blob: ffc9d9736c4f06e145705896853c73bb6e82d96d (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
|
<?xml version="1.0" encoding="UTF-8"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://test.federation.renater.fr/validation/ressource">
<md:Extensions>
<mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="https://federation.renater.fr/" registrationInstant="2013-07-09T15:20:50Z">
<mdrpi:RegistrationPolicy xml:lang="en">https://services.renater.fr/federation/en/metadata_registration_practice_statement</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
<mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
<saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>https://federation.renater.fr/category/metier</saml:AttributeValue>
<saml:AttributeValue>https://federation.renater.fr/scope/national</saml:AttributeValue>
</saml:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
<md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
<mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui">
<mdui:DisplayName xml:lang="en">RENATER - validation service</mdui:DisplayName>
<mdui:InformationURL xml:lang="fr">https://test.federation.renater.fr/validation/ressource</mdui:InformationURL>
<mdui:Description xml:lang="en">This SP allows validation of identity providers. The resource prints the list of user attributes received from the identity provider.</mdui:Description>
<mdui:DisplayName xml:lang="fr">Fédération Éducation-Recherche - Ressource de validation</mdui:DisplayName>
<mdui:Description xml:lang="fr">Ressource de validation. Permettant la validation rapide d'un fonctionnement d'un IdP dans la fédération Éducation - Recherche. La ressource ne fait qu'afficher les attributs qui lui sont renvoyés par l'IdP.
Il faut configurer manuellement les filtres d'attributs pour cette ressource.</mdui:Description>
</mdui:UIInfo>
</md:Extensions>
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDADCCAeigAwIBAgIJAJo2eFCDBL32MA0GCSqGSIb3DQEBBQUAMB4xHDAaBgNV
BAMTE2ZlZHRvb2xzLnJlbmF0ZXIuZnIwHhcNMTMwNTEzMTQ0MDI5WhcNMjMwNTEx
MTQ0MDI5WjAeMRwwGgYDVQQDExNmZWR0b29scy5yZW5hdGVyLmZyMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsLeEy6JlbrAPEwxBrnvwcx2fN5WtZ9Eq
lZHBgQFocnfxEtHpf7KGSll+LNu3AgqF10Ymljoa1+Gn6E2SbsmKFmXzOs31aB5t
eu79nAGci1abkuius628KO33o4Cjc3rJ/M7Rk7Px4t9kH7R01bXn3z3UGTvmPNyo
mfa8LAX8epaD4haoar3ymF0hFHFB57d2HzWC/2HW/OT0Y5CO7T+dJd3TxI/soiK1
pdw75LYAOdW6MT+ozrw3vY53B4um7jBZK2OhsrKIjrG2e4s0CzWFPs7jCUGnuvaY
21nAd/kR666LjvmJcoVq/vErOSKksvMS9SxiuKpxjQNkj9lB9klqvQIDAQABo0Ew
PzAeBgNVHREEFzAVghNmZWR0b29scy5yZW5hdGVyLmZyMB0GA1UdDgQWBBSglPv7
4KwzHQSzBtZphKPBskiQ5TANBgkqhkiG9w0BAQUFAAOCAQEArYVUgbOsV3U+/Xb/
NPPYIYdej09vWmdwOQjCjJc/DHiEkDPHQ4R/zbTEXPcW+t0CpYET2t/5MskmKNU7
vgkZLdw9GrRbXuJarzZZ1ZSdMDNKvMjgujOJfcgQ6KnbSi/KLniU7hagAsvzQkYQ
CXZqh5Jo6zGSJZIPTx3EpRuT82WFoFpcoccWeTSsda/A5nTQnq/1SpwBnfGz+xtE
alqV781u8dMtyty6cbwPSg3sYisSoXQRdl+4b7U3vGXQvbHM6PNEAljhkeX0+1Tk
aCoF678JhADPvQCtWTWZsbIFhV7bOsG+8UFqdH6z+yPMWUCPx6WbbTkkusi23Tbe
PbS4vQ==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>
MIIDADCCAeigAwIBAgIJAJo2eFCDBL32MA0GCSqGSIb3DQEBBQUAMB4xHDAaBgNV
BAMTE2ZlZHRvb2xzLnJlbmF0ZXIuZnIwHhcNMTMwNTEzMTQ0MDI5WhcNMjMwNTEx
MTQ0MDI5WjAeMRwwGgYDVQQDExNmZWR0b29scy5yZW5hdGVyLmZyMIIBIjANBgkq
hkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAsLeEy6JlbrAPEwxBrnvwcx2fN5WtZ9Eq
lZHBgQFocnfxEtHpf7KGSll+LNu3AgqF10Ymljoa1+Gn6E2SbsmKFmXzOs31aB5t
eu79nAGci1abkuius628KO33o4Cjc3rJ/M7Rk7Px4t9kH7R01bXn3z3UGTvmPNyo
mfa8LAX8epaD4haoar3ymF0hFHFB57d2HzWC/2HW/OT0Y5CO7T+dJd3TxI/soiK1
pdw75LYAOdW6MT+ozrw3vY53B4um7jBZK2OhsrKIjrG2e4s0CzWFPs7jCUGnuvaY
21nAd/kR666LjvmJcoVq/vErOSKksvMS9SxiuKpxjQNkj9lB9klqvQIDAQABo0Ew
PzAeBgNVHREEFzAVghNmZWR0b29scy5yZW5hdGVyLmZyMB0GA1UdDgQWBBSglPv7
4KwzHQSzBtZphKPBskiQ5TANBgkqhkiG9w0BAQUFAAOCAQEArYVUgbOsV3U+/Xb/
NPPYIYdej09vWmdwOQjCjJc/DHiEkDPHQ4R/zbTEXPcW+t0CpYET2t/5MskmKNU7
vgkZLdw9GrRbXuJarzZZ1ZSdMDNKvMjgujOJfcgQ6KnbSi/KLniU7hagAsvzQkYQ
CXZqh5Jo6zGSJZIPTx3EpRuT82WFoFpcoccWeTSsda/A5nTQnq/1SpwBnfGz+xtE
alqV781u8dMtyty6cbwPSg3sYisSoXQRdl+4b7U3vGXQvbHM6PNEAljhkeX0+1Tk
aCoF678JhADPvQCtWTWZsbIFhV7bOsG+8UFqdH6z+yPMWUCPx6WbbTkkusi23Tbe
PbS4vQ==
</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://test.federation.renater.fr/validation/ressource/Shibboleth.sso/SAML2/POST" index="1"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://test.federation.renater.fr/validation/ressource/Shibboleth.sso/SAML/POST" index="5"/>
<md:AttributeConsumingService index="0">
<md:ServiceName xml:lang="fr">Fédération Éducation-Recherche - Ressource de validation</md:ServiceName>
<md:ServiceName xml:lang="en">RENATER - validation service</md:ServiceName>
<md:ServiceDescription xml:lang="fr">Ressource de validation. Permettant la validation rapide d'un fonctionnement d'un IdP dans la fédération Éducation - Recherche. La ressource ne fait qu'afficher les attributs qui lui sont renvoyés par l'IdP.
Il faut configurer manuellement les filtres d'attributs pour cette ressource.</md:ServiceDescription>
<md:ServiceDescription xml:lang="en">This SP allows validation of identity providers. The resource prints the list of user attributes received from the identity provider.</md:ServiceDescription>
