blob: 68d6b19ce175f3fe30c20516153fdc970864902d (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
|
<?xml version="1.0" encoding="UTF-8"?>
<EntityDescriptor xmlns="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://idp-staging.shibboleth.ox.ac.uk/shibboleth-idp">
<!--
This is a Shibboleth IdP for the University of Oxford.
-->
<Extensions>
<mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
<saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>http://refeds.org/category/hide-from-discovery</saml:AttributeValue>
</saml:Attribute>
</mdattr:EntityAttributes>
<mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="http://ukfederation.org.uk" registrationInstant="2016-01-20T09:42:30Z">
<mdrpi:RegistrationPolicy xml:lang="en">http://ukfederation.org.uk/doc/mdrps-20130902</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
</Extensions>
<IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
<Extensions>
<shibmd:Scope xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" regexp="false">ox.ac.uk</shibmd:Scope>
</Extensions>
<KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDajCCAlKgAwIBAgIVAIAtmK4I7O7bvf0RPA0ZNHo2hkSAMA0GCSqGSIb3DQEB
CwUAMCoxKDAmBgNVBAMMH2lkcC1zdGFnaW5nLnNoaWJib2xldGgub3guYWMudWsw
HhcNMTYwMTE0MTczMTAyWhcNMzYwMTE0MTczMTAyWjAqMSgwJgYDVQQDDB9pZHAt
c3RhZ2luZy5zaGliYm9sZXRoLm94LmFjLnVrMIIBIjANBgkqhkiG9w0BAQEFAAOC
AQ8AMIIBCgKCAQEAlzER+bRzfZzTQ8dJKKfyBC6niOcIMI8fpEK3MDOFRaNjmrrm
ZShSh0ea/a0XcuK2KE1nJbqBdDYnLps120T/qCUd21dqL+z62HPMjSOddJvj5TNa
vylmkLQHNxhbzdqY6IghQWUIvbNKujQMe632ZIR3mx6t/yAXG9H4r1/0vzbcDGS+
qtGIgOlnxTxS8RFfw4dKV8FdaeljvlmL8nqHMhdmR7SEjnZ0m08v20kmKG6Siu2f
QD0/B3s23rz/M7e6z4mGc1OrSUzmuPZHnyY8A6eLZbYMbd7RCO34gs1TXVGTEY/t
AnfcZF3sqk1PPpVn4MQAJrcunx06TAzqlvhQTwIDAQABo4GGMIGDMB0GA1UdDgQW
BBSWC0uobK7TWktESwIkRr0J2+tltDBiBgNVHREEWzBZgh9pZHAtc3RhZ2luZy5z
aGliYm9sZXRoLm94LmFjLnVrhjZodHRwczovL2lkcC1zdGFnaW5nLnNoaWJib2xl
dGgub3guYWMudWsvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBAD1u
AItT11Prv9vZFYJeLgaMKwcFifjuBgbTW1e/6Z56LtsnRCVYeoaAL0isxkNuRpLg
25aFKkN+iU1TIuD8Qd2j36EtVA8CqVH2iybnwLky2jWZh75dbYyOCvp0YUSCPBPJ
OIVmhxVH5trGgcn6mWvKBqlOwxRzPi5xPV/WzQvRwb18VMKPHTgfgVMO8By/dxYV
z7bXOSrQjLP60GNEg1ruVkYIMQCp2kAukFU61xmOhDX2u/2cUhOLchU6WGX2NkOV
sfemgQTqBY1Rk1/XM+fn4aKWfsbmvAJilAD46sUZtiBvUNlMLwAb9j49t0aITeNz
CjMKBIk+697oQF/5Zhw=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</KeyDescriptor>
<KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDaDCCAlCgAwIBAgITekZgmzIaNoFuS/6wcr6UR9MwiDANBgkqhkiG9w0BAQsF
ADAqMSgwJgYDVQQDDB9pZHAtc3RhZ2luZy5zaGliYm9sZXRoLm94LmFjLnVrMB4X
DTE2MDExNDE3MzA1NFoXDTM2MDExNDE3MzA1NFowKjEoMCYGA1UEAwwfaWRwLXN0
YWdpbmcuc2hpYmJvbGV0aC5veC5hYy51azCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAI+WPG01l8PhqRj4EpKqLOCs5PIsWMhrjSEUtK7Q2TV5vbsmtEFm
