blob: 28ca74b7f80ba4596c9d3d52e9ea8167861fa623 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
|
<?xml version="1.0" encoding="UTF-8"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://idp.utia.cas.cz/idp/shibboleth">
<md:Extensions>
<eduidmd:RepublishRequest xmlns:eduidmd="http://eduid.cz/schema/metadata/1.0">
<eduidmd:RepublishTarget>http://edugain.org/</eduidmd:RepublishTarget>
</eduidmd:RepublishRequest>
<mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="http://www.eduid.cz/" registrationInstant="2014-03-07T08:48:51Z">
<mdrpi:RegistrationPolicy xml:lang="en">http://www.eduid.cz/wiki/_media/en/eduid/policy/policy_eduid_en-1_1.pdf</mdrpi:RegistrationPolicy>
<mdrpi:RegistrationPolicy xml:lang="cs">http://www.eduid.cz/wiki/_media/eduid/policy/policy_eduid_cz-1_1-3.pdf</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
<mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
<saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>http://eduid.cz/uri/idp-group/avcr</saml:AttributeValue>
</saml:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
<md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:mace:shibboleth:1.0">
<md:Extensions>
<shibmd:Scope xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" regexp="false">utia.cas.cz</shibmd:Scope>
<mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui">
<mdui:DisplayName xml:lang="en">Institute of Information Theory and Automation AS CR</mdui:DisplayName>
<mdui:DisplayName xml:lang="cs">Ústav teorie informace a automatizace AV ČR</mdui:DisplayName>
<mdui:Description xml:lang="en">Identity Provider UTIA AV CR employees.</mdui:Description>
<mdui:Description xml:lang="cs">Identity Provider pro zaměstnance ÚTIA AV ČR</mdui:Description>
<mdui:InformationURL xml:lang="en">http://www.utia.cas.cz/</mdui:InformationURL>
<mdui:InformationURL xml:lang="cs">http://www.utia.cas.cz/</mdui:InformationURL>
<mdui:Logo height="44" width="74">https://gedeon.cas.cz/loga/logo-utia-44.png</mdui:Logo>
<mdui:Logo height="411" width="960">https://gedeon.cas.cz/loga/logo-utia-411.png</mdui:Logo>
</mdui:UIInfo>
</md:Extensions>
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDJzCCAg+gAwIBAgIUVCoZ7ODsGasBcM+RvG51oUU2emswDQYJKoZIhvcNAQEL
BQAwGjEYMBYGA1UEAwwPaWRwLnV0aWEuY2FzLmN6MB4XDTE2MDUxMDA3NDczNFoX
