blob: a7c77ff5cb461a09a18b98cbecedf30807366a2f (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
|
<?xml version="1.0" encoding="UTF-8"?>
<md:EntityDescriptor xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://wayf.rcauth.eu/wayf/">
<md:Extensions>
<mdrpi:RegistrationInfo xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" registrationAuthority="http://www.surfconext.nl/" registrationInstant="2016-08-22T16:00:00Z">
<mdrpi:RegistrationPolicy xml:lang="en">https://wiki.surfnet.nl/display/eduGAIN/EduGAIN</mdrpi:RegistrationPolicy>
</mdrpi:RegistrationInfo>
<mdattr:EntityAttributes xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute">
<saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue>http://refeds.org/category/research-and-scholarship</saml:AttributeValue>
</saml:Attribute>
<saml:Attribute xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" Name="urn:oasis:names:tc:SAML:attribute:assurance-certification" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
<saml:AttributeValue xmlns:xs="http://www.w3.org/2001/XMLSchema" xsi:type="xs:string">https://refeds.org/sirtfi</saml:AttributeValue>
</saml:Attribute>
</mdattr:EntityAttributes>
</md:Extensions>
<md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:2.0:protocol">
<md:Extensions>
<mdui:UIInfo xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui">
<mdui:DisplayName xml:lang="en">RCAuth Pilot Online CA</mdui:DisplayName>
<mdui:Description xml:lang="en">RCAuth Pilot Online CA for providing end-user proxy certificates to Science Gateways and other portals</mdui:Description>
<mdui:InformationURL xml:lang="en">https://rcauth.eu/</mdui:InformationURL>
<mdui:PrivacyStatementURL xml:lang="en">https://rcauth.eu/privacy</mdui:PrivacyStatementURL>
<mdui:Logo width="800" height="388">http://rcauth.eu/images/RCauth-eu-logo.gif</mdui:Logo>
<mdui:Logo width="150" height="73">http://rcauth.eu/images/RCauth-eu-logo-150.gif</mdui:Logo>
</mdui:UIInfo>
</md:Extensions>
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDXTCCAkWgAwIBAgIJALR+hWgxJuxKMA0GCSqGSIb3DQEBCwUAMEUxEjAQBgoJkiaJk/IsZAEZFgJldTEWMBQGCgmSJomT8ixkARkWBnJjYXV0aDEXMBUGA1UEAwwOd2F5Zi5yY2F1dGguZXUwHhcNMTYwNjA5MTgzOTM3WhcNMzYwNzA5MTgzOTM3WjBFMRIwEAYKCZImiZPyLGQBGRYCZXUxFjAUBgoJkiaJk/IsZAEZFgZyY2F1dGgxFzAVBgNVBAMMDndheWYucmNhdXRoLmV1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvkp3v+IvRB/XTYpjjemICUba6w7R8UL3lIk3FSoYs0v/JcztpajiCbHdExGPUTckbFO3GY4YcoPcQH2NPzN37FQs8JuYpv+CTim+g43CIMW1nnZDQWxpeRGTl7Ih3sTY40MgQRhNUGtnJBHBCUFs8Yq9IDuljxhLMgZljUnUll5xFQjnBOcWsvtr6Z4vALSp7QkB15VqTkIVHzSq/iAvIcYGwWFt93xcdNRGQbTZ6bubp1MEGJxSA3+frBPE1Ee7geXpizY/gRUdTO+kj2dgqR+Jp1djwUIdcKvGDQf8Af9HUEPxRJdDef7TtoVbQsOoPJflzK+3tuQ5NAYGXZ2KYwIDAQABo1AwTjAdBgNVHQ4EFgQULHuCZRg2SEtDnLGxnCCVK57lA7UwHwYDVR0jBBgwFoAULHuCZRg2SEtDnLGxnCCVK57lA7UwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAQs8kXtotbAnEj1qZVls319nM1ES5cCY0e430HFJ7iF0mBDRyAGmuwnPrDcvHMFHALO2Gmj6WYcqNMSERjcACqTm700Qmz8RVnM2z1WoTQ0A65Xn4HKcy4lBppHtms5y/YaI9quBPynLIbd5jFLEakBidpoE/+kGwwov7067chebew61KArggd7SJnO5Y/35cdNF6PxilfXAdhSe5IZpKQptdYZ0mBS0mdcV6TDoH5pr2bVMJuggmRhQsSRW/H1x28krGyweGRFMohf5QEYogaEXig2QHcVT1pa3DIwgy9LJ803mEYYlf+ajnD/xXqyUV7qvZN8l6+p9Iob3SBEYOXQ==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIDXTCCAkWgAwIBAgIJALR+hWgxJuxKMA0GCSqGSIb3DQEBCwUAMEUxEjAQBgoJkiaJk/IsZAEZFgJldTEWMBQGCgmSJomT8ixkARkWBnJjYXV0aDEXMBUGA1UEAwwOd2F5Zi5yY2F1dGguZXUwHhcNMTYwNjA5MTgzOTM3WhcNMzYwNzA5MTgzOTM3WjBFMRIwEAYKCZImiZPyLGQBGRYCZXUxFjAUBgoJkiaJk/IsZAEZFgZyY2F1dGgxFzAVBgNVBAMMDndheWYucmNhdXRoLmV1MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAvkp3v+IvRB/XTYpjjemICUba6w7R8UL3lIk3FSoYs0v/JcztpajiCbHdExGPUTckbFO3GY4YcoPcQH2NPzN37FQs8JuYpv+CTim+g43CIMW1nnZDQWxpeRGTl7Ih3sTY40MgQRhNUGtnJBHBCUFs8Yq9IDuljxhLMgZljUnUll5xFQjnBOcWsvtr6Z4vALSp7QkB15VqTkIVHzSq/iAvIcYGwWFt93xcdNRGQbTZ6bubp1MEGJxSA3+frBPE1Ee7geXpizY/gRUdTO+kj2dgqR+Jp1djwUIdcKvGDQf8Af9HUEPxRJdDef7TtoVbQsOoPJflzK+3tuQ5NAYGXZ2KYwIDAQABo1AwTjAdBgNVHQ4EFgQULHuCZRg2SEtDnLGxnCCVK57lA7UwHwYDVR0jBBgwFoAULHuCZRg2SEtDnLGxnCCVK57lA7UwDAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAQs8kXtotbAnEj1qZVls319nM1ES5cCY0e430HFJ7iF0mBDRyAGmuwnPrDcvHMFHALO2Gmj6WYcqNMSERjcACqTm700Qmz8RVnM2z1WoTQ0A65Xn4HKcy4lBppHtms5y/YaI9quBPynLIbd5jFLEakBidpoE/+kGwwov7067chebew61KArggd7SJnO5Y/35cdNF6PxilfXAdhSe5IZpKQptdYZ0mBS0mdcV6TDoH5pr2bVMJuggmRhQsSRW/H1x28krGyweGRFMohf5QEYogaEXig2QHcVT1pa3DIwgy9LJ803mEYYlf+ajnD/xXqyUV7qvZN8l6+p9Iob3SBEYOXQ==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://wayf.rcauth.eu/wayf/module.php/saml/sp/saml2-logout.php/default-sp"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://wayf.rcauth.eu/wayf/module.php/saml/sp/saml2-acs.php/default-sp" index="0"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" Location="https://wayf.rcauth.eu/wayf/module.php/saml/sp/saml1-acs.php/default-sp" index="1"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://wayf.rcauth.eu/wayf/module.php/saml/sp/saml2-acs.php/default-sp" index="2"/>
<md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" Location="https://wayf.rcauth.eu/wayf/module.php/saml/sp/saml1-acs.php/default-sp/artifact" index="3"/>
<md:AttributeConsumingService index="0">
<md:ServiceName xml:lang="en">RCAuth.eu WAYF</md:ServiceName>
<md:ServiceDescription xml:lang="en">RCAuth Pilot Online CA for providing end-user proxy certificates to Science Gateways and other portals</md:ServiceDescription>
<md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.6" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonPrincipalName"/>
<md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.13" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonUniqueId"/>
<md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.10" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonTargetedID"/>
<md:RequestedAttribute Name="urn:oid:2.16.840.1.113730.3.1.241" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="displayName"/>
<md:RequestedAttribute Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="givenName"/>
<md:RequestedAttribute Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="sn"/>
<md:RequestedAttribute Name="urn:oid:2.5.4.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="cn"/>
<md:RequestedAttribute Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="mail"/>
<md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.5923.1.1.1.11" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="eduPersonAssurance"/>
<md:RequestedAttribute Name="urn:oid:1.3.6.1.4.1.25178.1.2.9" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" FriendlyName="schacHomeOrganization"/>
</md:AttributeConsumingService>
</md:SPSSODescriptor>
<md:Organization>
<md:OrganizationName xml:lang="en">Nikhef</md:OrganizationName>
<md:OrganizationDisplayName xml:lang="en">Nikhef</md:OrganizationDisplayName>
<md:OrganizationURL xml:lang="en">http://www.nikhef.nl</md:OrganizationURL>
</md:Organization>
<md:ContactPerson contactType="administrative">
<md:Company>RCAuth</md:Company>
<md:GivenName>Operator</md:GivenName>
<md:EmailAddress>ca@rcauth.eu</md:EmailAddress>
</md:ContactPerson>
<md:ContactPerson contactType="support">
<md:Company>RCAuth</md:Company>
<md:GivenName>Operator</md:GivenName>
<md:EmailAddress>ca@rcauth.eu</md:EmailAddress>
</md:ContactPerson>
<md:ContactPerson xmlns:remd="http://refeds.org/metadata" contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
<md:Company>Nikhef</md:Company>
<md:GivenName>CSIRT</md:GivenName>
<md:EmailAddress>security@nikhef.nl</md:EmailAddress>
<md:TelephoneNumber>+31205925090</md:TelephoneNumber>
</md:ContactPerson>
<md:ContactPerson contactType="technical">
<md:GivenName>Operator</md:GivenName>
<md:EmailAddress>ca@rcauth.eu</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
|