yivfgB3ZQeUedxhMY5gD7wHbVzRf/bUmxz+I2orfOpBsaDxh6TH1J7NIbDXUyK+J
tF0jirsCWjYHZ1gGj/OshWjCQvWP4qX4e4pYmIdyTJJpIi2KIRwxh7KVAedFbdT+
dqgOnaygrjZ6jV49RyJ+FLUU1E+g61jL4bIl4fsipLm/zy4N6+qo85BV2JFLd/xU
LaTBO9IhxYxsU0Qo2GMzGD+XE2o5+w42QUfBYRd8xEVQkNbxTwxzTV+gcMpbfRys
YNCMmVmSb3zGMyZNUJOeatVYV04GAxcEcdUCAwEAAaOBhjCBgzAdBgNVHQ4EFgQU
4pAfbU3vAHNn9RLiF+8p5f8aEwkwYgYDVR0RBFswWYIfaWRwLXN0YWdpbmcuc2hp
YmJvbGV0aC5veC5hYy51a4Y2aHR0cHM6Ly9pZHAtc3RhZ2luZy5zaGliYm9sZXRo
Lm94LmFjLnVrL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQCFuOAP
a1jPW7sQIL536NCD9t/m3rBNk6xIIkgTDVbTOU/xpj6JsEOm3WiO/ukRPfDybYNJ
Q9rHqSvM6/IB/Ao0cdgnMbTf5yoYhBy7F5HXv7NXyYHZ/tTnIIr/fLZpzXnjb6PQ
LSJi70+wK0TdTLA5eHXW04h8h12Tt/aRHZ76rP+F/JykrLX2okgP1FQAc5JOYtDC
bQjgdqBZIu75bAIOOGPEHtwD9glkbpP3prJZo6Ib9kxXEA3C3FRgXSOL8bC18lx3
sqFWVybrxsBpkuXMazAh7vzbszSc5PRDllivVZCEVzzj3+uNR6s1GwBcDvOQzvJs
xMLJFJJld3a0yB22
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</KeyDescriptor>
<KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDajCCAlKgAwIBAgIVAPRlUe+MIjGNcHPwwfonzqdE0uphMA0GCSqGSIb3DQEB
CwUAMCoxKDAmBgNVBAMMH2lkcC1zdGFnaW5nLnNoaWJib2xldGgub3guYWMudWsw
HhcNMTYwMTE0MTczMDU0WhcNMzYwMTE0MTczMDU0WjAqMSgwJgYDVQQDDB9pZHAt
c3RhZ2luZy5zaGliYm9sZXRoLm94LmFjLnVrMIIBIjANBgkqhkiG9w0BAQEFAAOC
AQ8AMIIBCgKCAQEAiLVYz2X2tTa7+ujJmdeI2Hg2hDmEejDV2MzXGJgVkyQ/mt08
8a2cEK+4SkSDSwYtQG1ru0yn5OjB38HTcFpUbxGpMl/1WOIPGxHYb55p+d0DR0q6
+08y1vlwT5h4RVFaFj+Tx0LmDcip5kxYzPkmItiunKsMOsxDgnuC1yFxT/UFors+
ZWsb8wkbk2OX0K3jHbD3Hbm7bqmKOIp5NsmZaSbXUOw3FIxnPZwX+oZLerU7LRgd
dHrLdtf8Q5FUCuVPESjTyGw/k62LlTJRcCUXrlJ3K2mZZET3M+Xl+B/jl4NVBp4v
NPmpKuRlwNejIKKHy0Cb5utpJCPg5JHVa6qESwIDAQABo4GGMIGDMB0GA1UdDgQW
BBQm5+FRSx0Sid4vbNqz8nzNjRLV3TBiBgNVHREEWzBZgh9pZHAtc3RhZ2luZy5z
aGliYm9sZXRoLm94LmFjLnVrhjZodHRwczovL2lkcC1zdGFnaW5nLnNoaWJib2xl
dGgub3guYWMudWsvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBACPw
86BQmyOetDs77HbNi8ixLchm29yxdvpSTwJeyjtGo2y6puW0lZQm4P4hEQSHHnLj
wQpgq8XbQkep3ZOBObeVAbfrjSr0jL+ZCIogUveEpsIFwJRvamEZX679gzw0sRgK
C+CqY2raoShDE+tlrfjOTGEULJ3icNvrvy+babwlKQDKxUVu4mROwoet7tIe4jm6
VzgVIhY7jGZH59TvcN32ddAlYbzlqxbP+89yzOY4jUPDpUym41m1CUc2a4ne7e1u
lOakNEYy9WRL8/SBEMSQdlAs5vKh6nvlOdX9cYLGJEQ/BpRPB40O6eqbcFbIhJSk
Uf13ppG6F4RF0QOHD3Y=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</KeyDescriptor>
<ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp-staging.shibboleth.ox.ac.uk:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
<ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp-staging.shibboleth.ox.ac.uk:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
<NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</NameIDFormat>
<NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</NameIDFormat>
<SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp-staging.shibboleth.ox.ac.uk/idp/profile/Shibboleth/SSO"/>
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp-staging.shibboleth.ox.ac.uk/idp/profile/SAML2/POST/SSO"/>
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp-staging.shibboleth.ox.ac.uk/idp/profile/SAML2/POST-SimpleSign/SSO"/>
<SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp-staging.shibboleth.ox.ac.uk/idp/profile/SAML2/Redirect/SSO"/>
</IDPSSODescriptor>
<AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
<Extensions>
<shibmd:Scope xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" regexp="false">ox.ac.uk</shibmd:Scope>
</Extensions>
<KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDajCCAlKgAwIBAgIVAIAtmK4I7O7bvf0RPA0ZNHo2hkSAMA0GCSqGSIb3DQEB
CwUAMCoxKDAmBgNVBAMMH2lkcC1zdGFnaW5nLnNoaWJib2xldGgub3guYWMudWsw
HhcNMTYwMTE0MTczMTAyWhcNMzYwMTE0MTczMTAyWjAqMSgwJgYDVQQDDB9pZHAt
c3RhZ2luZy5zaGliYm9sZXRoLm94LmFjLnVrMIIBIjANBgkqhkiG9w0BAQEFAAOC
AQ8AMIIBCgKCAQEAlzER+bRzfZzTQ8dJKKfyBC6niOcIMI8fpEK3MDOFRaNjmrrm
ZShSh0ea/a0XcuK2KE1nJbqBdDYnLps120T/qCUd21dqL+z62HPMjSOddJvj5TNa
vylmkLQHNxhbzdqY6IghQWUIvbNKujQMe632ZIR3mx6t/yAXG9H4r1/0vzbcDGS+
qtGIgOlnxTxS8RFfw4dKV8FdaeljvlmL8nqHMhdmR7SEjnZ0m08v20kmKG6Siu2f
QD0/B3s23rz/M7e6z4mGc1OrSUzmuPZHnyY8A6eLZbYMbd7RCO34gs1TXVGTEY/t
AnfcZF3sqk1PPpVn4MQAJrcunx06TAzqlvhQTwIDAQABo4GGMIGDMB0GA1UdDgQW
BBSWC0uobK7TWktESwIkRr0J2+tltDBiBgNVHREEWzBZgh9pZHAtc3RhZ2luZy5z
aGliYm9sZXRoLm94LmFjLnVrhjZodHRwczovL2lkcC1zdGFnaW5nLnNoaWJib2xl
dGgub3guYWMudWsvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBAD1u
AItT11Prv9vZFYJeLgaMKwcFifjuBgbTW1e/6Z56LtsnRCVYeoaAL0isxkNuRpLg
25aFKkN+iU1TIuD8Qd2j36EtVA8CqVH2iybnwLky2jWZh75dbYyOCvp0YUSCPBPJ
OIVmhxVH5trGgcn6mWvKBqlOwxRzPi5xPV/WzQvRwb18VMKPHTgfgVMO8By/dxYV
z7bXOSrQjLP60GNEg1ruVkYIMQCp2kAukFU61xmOhDX2u/2cUhOLchU6WGX2NkOV
sfemgQTqBY1Rk1/XM+fn4aKWfsbmvAJilAD46sUZtiBvUNlMLwAb9j49t0aITeNz
CjMKBIk+697oQF/5Zhw=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</KeyDescriptor>
<KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDaDCCAlCgAwIBAgITekZgmzIaNoFuS/6wcr6UR9MwiDANBgkqhkiG9w0BAQsF
ADAqMSgwJgYDVQQDDB9pZHAtc3RhZ2luZy5zaGliYm9sZXRoLm94LmFjLnVrMB4X
DTE2MDExNDE3MzA1NFoXDTM2MDExNDE3MzA1NFowKjEoMCYGA1UEAwwfaWRwLXN0
YWdpbmcuc2hpYmJvbGV0aC5veC5hYy51azCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAI+WPG01l8PhqRj4EpKqLOCs5PIsWMhrjSEUtK7Q2TV5vbsmtEFm
yivfgB3ZQeUedxhMY5gD7wHbVzRf/bUmxz+I2orfOpBsaDxh6TH1J7NIbDXUyK+J
tF0jirsCWjYHZ1gGj/OshWjCQvWP4qX4e4pYmIdyTJJpIi2KIRwxh7KVAedFbdT+
dqgOnaygrjZ6jV49RyJ+FLUU1E+g61jL4bIl4fsipLm/zy4N6+qo85BV2JFLd/xU
LaTBO9IhxYxsU0Qo2GMzGD+XE2o5+w42QUfBYRd8xEVQkNbxTwxzTV+gcMpbfRys
YNCMmVmSb3zGMyZNUJOeatVYV04GAxcEcdUCAwEAAaOBhjCBgzAdBgNVHQ4EFgQU
