blob: b426543059c1c6789d2aa6ac9da4e7e83b346fbe (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
|
<?xml version="1.0" encoding="UTF-8"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://idp.ssc.cas.cz/idp/shibboleth">
<md:Extensions>
<eduidmd:RepublishRequest xmlns:eduidmd="http://eduid.cz/schema/metadata/1.0">
<eduidmd:RepublishTarget>http://edugain.org/</eduidmd:RepublishTarget>
</eduidmd:RepublishRequest>
<mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="http://www.eduid.cz/" registrationInstant="2014-03-06T11:08:18Z">
<mdrpi:RegistrationPolicy xml:lang="en">http://www.eduid.cz/wiki/_media/en/eduid/policy/policy_eduid_en-1_1.pdf</mdrpi:RegistrationPolicy>
<mdrpi:RegistrationPolicy xml:lang="cs">http://www.eduid.cz/wiki/_media/eduid/policy/policy_eduid_cz-1_1-3.pdf</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
<mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
<saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>http://eduid.cz/uri/idp-group/avcr</saml:AttributeValue>
</saml:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
<md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
<md:Extensions>
<shibmd:Scope xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" regexp="false">ssc.cas.cz</shibmd:Scope>
<mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui">
<mdui:DisplayName xml:lang="en">Centre of Administration and Operations of AS CR</mdui:DisplayName>
<mdui:DisplayName xml:lang="cs">Středisko společných činností AV ČR</mdui:DisplayName>
<mdui:Description xml:lang="en">Identity Provider SSC AV CR employees.</mdui:Description>
<mdui:Description xml:lang="cs">Identity Provider pro zaměstnance SSČ AV ČR</mdui:Description>
<mdui:InformationURL xml:lang="en">http://www.ssc.cas.cz/</mdui:InformationURL>
<mdui:InformationURL xml:lang="cs">http://www.ssc.cas.cz/</mdui:InformationURL>
<mdui:Logo height="40" width="74">https://gedeon.cas.cz/loga/logo-ssc-44.png</mdui:Logo>
<mdui:Logo height="638" width="1080">https://gedeon.cas.cz/loga/logo-ssc-638.png</mdui:Logo>
</mdui:UIInfo>
</md:Extensions>
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDIzCCAgugAwIBAgIUH+9s+EsAoecplRXJyLBgG/ZkwmwwDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOaWRwLnNzYy5jYXMuY3owHhcNMTYxMDI0MDgyMTIxWhcN
MzYxMDI0MDgyMTIxWjAZMRcwFQYDVQQDDA5pZHAuc3NjLmNhcy5jejCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAOuB7cZZsm4Oq55kEmPuvZmSktAwrh3o
CMNHdg7vwB4Q9QSpdWEW7w7C3WvTR8q98DZ28iDTg51LosHqWwGwGpkDnMdt/6Z7
NS9JuWCFwrMwXnIB/rI6jvATSsQPTPuGtT4pz9hwgRYwMKqFEBNY3cZBMqlUyDYr
KHtFe5VfrS09vpRM4hse42dn+9WUXc4ddxzaP/mrZdN9aYvWyAa7PKhgEuvURSRq
SvrgizUVIdpV/+G7k851B0ozCMF0EsMd/gdku8WaF6kLdutgk30ijCy+8p/IGdhl
QynIXO6VmHqMl96y4Cq1b65NQ/ZKDczl9xqtn8hhAkc0d+tg6mOQwVsCAwEAAaNj
MGEwHQYDVR0OBBYEFHMCmxC0W8Q0Y93RjGBaEdA6YBJ7MEAGA1UdEQQ5MDeCDmlk
