|
| 1 | +<?xml version='1.0' encoding='UTF-8'?> |
| 2 | +<md:EntitiesDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:mdui="urn:oasis:names:tc:SAML:metadata:ui" xmlns:mdattr="urn:oasis:names:tc:SAML:metadata:attribute" xmlns:mdrpi="urn:oasis:names:tc:SAML:metadata:rpi" xmlns:shibmd="urn:mace:shibboleth:metadata:1.0" xmlns:xrd="http://docs.oasis-open.org/ns/xri/xrd-1.0" xmlns:pyff="http://pyff.io/NS" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ser="http://eidas.europa.eu/metadata/servicelist" xmlns:eidas="http://eidas.europa.eu/saml-extensions" xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport" xmlns:samla="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" xmlns:wayf="http://sdss.ac.uk/2006/06/WAYF" xmlns:req-attr="urn:oasis:names:tc:SAML:protcol:ext:req-attr" Name="test"> |
| 3 | + <md:EntityDescriptor entityID="https://example.com/shibboleth"> |
| 4 | + <md:Extensions> |
| 5 | + <mdrpi:RegistrationInfo registrationAuthority="http://www.swamid.se/" registrationInstant="2015-02-11T11:09:51Z"> |
| 6 | + <mdrpi:RegistrationPolicy xml:lang="en">http://swamid.se/policy/mdrps</mdrpi:RegistrationPolicy> |
| 7 | + </mdrpi:RegistrationInfo> |
| 8 | + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> |
| 9 | + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> |
| 10 | + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> |
| 11 | + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/> |
| 12 | + <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> |
| 13 | + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/> |
| 14 | + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/> |
| 15 | + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/> |
| 16 | + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/> |
| 17 | + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/> |
| 18 | + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/> |
| 19 | + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> |
| 20 | + <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/> |
| 21 | + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/> |
| 22 | + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> |
| 23 | + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/> |
| 24 | + <mdattr:EntityAttributes> |
| 25 | + <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://macedir.org/entity-category"> |
| 26 | + <saml:AttributeValue>http://www.geant.net/uri/dataprotection-code-of-conduct/v1</saml:AttributeValue> |
| 27 | + </saml:Attribute> |
| 28 | + <saml:Attribute NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" Name="http://refeds.org/entity-selection-profile"> |
| 29 | + <saml:AttributeValue>ewogICJwcm9maWxlcyI6IHsKICAgICJpbmNvbW1vbi13YXlmaW5kZXIiOiB7CiAgICAgICAic3RyaWN0IjogdHJ1ZSwKICAgICAgICJlbnRpdGllcyI6IFsKICAgICAgICAgewogICAgICAgICAgICJzZWxlY3QiOiAiaHR0cHM6Ly9tZHEuaW5jb21tb24ub3JnL2VudGl0aWVzIiwKICAgICAgICAgICAibWF0Y2giOiAibWRfc291cmNlIiwKICAgICAgICAgICAiaW5jbHVkZSI6IHRydWUKICAgICAgICAgfQogICAgICAgXQogICAgfQogIH0KfQ==</saml:AttributeValue> |