4pAfbU3vAHNn9RLiF+8p5f8aEwkwYgYDVR0RBFswWYIfaWRwLXN0YWdpbmcuc2hp
YmJvbGV0aC5veC5hYy51a4Y2aHR0cHM6Ly9pZHAtc3RhZ2luZy5zaGliYm9sZXRo
Lm94LmFjLnVrL2lkcC9zaGliYm9sZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQCFuOAP
a1jPW7sQIL536NCD9t/m3rBNk6xIIkgTDVbTOU/xpj6JsEOm3WiO/ukRPfDybYNJ
Q9rHqSvM6/IB/Ao0cdgnMbTf5yoYhBy7F5HXv7NXyYHZ/tTnIIr/fLZpzXnjb6PQ
LSJi70+wK0TdTLA5eHXW04h8h12Tt/aRHZ76rP+F/JykrLX2okgP1FQAc5JOYtDC
bQjgdqBZIu75bAIOOGPEHtwD9glkbpP3prJZo6Ib9kxXEA3C3FRgXSOL8bC18lx3
sqFWVybrxsBpkuXMazAh7vzbszSc5PRDllivVZCEVzzj3+uNR6s1GwBcDvOQzvJs
xMLJFJJld3a0yB22
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</KeyDescriptor>
<KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDajCCAlKgAwIBAgIVAPRlUe+MIjGNcHPwwfonzqdE0uphMA0GCSqGSIb3DQEB
CwUAMCoxKDAmBgNVBAMMH2lkcC1zdGFnaW5nLnNoaWJib2xldGgub3guYWMudWsw
HhcNMTYwMTE0MTczMDU0WhcNMzYwMTE0MTczMDU0WjAqMSgwJgYDVQQDDB9pZHAt
c3RhZ2luZy5zaGliYm9sZXRoLm94LmFjLnVrMIIBIjANBgkqhkiG9w0BAQEFAAOC
AQ8AMIIBCgKCAQEAiLVYz2X2tTa7+ujJmdeI2Hg2hDmEejDV2MzXGJgVkyQ/mt08
8a2cEK+4SkSDSwYtQG1ru0yn5OjB38HTcFpUbxGpMl/1WOIPGxHYb55p+d0DR0q6
+08y1vlwT5h4RVFaFj+Tx0LmDcip5kxYzPkmItiunKsMOsxDgnuC1yFxT/UFors+
ZWsb8wkbk2OX0K3jHbD3Hbm7bqmKOIp5NsmZaSbXUOw3FIxnPZwX+oZLerU7LRgd
dHrLdtf8Q5FUCuVPESjTyGw/k62LlTJRcCUXrlJ3K2mZZET3M+Xl+B/jl4NVBp4v
NPmpKuRlwNejIKKHy0Cb5utpJCPg5JHVa6qESwIDAQABo4GGMIGDMB0GA1UdDgQW
BBQm5+FRSx0Sid4vbNqz8nzNjRLV3TBiBgNVHREEWzBZgh9pZHAtc3RhZ2luZy5z
aGliYm9sZXRoLm94LmFjLnVrhjZodHRwczovL2lkcC1zdGFnaW5nLnNoaWJib2xl
dGgub3guYWMudWsvaWRwL3NoaWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBACPw
86BQmyOetDs77HbNi8ixLchm29yxdvpSTwJeyjtGo2y6puW0lZQm4P4hEQSHHnLj
wQpgq8XbQkep3ZOBObeVAbfrjSr0jL+ZCIogUveEpsIFwJRvamEZX679gzw0sRgK
C+CqY2raoShDE+tlrfjOTGEULJ3icNvrvy+babwlKQDKxUVu4mROwoet7tIe4jm6
VzgVIhY7jGZH59TvcN32ddAlYbzlqxbP+89yzOY4jUPDpUym41m1CUc2a4ne7e1u
lOakNEYy9WRL8/SBEMSQdlAs5vKh6nvlOdX9cYLGJEQ/BpRPB40O6eqbcFbIhJSk
Uf13ppG6F4RF0QOHD3Y=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</KeyDescriptor>
<AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp-staging.shibboleth.ox.ac.uk:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
</AttributeAuthorityDescriptor>
<Organization>
<OrganizationName xml:lang="en">University of Oxford</OrganizationName>
<OrganizationDisplayName xml:lang="en">University of Oxford, Staging IdP</OrganizationDisplayName>
<OrganizationURL xml:lang="en">http://it.ox.ac.uk/</OrganizationURL>
</Organization>
<ContactPerson contactType="support">
<GivenName>Identity and Access Management</GivenName>
<EmailAddress>mailto:iam@it.ox.ac.uk</EmailAddress>
</ContactPerson>
<ContactPerson contactType="technical">
<GivenName>Identity and Access Management</GivenName>
<EmailAddress>mailto:iam@it.ox.ac.uk</EmailAddress>
</ContactPerson>
</EntityDescriptor>
|