cC5zc2MuY2FzLmN6hiVodHRwczovL2lkcC5zc2MuY2FzLmN6L2lkcC9zaGliYm9s
ZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQBO+ImsGkiX/S+mv4K7Tw/AbfXtNKLF/8p+
9zFee91MUjISc/MNjj/KXa4GXk/N//bTQLHG8uua6w8kKdK04mg3AP6eaIKFjmfT
xRQBB56DYFetWd3XGGS8LDmZSrt/+MZd2APNOCfD+w5OoaHeIbgPFrRh07OMLyEv
afwMwJctLGTBbN7cFcXk294sGIwTPetuNfEfWH7UgHFEKcsiQ+zUWhMDJG+ex1n7
wwLM0eJnA2fMV0HB06IF3qt8DK/MHCSa9mx8LniCDESDTFMq/uMoXs+Jl6R3sVvp
IoENzXl0EGnCtFQmbRnSREKQFw96d6/lTHT3L9CE65Tr0kwIGhbt
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDIzCCAgugAwIBAgIUXPYLmocUcTH+oKw7G2+QXKvjEEQwDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOaWRwLnNzYy5jYXMuY3owHhcNMTYxMDI0MDgyMTE5WhcN
MzYxMDI0MDgyMTE5WjAZMRcwFQYDVQQDDA5pZHAuc3NjLmNhcy5jejCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAIxN9gtDpQWeqhbniCFVz2fsc8HvHjnf
Xa6Qx1h5XbgAIQ+EIjaD5rKsOe1ZtwTaeBD2BDnwMFD2hj+Q6Ujh7nxD6rn+Q2Ot
oLfYVbZSbv+8fvOl/mb4EMBCEguJMeUz5RmX04j3QpiriLNcjnWqXUS9WCYdRLjk
rnamOQygpN27TIPnoUHvCsoRn1wMODKKItdjLXiHDqEQqJ7K16DzS74GYRwktg85
P/kUJxB9Ff6Vs0RUXh8w37QPFgSdkItEWQQHMaaMGgpmufqLghTjA6zTVRJtX1Gs
dPW8zwdChhnOQan1MIa49UWXb76jQzoGNHfkAs77bdiOFViFiwqh+eMCAwEAAaNj
MGEwHQYDVR0OBBYEFPazSkIhwwoRQhMevpLNdKopcZALMEAGA1UdEQQ5MDeCDmlk
cC5zc2MuY2FzLmN6hiVodHRwczovL2lkcC5zc2MuY2FzLmN6L2lkcC9zaGliYm9s
ZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQAO4yaE/gCOhn9GOQ/3lWwXAnATn2sONKHe
cBLampWCuGUrvTqmrtHINJ3cEGi0Oaefw2M+t7LyxOt4IcEIf30TBOCDCZ/H0byI
BcfVrpSUHGMlU7Ar1TMG/vYsuOISZZvvJMBJDmKzMhrhT4SoE7W6Zt/pAJUXWkF9
Bp15VXtn80L4TqGrXWWjNesyd16UNYdUmL6kSDu2SHtvXHCqRBknVqVzu/ad84h+
WlvR75sMM4Z6s19foKRAvICkbgUQIZash4z8iKabi+9a4yY+WQmzS2LO16wmUyD+
PekHDlCio2wnMsWiQbs8R8TPVp841I/WkoZQ39GaNQAYT6qmpusg
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDIzCCAgugAwIBAgIUO+a4F1CQBqxJA1JElzFTYRCgOIswDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOaWRwLnNzYy5jYXMuY3owHhcNMTYxMDI0MDgyMTIwWhcN
MzYxMDI0MDgyMTIwWjAZMRcwFQYDVQQDDA5pZHAuc3NjLmNhcy5jejCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAJVgNZCivPcYuhqIHlM63jO4SezeeKwo
gJz8yWzcrsVzc/oJJnX3OXEjNue0DZWfnR8Q0MCtzP7viN4N5YHFujesLBP5tRZK
hb1QF+f7obvGtnocw1eqncWesCVYHINSTZoZLLbf+5ckdxVOXPL/GrVLP1uxYKRI
XgrjjcYuW8NqCEP/INgiwZW6uW5J9Y9sKTr6TD5NO12EgDuFO1hl0xOpIFWdNY6n
A2gQlWMwoY3YxTgjzb3h5O+BFhWrl/OzQOCtVrAjIlAubxYEssApfQ90YgTLOh6/
DPqDF2H8xpLpk8//1HDCBxDSnp2RRXnYrcIAGg8A/mNGiK5gOSlXMJ0CAwEAAaNj
MGEwHQYDVR0OBBYEFH2NPdHPXXO2zeB2IXMga733h1L7MEAGA1UdEQQ5MDeCDmlk
cC5zc2MuY2FzLmN6hiVodHRwczovL2lkcC5zc2MuY2FzLmN6L2lkcC9zaGliYm9s
ZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQBIp24cXH21EsJPUfa9EbYer83l1BS5bgG3
/7DIjJZg356RukerjOD9TYSyxYst7C/pmMPfd3v9Tbnpj6oNRsg8eRmT3FvbY4pT
1TK6h4moo/KruogrNwrK4PIPEFY8h5ynIxVz2fHNB4eitueFiP3o09u6bPnSgGyB
54KvQjxwEozm+gZ6nJGzgNXo+o4xkY9BILUAZSm6J7Br118pWU3AFNLGZ0Tqywju