DTM2MDUxMDA3NDczNFowGjEYMBYGA1UEAwwPaWRwLnV0aWEuY2FzLmN6MIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAjruOWHCfO056R1m1rZcYhLK5TyvY
elkRKMzYNOZsl9TfvTXEgJDRynxRWtHpjLifp60/+LHjQfgJ/AgqgjPsc0h7wB4c
nSd/jWb9zEXlIBXThHG5/nI+LNqB8MXs0UVThzLL16k3fX1DAoom+Kw4uYbalrAb
it2/WDYquOoCYNux8U7JaP0rR86hg5CvhLL3/M9Ecp9yH69VXAV0qN4p2UKb51ue
P7JbXswpK3CMJ2+W0zVRgor0W7JOJSqa1nzqfH+6uBU+MpIhV0IYmXsBMsjpl6gO
UJ19LdLuXcHOfNsLLEIDfOAO8rsJnDDj/Gm8g++uNxPLO7pIPmy3QLlTVQIDAQAB
o2UwYzAdBgNVHQ4EFgQUsIFyUtCTMUh4GdmwBM042BCR35gwQgYDVR0RBDswOYIP
aWRwLnV0aWEuY2FzLmN6hiZodHRwczovL2lkcC51dGlhLmNhcy5jei9pZHAvc2hp
YmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAZ2/ouJcgRIhHpitQa5tfm9cY8bAf
T3PlI9i2wrTBNxpGaOgSGTdwgOPaQFkhlQlbnsuaS+lBTBeoPachiiPri7iD34TF
a0rUGydcfe0WCtjehAnxaDNLN+94IKjGKe8b3jt/mzTbsDamSSqesj+l390zEWex
F7ZWWTl01IH78lNjzMJUZwdfLLW8fYorMkKLtr0enMP1NC7LoB3vC4miKw+ouAw6
G09GnvfeK6Psq/kTDKuDyyrhbJddnXXra6OHfKl7RFPH4WAxbmsJYGYm5YyxnA53
HOuVmLiSmuazcRQpzKBs/0vnKUQLsmsI5qywWNGaFhXLqCIPv2pOywwyWQ==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDKDCCAhCgAwIBAgIVANqdmG7MzbTHfpoxa6zUyqvBfqyNMA0GCSqGSIb3DQEB
CwUAMBoxGDAWBgNVBAMMD2lkcC51dGlhLmNhcy5jejAeFw0xNjA1MTAwNzQ3MzJa
Fw0zNjA1MTAwNzQ3MzJaMBoxGDAWBgNVBAMMD2lkcC51dGlhLmNhcy5jejCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJuLDClp+Zgdh3ddMGQfyEHeZgpV
p3RffukqtbQTgjrsi8Jeyqt9ShZvncaMaqKV2+3UK6/ZnIKhfAHNoDHSHgMBsq8T
7F2W/PWZCKuLZGSo6qP6wpSKSFgU3BxI3smjq6QEFbRwIbJukCJgQmuXokTwByJK
7cbkCOtBJomzUvdwstPxHK3WXh6qcK8HFNwqNPs8lrCXUnbrN8oU1yLZiVZ0QM9x
cIKD9iNxUJzFYQ7EBEglKxa2N10nfiItJS2g82qEHyitpN74aK/ZFSi7+c3/EXxw
Fa7xFOVDitGPq0R63mF33QFnuVTE20iptP5Rnho3Uy3SqX0zz22vc99I/hMCAwEA
AaNlMGMwHQYDVR0OBBYEFMA8iy6wksZf7nv62jauDUDrpIIJMEIGA1UdEQQ7MDmC
D2lkcC51dGlhLmNhcy5jeoYmaHR0cHM6Ly9pZHAudXRpYS5jYXMuY3ovaWRwL3No
aWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBABeFoO/Bc26/+A3iUG6m5gkHftYc
pAHmIeZPS1UGlE25jtyrgJl/iwYsK4tgNg+UCD39ur8XPCdwBIqYBtHbymple0Dc
/hD5vpM2xX5sLgd7PUf1ZeGf4F8FtYgxcW1XmIArWN7R55PaeuOeJ6u97vcKDeCB
VwQQbvVfBHCHzuN4ssBB9lt7VrVHTUUBLi16iS4iX5YpxKTT0DleysfHr2GLiQCu
1GMXMsilxgUT6+sg8C447hQSu4pZX4HhR7w0D/871njGUjtfJz7b9zWu7FNDXJf7
fcbXMlSxq+WEOxFY5ZBhFsDMi2QH1GfpR02V1g8lDjfZ+VP+PpriqEJsvNY=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDJzCCAg+gAwIBAgIUY/hbQh1yZ2je5HRjYl69seoR234wDQYJKoZIhvcNAQEL