<md:RequestedAttribute FriendlyName="uid" Name="urn:oid:0.9.2342.19200300.100.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="mobile" Name="urn:oid:0.9.2342.19200300.100.1.41" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="labeledURI" Name="urn:oid:1.3.6.1.4.1.250.1.57" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="schacHomeOrganizationType" Name="urn:oid:1.3.6.1.4.1.25178.1.2.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="schacHomeOrganization" Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonTargetedID" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonNickname" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.2" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonOrgDN" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonOrgUnitDN" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonPrimaryAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.5" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonPrincipalName" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonEntitlement" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.7" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonPrimaryOrgUnitDN" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.8" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduPersonScopedAffiliation" Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="eduOrgLegalName" Name="urn:oid:1.3.6.1.4.1.5923.1.2.1.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannListeRouge" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.1" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEtuId" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEmpId" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannAutreTelephone" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.12" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEntiteAffectationPrincipale" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.13" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEtablissement" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.14" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannMailPerso" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.15" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannActivite" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.2" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannRole" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.21" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannRoleGenerique" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.23" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannRoleEntite" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.24" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEtuAnneeInscription" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.25" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEtuCursusAnnee" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.26" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEtuDiplome" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.27" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEtuElementPedagogique" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.28" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEtuEtape" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.29" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannOrganisme" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEtuInscription" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.30" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEtuRegimeInscription" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.31" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEtuSecteurDisciplinaire" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.32" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEtuTypeDiplome" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.33" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannAutreMail" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.34" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannCivilite" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannAffectation" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.5" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannEntiteAffectation" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.8" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="supannCodeINE" Name="urn:oid:1.3.6.1.4.1.7135.1.2.1.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="mailForwardingAddress" Name="urn:oid:2.16.840.1.113730.3.1.17" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="displayName" Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="preferredLanguage" Name="urn:oid:2.16.840.1.113730.3.1.39" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="o" Name="urn:oid:2.5.4.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="ou" Name="urn:oid:2.5.4.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="title" Name="urn:oid:2.5.4.12" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="postalAddress" Name="urn:oid:2.5.4.16" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="telephoneNumber" Name="urn:oid:2.5.4.20" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="facsimileTelephoneNumber" Name="urn:oid:2.5.4.23" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="cn" Name="urn:oid:2.5.4.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="userCertificate" Name="urn:oid:2.5.4.36" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
<md:RequestedAttribute FriendlyName="l" Name="urn:oid:2.5.4.7" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/>
</md:AttributeConsumingService>
</md:SPSSODescriptor>
<md:Organization>
<md:OrganizationName xml:lang="en">GIP RENATER</md:OrganizationName>
<md:OrganizationDisplayName xml:lang="en">GIP RENATER</md:OrganizationDisplayName>
<md:OrganizationURL xml:lang="en">http://www.renater.fr</md:OrganizationURL>
</md:Organization>
<md:ContactPerson contactType="technical">
<md:SurName>Sebastien Medard</md:SurName>
<md:EmailAddress>sebastien.medard@renater.fr</md:EmailAddress>
</md:ContactPerson>
<md:ContactPerson contactType="technical">
<md:SurName>Olivier Salaün</md:SurName>
<md:EmailAddress>olivier.salaun@renater.fr</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
|