kMVIyYOLWdkp5fvcrUJthN6Mga2hhyXQVtKF5rM61gAlobofFjDaiPydIG4Nkdku
aOsLsMa0+JqHIhyWCwtmBdrNAEEzxINQ4e4LaiIoCOEYgEE4Pvvj
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ssc.cas.cz:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
<md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.ssc.cas.cz:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
<md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
<md:SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.ssc.cas.cz/idp/profile/Shibboleth/SSO"/>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.ssc.cas.cz/idp/profile/SAML2/POST/SSO"/>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.ssc.cas.cz/idp/profile/SAML2/POST-SimpleSign/SSO"/>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.ssc.cas.cz/idp/profile/SAML2/Redirect/SSO"/>
</md:IDPSSODescriptor>
<md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
<md:Extensions>
<shibmd:Scope xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" regexp="false">ssc.cas.cz</shibmd:Scope>
</md:Extensions>
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDIzCCAgugAwIBAgIUH+9s+EsAoecplRXJyLBgG/ZkwmwwDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOaWRwLnNzYy5jYXMuY3owHhcNMTYxMDI0MDgyMTIxWhcN
MzYxMDI0MDgyMTIxWjAZMRcwFQYDVQQDDA5pZHAuc3NjLmNhcy5jejCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAOuB7cZZsm4Oq55kEmPuvZmSktAwrh3o
CMNHdg7vwB4Q9QSpdWEW7w7C3WvTR8q98DZ28iDTg51LosHqWwGwGpkDnMdt/6Z7
NS9JuWCFwrMwXnIB/rI6jvATSsQPTPuGtT4pz9hwgRYwMKqFEBNY3cZBMqlUyDYr
KHtFe5VfrS09vpRM4hse42dn+9WUXc4ddxzaP/mrZdN9aYvWyAa7PKhgEuvURSRq
SvrgizUVIdpV/+G7k851B0ozCMF0EsMd/gdku8WaF6kLdutgk30ijCy+8p/IGdhl
QynIXO6VmHqMl96y4Cq1b65NQ/ZKDczl9xqtn8hhAkc0d+tg6mOQwVsCAwEAAaNj
MGEwHQYDVR0OBBYEFHMCmxC0W8Q0Y93RjGBaEdA6YBJ7MEAGA1UdEQQ5MDeCDmlk
cC5zc2MuY2FzLmN6hiVodHRwczovL2lkcC5zc2MuY2FzLmN6L2lkcC9zaGliYm9s
ZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQBO+ImsGkiX/S+mv4K7Tw/AbfXtNKLF/8p+
9zFee91MUjISc/MNjj/KXa4GXk/N//bTQLHG8uua6w8kKdK04mg3AP6eaIKFjmfT
xRQBB56DYFetWd3XGGS8LDmZSrt/+MZd2APNOCfD+w5OoaHeIbgPFrRh07OMLyEv
afwMwJctLGTBbN7cFcXk294sGIwTPetuNfEfWH7UgHFEKcsiQ+zUWhMDJG+ex1n7
wwLM0eJnA2fMV0HB06IF3qt8DK/MHCSa9mx8LniCDESDTFMq/uMoXs+Jl6R3sVvp
IoENzXl0EGnCtFQmbRnSREKQFw96d6/lTHT3L9CE65Tr0kwIGhbt
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDIzCCAgugAwIBAgIUXPYLmocUcTH+oKw7G2+QXKvjEEQwDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOaWRwLnNzYy5jYXMuY3owHhcNMTYxMDI0MDgyMTE5WhcN
MzYxMDI0MDgyMTE5WjAZMRcwFQYDVQQDDA5pZHAuc3NjLmNhcy5jejCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAIxN9gtDpQWeqhbniCFVz2fsc8HvHjnf
Xa6Qx1h5XbgAIQ+EIjaD5rKsOe1ZtwTaeBD2BDnwMFD2hj+Q6Ujh7nxD6rn+Q2Ot
oLfYVbZSbv+8fvOl/mb4EMBCEguJMeUz5RmX04j3QpiriLNcjnWqXUS9WCYdRLjk
rnamOQygpN27TIPnoUHvCsoRn1wMODKKItdjLXiHDqEQqJ7K16DzS74GYRwktg85