| 30 | + </saml:Attribute> |
| 31 | + </mdattr:EntityAttributes> |
| 32 | + </md:Extensions> |
| 33 | + <md:SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> |
| 34 | + <md:Extensions> |
| 35 | + <init:RequestInitiator Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://cpauth.icos-cp.eu/saml/login"/> |
| 36 | + <mdui:UIInfo> |
| 37 | + <mdui:DisplayName xml:lang="en">Carbon Portal authentication service</mdui:DisplayName> |
| 38 | + <mdui:DisplayName xml:lang="sv">Kolportalens autentiseringstjänst</mdui:DisplayName> |
| 39 | + <mdui:Description xml:lang="en">Single Sign On for services of ICOS Carbon Portal. Maintained by the Carbon Portal team at Physical Geography department (nateko.lu.se).</mdui:Description> |
| 40 | + <mdui:Description xml:lang="sv">Single Sign On tjänst för ICOS Kolportalen. Hanteras av Carbon Portal teamet på INES (nateko.lu.se).</mdui:Description> |
| 41 | + <mdui:PrivacyStatementURL xml:lang="en">https://cpauth.icos-cp.eu/saml/privacyStatement</mdui:PrivacyStatementURL> |
| 42 | + <mdui:InformationURL xml:lang="en">https://www.icos-cp.eu/</mdui:InformationURL> |
| 43 | + <mdui:InformationURL xml:lang="sv">https://www.icos-cp.eu/</mdui:InformationURL> |
| 44 | + <mdui:PrivacyStatementURL xml:lang="sv">https://cpauth.icos-cp.eu/saml/privacyStatement</mdui:PrivacyStatementURL> |
| 45 | + </mdui:UIInfo> |
| 46 | + </md:Extensions> |
| 47 | + <md:KeyDescriptor> |
| 48 | + <ds:KeyInfo> |
| 49 | + <ds:KeyName>cpauth.icos-cp.eu</ds:KeyName> |
| 50 | + <ds:X509Data> |
| 51 | + <ds:X509SubjectName>CN=cpauth.icos-cp.eu</ds:X509SubjectName> |
| 52 | + <ds:X509Certificate>MIIEJzCCAw+gAwIBAgIJANC3VWNs7fbTMA0GCSqGSIb3DQEBCwUAMIGpMQswCQYD |
| 53 | +VQQGEwJTRTERMA8GA1UECAwIU2vDg8KlbmUxDTALBgNVBAcMBEx1bmQxGzAZBgNV |
| 54 | +BAoMEklDT1MgQ2FyYm9uIFBvcnRhbDEfMB0GA1UECwwWQXV0aGVudGljYXRpb24g |
| 55 | +U2VydmljZTEaMBgGA1UEAwwRY3BhdXRoLmljb3MtY3AuZXUxHjAcBgkqhkiG9w0B |
| 56 | +CQEWD2luZm9AaWNvcy1jcC5ldTAeFw0xNTAyMDUxMjI0MzZaFw0yNTAyMDIxMjI0 |
| 57 | +MzZaMIGpMQswCQYDVQQGEwJTRTERMA8GA1UECAwIU2vDg8KlbmUxDTALBgNVBAcM |
| 58 | +BEx1bmQxGzAZBgNVBAoMEklDT1MgQ2FyYm9uIFBvcnRhbDEfMB0GA1UECwwWQXV0 |
| 59 | +aGVudGljYXRpb24gU2VydmljZTEaMBgGA1UEAwwRY3BhdXRoLmljb3MtY3AuZXUx |
| 60 | +HjAcBgkqhkiG9w0BCQEWD2luZm9AaWNvcy1jcC5ldTCCASIwDQYJKoZIhvcNAQEB |
| 61 | +BQADggEPADCCAQoCggEBAM2QN1jaZJeuPAH+4sVMZKk7vg4JIbUuTMKk0+KIAg5M |
| 62 | +XiVsRiEUjY+LtIncrvA/kf2CIySI0WkbwZMjcDd03hNj4kLWhuyxfOCwDO6DsUbG |
| 63 | +MbyI6HIYWXJp5ljfEEFgtMqT3dDtD5vwq8h4Zy20ukxOoIokKczrAvn4JjkMsj6Z |
| 64 | +0CEAFBC29o4E8PWQbUBgvt6Z+2ao+RHMLD7nZVBx98Occ9KfnYnDDd9Oi1XFe009 |
| 65 | +zaSbcqY2RpN8I9hcW/KQf3KnGW5xZ5dr4rhGklCkYr+h0W3xKu+hin8bk91t1Dkr |
| 66 | +gaKl/N7M3Oof3k+7ZBlwaV97es5InWCeNgDxCGkBRNsCAwEAAaNQME4wHQYDVR0O |
| 67 | +BBYEFDcD7MVudooGaNRYqXBYqQi3VzGxMB8GA1UdIwQYMBaAFDcD7MVudooGaNRY |
| 68 | +qXBYqQi3VzGxMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBABS02eZS |
| 69 | +weXGMJ2fEIy2JH0VhCbjuX/rz+8Hfh9LjzNb3QwKHuwP83yvPqRulV9FYmvOoK8T |
| 70 | +fMou5aW0mZ+QgJNKOrxY5vFxUq6pn3OiYbBu3m1C9ajbU/nx2evzt4+qUwTfHFb+ |