BQAwGjEYMBYGA1UEAwwPaWRwLnV0aWEuY2FzLmN6MB4XDTE2MDUxMDA3NDczM1oX
DTM2MDUxMDA3NDczM1owGjEYMBYGA1UEAwwPaWRwLnV0aWEuY2FzLmN6MIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAk+qJwtsnqNHhDlOEK4+T8O+fSHUt
HiTuAdsqTLS6OGLg4URhvlegYV5mnR2wuzi10iwryp7xuSn0z861mP5RR4XeI+Gr
HKDuY1M28LpI0S+blEQQK39EqzkR4UBp909eqzEV+kH7OTkW+eAUqWKXL2PUvxGx
IIYa9oEogcINawWh8E4vJbIVortOYupc2CI+Y55Fj1uCcxwhkm8se/W5VKkLUtxN
7kSDhjLeNV/OvZ1ezsSZV74amssJ+eEOFqNtgSUtJEDqXZRfnsL9pI0QjDO42VaE
SVmmrXH+H68fXosUmo5tTGW8XC/X4CdI0pXqUu+BOvAi5ry2AEa+Bx7EJwIDAQAB
o2UwYzAdBgNVHQ4EFgQU6uWE18BSvgMG3obMkDV2ZBhRyMEwQgYDVR0RBDswOYIP
aWRwLnV0aWEuY2FzLmN6hiZodHRwczovL2lkcC51dGlhLmNhcy5jei9pZHAvc2hp
YmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAOueAMdQeIdGR4cMjubUXGRAhHxjC
N1X1GCBIYu0qOtYW+ZdBHXNcdKHmwx07vG5sD3eJ4Vgk/42F+3y5m8WSW8e+X07n
rIEloi1nYSwzsKqmsMqMZPr8XofAGWLDckDaZPIeZcstVUCIM33poO0q5BbFkGNi
k/o+oZPQ0qGarGpuoCkAqN7pU4H+O0Ud6mwKUfa9CZ6Zgo6kS6U1ETMN42kh+W5G
UAA1gxjj2ty44WzARV3w5IfuX+xC/cNgu7G7wdwvhbsSB4YE1KWLJ8il2TudE9N9
RhTsHUGwbFmwQ+kjD5opXKF38qnSsB9pdSR+imsqzeAcOeLpe0jBgaGD1w==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.utia.cas.cz:8443/idp/profile/SAML1/SOAP/ArtifactResolution" index="1"/>
<md:ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://idp.utia.cas.cz:8443/idp/profile/SAML2/SOAP/ArtifactResolution" index="2"/>
<md:NameIDFormat>urn:mace:shibboleth:1.0:nameIdentifier</md:NameIDFormat>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat>
<md:SingleSignOnService Binding="urn:mace:shibboleth:1.0:profiles:AuthnRequest" Location="https://idp.utia.cas.cz/idp/profile/Shibboleth/SSO"/>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://idp.utia.cas.cz/idp/profile/SAML2/POST/SSO"/>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://idp.utia.cas.cz/idp/profile/SAML2/POST-SimpleSign/SSO"/>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.utia.cas.cz/idp/profile/SAML2/Redirect/SSO"/>
</md:IDPSSODescriptor>
<md:AttributeAuthorityDescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol">
<md:Extensions>
<shibmd:Scope xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" regexp="false">utia.cas.cz</shibmd:Scope>
</md:Extensions>
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDJzCCAg+gAwIBAgIUVCoZ7ODsGasBcM+RvG51oUU2emswDQYJKoZIhvcNAQEL