P/kUJxB9Ff6Vs0RUXh8w37QPFgSdkItEWQQHMaaMGgpmufqLghTjA6zTVRJtX1Gs
dPW8zwdChhnOQan1MIa49UWXb76jQzoGNHfkAs77bdiOFViFiwqh+eMCAwEAAaNj
MGEwHQYDVR0OBBYEFPazSkIhwwoRQhMevpLNdKopcZALMEAGA1UdEQQ5MDeCDmlk
cC5zc2MuY2FzLmN6hiVodHRwczovL2lkcC5zc2MuY2FzLmN6L2lkcC9zaGliYm9s
ZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQAO4yaE/gCOhn9GOQ/3lWwXAnATn2sONKHe
cBLampWCuGUrvTqmrtHINJ3cEGi0Oaefw2M+t7LyxOt4IcEIf30TBOCDCZ/H0byI
BcfVrpSUHGMlU7Ar1TMG/vYsuOISZZvvJMBJDmKzMhrhT4SoE7W6Zt/pAJUXWkF9
Bp15VXtn80L4TqGrXWWjNesyd16UNYdUmL6kSDu2SHtvXHCqRBknVqVzu/ad84h+
WlvR75sMM4Z6s19foKRAvICkbgUQIZash4z8iKabi+9a4yY+WQmzS2LO16wmUyD+
PekHDlCio2wnMsWiQbs8R8TPVp841I/WkoZQ39GaNQAYT6qmpusg
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDIzCCAgugAwIBAgIUO+a4F1CQBqxJA1JElzFTYRCgOIswDQYJKoZIhvcNAQEL
BQAwGTEXMBUGA1UEAwwOaWRwLnNzYy5jYXMuY3owHhcNMTYxMDI0MDgyMTIwWhcN
MzYxMDI0MDgyMTIwWjAZMRcwFQYDVQQDDA5pZHAuc3NjLmNhcy5jejCCASIwDQYJ
KoZIhvcNAQEBBQADggEPADCCAQoCggEBAJVgNZCivPcYuhqIHlM63jO4SezeeKwo
gJz8yWzcrsVzc/oJJnX3OXEjNue0DZWfnR8Q0MCtzP7viN4N5YHFujesLBP5tRZK
hb1QF+f7obvGtnocw1eqncWesCVYHINSTZoZLLbf+5ckdxVOXPL/GrVLP1uxYKRI
XgrjjcYuW8NqCEP/INgiwZW6uW5J9Y9sKTr6TD5NO12EgDuFO1hl0xOpIFWdNY6n
A2gQlWMwoY3YxTgjzb3h5O+BFhWrl/OzQOCtVrAjIlAubxYEssApfQ90YgTLOh6/
DPqDF2H8xpLpk8//1HDCBxDSnp2RRXnYrcIAGg8A/mNGiK5gOSlXMJ0CAwEAAaNj
MGEwHQYDVR0OBBYEFH2NPdHPXXO2zeB2IXMga733h1L7MEAGA1UdEQQ5MDeCDmlk
cC5zc2MuY2FzLmN6hiVodHRwczovL2lkcC5zc2MuY2FzLmN6L2lkcC9zaGliYm9s
ZXRoMA0GCSqGSIb3DQEBCwUAA4IBAQBIp24cXH21EsJPUfa9EbYer83l1BS5bgG3
/7DIjJZg356RukerjOD9TYSyxYst7C/pmMPfd3v9Tbnpj6oNRsg8eRmT3FvbY4pT
1TK6h4moo/KruogrNwrK4PIPEFY8h5ynIxVz2fHNB4eitueFiP3o09u6bPnSgGyB
54KvQjxwEozm+gZ6nJGzgNXo+o4xkY9BILUAZSm6J7Br118pWU3AFNLGZ0Tqywju
kMVIyYOLWdkp5fvcrUJthN6Mga2hhyXQVtKF5rM61gAlobofFjDaiPydIG4Nkdku
aOsLsMa0+JqHIhyWCwtmBdrNAEEzxINQ4e4LaiIoCOEYgEE4Pvvj
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.ssc.cas.cz:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
</md:AttributeAuthorityDescriptor>
<md:Organization>
<md:OrganizationName xml:lang="en">Centre of Administration and Operations of ASCR</md:OrganizationName>
<md:OrganizationName xml:lang="cs">Středisko společných činností AV ČR</md:OrganizationName>
<md:OrganizationDisplayName xml:lang="en">Centre of Administration and Operations of ASCR, v. v. i.</md:OrganizationDisplayName>
<md:OrganizationDisplayName xml:lang="cs">Středisko společných činností AV ČR</md:OrganizationDisplayName>
<md:OrganizationURL xml:lang="en">http://www.ssc.cas.cz/</md:OrganizationURL>
<md:OrganizationURL xml:lang="cs">http://www.ssc.cas.cz/</md:OrganizationURL>
</md:Organization>
<md:ContactPerson contactType="technical">
<md:GivenName>Petr</md:GivenName>
<md:SurName>Vaníček</md:SurName>
<md:EmailAddress>vanicekp@utia.cas.cz</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
|