+s1mt3KolSDzdkdVL5J4+2IV2cCx13mcMZpOG6yyk
HkBz+zwnJuQ94QQtF0NnGmY4qkO2VyGtRKomcjN2C0hygG17HzRUFk4Mq28g6m6T
t9aBsdTlfwJ/uIsv+XH0G0JmupgEaz0EZuxstYxEJXQdxrmTW3cFz5bS1KXNAF70
/zys1o8p3R8NOXY2rK34GWzaMthGCMQ105MNnZljA66hqhKEOP6chw==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
<md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/>
<md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/>
</md:KeyDescriptor>
<md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://wireguard-1.lan.kth.se/Shibboleth.sso/Artifact/SOAP" index="1"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://wireguard-1.lan.kth.se/Shibboleth.sso/SLO/SOAP"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://wireguard-1.lan.kth.se/Shibboleth.sso/SLO/Redirect"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://wireguard-1.lan.kth.se/Shibboleth.sso/SLO/POST"/>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://wireguard-1.lan.kth.se/Shibboleth.sso/SLO/Artifact"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://wireguard-1.lan.kth.se/Shibboleth.sso/SAML2/POST" index="1"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://wireguard-1.lan.kth.se/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://wireguard-1.lan.kth.se/Shibboleth.sso/SAML2/Artifact" index="3"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://wireguard-1.lan.kth.se/Shibboleth.sso/SAML2/ECP" index="4"/>
<md:AttributeConsumingService index="1">
<md:ServiceName xml:lang="en">Wireguard</md:ServiceName>
<md:ServiceName xml:lang="sv">Wireguard</md:ServiceName>
<md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
</md:AttributeConsumingService>
</md:SPSSODescriptor>
<md:Organization>
<md:OrganizationName xml:lang="en">Royal Institute of Technology</md:OrganizationName>
<md:OrganizationName xml:lang="sv">Kungliga Tekniska högskolan</md:OrganizationName>
<md:OrganizationDisplayName xml:lang="sv">KTH</md:OrganizationDisplayName>
<md:OrganizationDisplayName xml:lang="en">KTH</md:OrganizationDisplayName>
<md:OrganizationURL xml:lang="en">https://www.kth.se/en</md:OrganizationURL>
<md:OrganizationURL xml:lang="sv">https://www.kth.se/</md:OrganizationURL>
</md:Organization>
<md:ContactPerson contactType="administrative">
<md:Company>Kungliga Tekniska högskolan</md:Company>
<md:GivenName>Hans</md:GivenName>
<md:SurName>Åkerman</md:SurName>
<md:EmailAddress>mailto:hakerman@kth.se</md:EmailAddress>
<md:TelephoneNumber>+4687906000</md:TelephoneNumber>
</md:ContactPerson>
<md:ContactPerson contactType="technical">
<md:Company>Kungliga Tekniska högskolan</md:Company>
<md:GivenName>Hans</md:GivenName>
<md:SurName>Akerman</md:SurName>
<md:EmailAddress>mailto:hakerman@kth.se</md:EmailAddress>
<md:TelephoneNumber>+4687906000</md:TelephoneNumber>
</md:ContactPerson>
<md:ContactPerson contactType="support">
<md:Company>Kungliga Tekniska högskolan</md:Company>
<md:GivenName>IT-Support</md:GivenName>
<md:EmailAddress>mailto:it-support@kth.se</md:EmailAddress>
<md:TelephoneNumber>+46 8 790 6600</md:TelephoneNumber>
</md:ContactPerson>
</md:EntityDescriptor>
|