BQAwGjEYMBYGA1UEAwwPaWRwLnV0aWEuY2FzLmN6MB4XDTE2MDUxMDA3NDczNFoX
DTM2MDUxMDA3NDczNFowGjEYMBYGA1UEAwwPaWRwLnV0aWEuY2FzLmN6MIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAjruOWHCfO056R1m1rZcYhLK5TyvY
elkRKMzYNOZsl9TfvTXEgJDRynxRWtHpjLifp60/+LHjQfgJ/AgqgjPsc0h7wB4c
nSd/jWb9zEXlIBXThHG5/nI+LNqB8MXs0UVThzLL16k3fX1DAoom+Kw4uYbalrAb
it2/WDYquOoCYNux8U7JaP0rR86hg5CvhLL3/M9Ecp9yH69VXAV0qN4p2UKb51ue
P7JbXswpK3CMJ2+W0zVRgor0W7JOJSqa1nzqfH+6uBU+MpIhV0IYmXsBMsjpl6gO
UJ19LdLuXcHOfNsLLEIDfOAO8rsJnDDj/Gm8g++uNxPLO7pIPmy3QLlTVQIDAQAB
o2UwYzAdBgNVHQ4EFgQUsIFyUtCTMUh4GdmwBM042BCR35gwQgYDVR0RBDswOYIP
aWRwLnV0aWEuY2FzLmN6hiZodHRwczovL2lkcC51dGlhLmNhcy5jei9pZHAvc2hp
YmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAZ2/ouJcgRIhHpitQa5tfm9cY8bAf
T3PlI9i2wrTBNxpGaOgSGTdwgOPaQFkhlQlbnsuaS+lBTBeoPachiiPri7iD34TF
a0rUGydcfe0WCtjehAnxaDNLN+94IKjGKe8b3jt/mzTbsDamSSqesj+l390zEWex
F7ZWWTl01IH78lNjzMJUZwdfLLW8fYorMkKLtr0enMP1NC7LoB3vC4miKw+ouAw6
G09GnvfeK6Psq/kTDKuDyyrhbJddnXXra6OHfKl7RFPH4WAxbmsJYGYm5YyxnA53
HOuVmLiSmuazcRQpzKBs/0vnKUQLsmsI5qywWNGaFhXLqCIPv2pOywwyWQ==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDKDCCAhCgAwIBAgIVANqdmG7MzbTHfpoxa6zUyqvBfqyNMA0GCSqGSIb3DQEB
CwUAMBoxGDAWBgNVBAMMD2lkcC51dGlhLmNhcy5jejAeFw0xNjA1MTAwNzQ3MzJa
Fw0zNjA1MTAwNzQ3MzJaMBoxGDAWBgNVBAMMD2lkcC51dGlhLmNhcy5jejCCASIw
DQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJuLDClp+Zgdh3ddMGQfyEHeZgpV
p3RffukqtbQTgjrsi8Jeyqt9ShZvncaMaqKV2+3UK6/ZnIKhfAHNoDHSHgMBsq8T
7F2W/PWZCKuLZGSo6qP6wpSKSFgU3BxI3smjq6QEFbRwIbJukCJgQmuXokTwByJK
7cbkCOtBJomzUvdwstPxHK3WXh6qcK8HFNwqNPs8lrCXUnbrN8oU1yLZiVZ0QM9x
cIKD9iNxUJzFYQ7EBEglKxa2N10nfiItJS2g82qEHyitpN74aK/ZFSi7+c3/EXxw
Fa7xFOVDitGPq0R63mF33QFnuVTE20iptP5Rnho3Uy3SqX0zz22vc99I/hMCAwEA
AaNlMGMwHQYDVR0OBBYEFMA8iy6wksZf7nv62jauDUDrpIIJMEIGA1UdEQQ7MDmC
D2lkcC51dGlhLmNhcy5jeoYmaHR0cHM6Ly9pZHAudXRpYS5jYXMuY3ovaWRwL3No
aWJib2xldGgwDQYJKoZIhvcNAQELBQADggEBABeFoO/Bc26/+A3iUG6m5gkHftYc
pAHmIeZPS1UGlE25jtyrgJl/iwYsK4tgNg+UCD39ur8XPCdwBIqYBtHbymple0Dc
/hD5vpM2xX5sLgd7PUf1ZeGf4F8FtYgxcW1XmIArWN7R55PaeuOeJ6u97vcKDeCB
VwQQbvVfBHCHzuN4ssBB9lt7VrVHTUUBLi16iS4iX5YpxKTT0DleysfHr2GLiQCu
1GMXMsilxgUT6+sg8C447hQSu4pZX4HhR7w0D/871njGUjtfJz7b9zWu7FNDXJf7
fcbXMlSxq+WEOxFY5ZBhFsDMi2QH1GfpR02V1g8lDjfZ+VP+PpriqEJsvNY=