| 71 | +ZgXpOtmxRekFzVvGZ18BSPJKwAAqqZ11X7skT/NwEAhbgplVPv9WkDmDzqNvHqQJ |
| 72 | +nyRgD2ZqUPU9nEOjGy0gI07dciVcYZQ+CiZeSECIWgQwjDEBDuwMCVAZA6gfdz6C |
| 73 | +KJuN+RUSKPEcxPxle1MiB4MU0ei5X4xUbvLWKn9Ok7TOXg2BpnMAv6eON1wVo0Aa |
| 74 | +D265cqy6Le/toVg=</ds:X509Certificate> |
| 75 | + </ds:X509Data> |
| 76 | + </ds:KeyInfo> |
| 77 | + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> |
| 78 | + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> |
| 79 | + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> |
| 80 | + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> |
| 81 | + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> |
| 82 | + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> |
| 83 | + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> |
| 84 | + <md:EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> |
| 85 | + <md:EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> |
| 86 | + </md:KeyDescriptor> |
| 87 | + <md:AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://cpauth.icos-cp.eu/saml/SAML2/POST" index="1" isDefault="true"/> |
| 88 | + <md:AttributeConsumingService index="1"> |
| 89 | + <md:ServiceName xml:lang="en">ICOS Carbon Portal SAML service</md:ServiceName> |
| 90 | + <md:ServiceName xml:lang="sv">ICOS Kolportalens SAML tjänst</md:ServiceName> |
| 91 | + <md:RequestedAttribute FriendlyName="givenName" Name="urn:oid:2.5.4.42" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> |
| 92 | + <md:RequestedAttribute FriendlyName="sn" Name="urn:oid:2.5.4.4" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> |
| 93 | + <md:RequestedAttribute FriendlyName="mail" Name="urn:oid:0.9.2342.19200300.100.1.3" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" isRequired="true"/> |
| 94 | + </md:AttributeConsumingService> |
| 95 | + </md:SPSSODescriptor> |
| 96 | + <md:Organization> |
| 97 | + <md:OrganizationName xml:lang="en">ICOS Carbon Portal</md:OrganizationName> |
| 98 | + <md:OrganizationName xml:lang="sv">ICOS Kolportalen</md:OrganizationName> |
| 99 | + <md:OrganizationDisplayName xml:lang="en">Carbon Portal</md:OrganizationDisplayName> |
| 100 | + <md:OrganizationDisplayName xml:lang="sv">Kolportalen</md:OrganizationDisplayName> |
| 101 | + <md:OrganizationURL xml:lang="en">https://www.icos-cp.eu/</md:OrganizationURL> |
| 102 | + <md:OrganizationURL xml:lang="sv">https://www.icos-cp.eu/</md:OrganizationURL> |
| 103 | + </md:Organization> |
| 104 | + <md:ContactPerson contactType="technical"> |
| 105 | + <md:GivenName>Oleg</md:GivenName> |
| 106 | + <md:SurName>Mirzov</md:SurName> |
| 107 | + < md:EmailAddress>mailto: [email protected]</ md:EmailAddress> |
| 108 | + </md:ContactPerson> |
| 109 | + <md:ContactPerson contactType="administrative"> |
| 110 | + <md:GivenName>Alex</md:GivenName> |
| 111 | + <md:SurName>Vermeulen</md:SurName> |
| 112 | + < md:EmailAddress>mailto: [email protected]</ md:EmailAddress> |
| 113 | + </md:ContactPerson> |
| 114 | +</md:EntityDescriptor></md:EntitiesDescriptor> |
0 commit comments