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDJzCCAg+gAwIBAgIUY/hbQh1yZ2je5HRjYl69seoR234wDQYJKoZIhvcNAQEL
BQAwGjEYMBYGA1UEAwwPaWRwLnV0aWEuY2FzLmN6MB4XDTE2MDUxMDA3NDczM1oX
DTM2MDUxMDA3NDczM1owGjEYMBYGA1UEAwwPaWRwLnV0aWEuY2FzLmN6MIIBIjAN
BgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAk+qJwtsnqNHhDlOEK4+T8O+fSHUt
HiTuAdsqTLS6OGLg4URhvlegYV5mnR2wuzi10iwryp7xuSn0z861mP5RR4XeI+Gr
HKDuY1M28LpI0S+blEQQK39EqzkR4UBp909eqzEV+kH7OTkW+eAUqWKXL2PUvxGx
IIYa9oEogcINawWh8E4vJbIVortOYupc2CI+Y55Fj1uCcxwhkm8se/W5VKkLUtxN
7kSDhjLeNV/OvZ1ezsSZV74amssJ+eEOFqNtgSUtJEDqXZRfnsL9pI0QjDO42VaE
SVmmrXH+H68fXosUmo5tTGW8XC/X4CdI0pXqUu+BOvAi5ry2AEa+Bx7EJwIDAQAB
o2UwYzAdBgNVHQ4EFgQU6uWE18BSvgMG3obMkDV2ZBhRyMEwQgYDVR0RBDswOYIP
aWRwLnV0aWEuY2FzLmN6hiZodHRwczovL2lkcC51dGlhLmNhcy5jei9pZHAvc2hp
YmJvbGV0aDANBgkqhkiG9w0BAQsFAAOCAQEAOueAMdQeIdGR4cMjubUXGRAhHxjC
N1X1GCBIYu0qOtYW+ZdBHXNcdKHmwx07vG5sD3eJ4Vgk/42F+3y5m8WSW8e+X07n
rIEloi1nYSwzsKqmsMqMZPr8XofAGWLDckDaZPIeZcstVUCIM33poO0q5BbFkGNi
k/o+oZPQ0qGarGpuoCkAqN7pU4H+O0Ud6mwKUfa9CZ6Zgo6kS6U1ETMN42kh+W5G
UAA1gxjj2ty44WzARV3w5IfuX+xC/cNgu7G7wdwvhbsSB4YE1KWLJ8il2TudE9N9
RhTsHUGwbFmwQ+kjD5opXKF38qnSsB9pdSR+imsqzeAcOeLpe0jBgaGD1w==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:AttributeService Binding="urn:oasis:names:tc:SAML:1.0:bindings:SOAP-binding" Location="https://idp.utia.cas.cz:8443/idp/profile/SAML1/SOAP/AttributeQuery"/>
</md:AttributeAuthorityDescriptor>
<md:Organization>
<md:OrganizationName xml:lang="en">Institute of Information Theory and Automation</md:OrganizationName>
<md:OrganizationName xml:lang="cs">Ústav teorie informace a automatizace AV ČR</md:OrganizationName>
<md:OrganizationDisplayName xml:lang="en">Institute of Information Theory and Automation, Public Research Institution</md:OrganizationDisplayName>
<md:OrganizationDisplayName xml:lang="cs">Ústav teorie informace a automatizace AV ČR, v.v.i.</md:OrganizationDisplayName>
<md:OrganizationURL xml:lang="en">http://www.utia.cas.cz/</md:OrganizationURL>
<md:OrganizationURL xml:lang="cs">http://www.utia.cas.cz/</md:OrganizationURL>
</md:Organization>
<md:ContactPerson contactType="technical">
<md:GivenName>Petr</md:GivenName>
<md:SurName>Vaníček</md:SurName>
<md:EmailAddress>vanicekp@utia.cas.cz</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
|