From 67db1503f0b2d337f04697993446024adceb0c7c Mon Sep 17 00:00:00 2001
From: Ryan Rumbaugh <rrumbaugh@nebraska.edu>
Date: Thu, 17 Nov 2022 11:39:59 -0600
Subject: [PATCH] Resolve "Onboard production Lincoln student success hub"

---
 nefed.xml | 69 +++++++++++++++++++++++++++++++++++++++++++++++++++++++
 1 file changed, 69 insertions(+)

diff --git a/nefed.xml b/nefed.xml
index c8b02ae..1822c6a 100644
--- a/nefed.xml
+++ b/nefed.xml
@@ -18757,4 +18757,73 @@ bHwSoBy5hLPNALaEUoa5zPDwlixwRjFQTc5XXaRpgIjy/2gsL8+Y5QRhyXnLqgO67BlLYW/GuHE=</ds
             <EmailAddress>security@nebraska.edu</EmailAddress>
         </ContactPerson>
     </EntityDescriptor>
+    <EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://unlincoln.force.com/SSH" xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
+        <Extensions>
+           <mdrpi:RegistrationInfo registrationAuthority="https://nebraska.edu/nefed" />
+           <mdattr:EntityAttributes>
+              <saml:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
+                 <saml:AttributeValue>https://nebraska.edu/category/registered-by-nefed</saml:AttributeValue>
+              </saml:Attribute>
+           </mdattr:EntityAttributes>
+           <mdui:UIInfo>
+              <mdui:DisplayName xml:lang="en">Lincoln Student Success Hub</mdui:DisplayName>
+              <mdui:Description xml:lang="en">Lincoln Student Success Hub</mdui:Description>
+              <mdui:InformationURL xml:lang="en">https://unlincoln.force.com/SSH</mdui:InformationURL>
+              <mdui:PrivacyStatementURL xml:lang="en">https://unlincoln.force.com/SSH</mdui:PrivacyStatementURL>
+           </mdui:UIInfo>
+        </Extensions>
+        <SPSSODescriptor AuthnRequestsSigned="true" WantAssertionsSigned="true" protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
+           <KeyDescriptor use="signing">
+              <ds:KeyInfo>
+                 <ds:X509Data>
+                    <ds:X509Certificate>MIIErDCCA5SgAwIBAgIOAYJlndbjAAAAAAGX+50wDQYJKoZIhvcNAQELBQAwgZAx KDAmBgNVBAMMH1NlbGZTaWduZWRDZXJ0XzAzQXVnMjAyMl8xNjMwMjIxGDAWBgNV BAsMDzAwRDVlMDAwMDAwSnNjQjEXMBUGA1UECgwOU2FsZXNmb3JjZS5jb20xFjAU BgNVBAcMDVNhbiBGcmFuY2lzY28xCzAJBgNVBAgMAkNBMQwwCgYDVQQGEwNVU0Ew HhcNMjIwODAzMjEzMDE5WhcNMjMwODAzMTIwMDAwWjCBkDEoMCYGA1UEAwwfU2Vs ZlNpZ25lZENlcnRfMDNBdWcyMDIyXzE2MzAyMjEYMBYGA1UECwwPMDBENWUwMDAw MDBKc2NCMRcwFQYDVQQKDA5TYWxlc2ZvcmNlLmNvbTEWMBQGA1UEBwwNU2FuIEZy YW5jaXNjbzELMAkGA1UECAwCQ0ExDDAKBgNVBAYTA1VTQTCCASIwDQYJKoZIhvcN AQEBBQADggEPADCCAQoCggEBALw9Xc01ZJpapWMoXUqc5vo0/ujJ7U11Ixq2MP5w GV0+4zFHa3Hrq6+FPNSkLYq2/gkXnvNZtIAb7JV2GmghwrgsJ8W2TSF+Q0+VDPog Er14/LPIVx+XCx0KPHLMubnIYMXCHnLrQLJKOKePxbSB0kHZo2pNRtHWup5lUtQk bcaTTflqokls+08n+me/odc4MAestjIbK1abmiC1jABE/PRIfeQBX7TNE7ChuTPF 3eQ7gHN3+ChaU8Z3vBuHiymOHHyddp4FXRyXYQP3iyvYUR3Gtgtt0GKDcz2RUgMS Hc5zMkKkyvjUevakoOiZt2pDPVVMlaOgtn38Z9wObsmgBPECAwEAAaOCAQAwgf0w HQYDVR0OBBYEFCZqJIdhsTtwdn1KdJee2kD0LX4gMA8GA1UdEwEB/wQFMAMBAf8w gcoGA1UdIwSBwjCBv4AUJmokh2GxO3B2fUp0l57aQPQtfiChgZakgZMwgZAxKDAm BgNVBAMMH1NlbGZTaWduZWRDZXJ0XzAzQXVnMjAyMl8xNjMwMjIxGDAWBgNVBAsM DzAwRDVlMDAwMDAwSnNjQjEXMBUGA1UECgwOU2FsZXNmb3JjZS5jb20xFjAUBgNV BAcMDVNhbiBGcmFuY2lzY28xCzAJBgNVBAgMAkNBMQwwCgYDVQQGEwNVU0GCDgGC ZZ3W4wAAAAABl/udMA0GCSqGSIb3DQEBCwUAA4IBAQBARIx3LPBIMD85bIfiesCM GPIV5SQ8IwaTmk5I4/u9+t8UWRYHkm7j05qhBmiwKxgNaeZyf8cl+rffzKc9LR89 aCDGX62Jc9vVnxx1Lu6iIihmjN18C3dABdh9M1c7Zw8ySSU7Odz5zcb3jWhrbcOs mDSWXxyF9mCCrAKb2p3JxbyAJ/wR5764lg/YDs31cFPg1BCvh8f5rv5ynTsb++KP G2I3hVycaPqcXMNSiYcnT47j5/vGGp5z4ukDJlbiFGX7tQe+38L/zUtkvYyLwBdu SFSLyrEnayDVXrxwX5AAugDSVGrISgcJlQQm2EFZvtAsgwFSDzzZqEKP+t+mNRMZ</ds:X509Certificate>
+                 </ds:X509Data>
+              </ds:KeyInfo>
+           </KeyDescriptor>
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.my.salesforce.com/services/auth/sp/saml2/logout" />
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://unlincoln.my.salesforce.com/services/auth/sp/saml2/logout" />
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.force.com/appointments/services/auth/sp/saml2/logout" />
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://unlincoln.force.com/appointments/services/auth/sp/saml2/logout" />
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.force.com/portal/services/auth/sp/saml2/logout" />
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://unlincoln.force.com/portal/services/auth/sp/saml2/logout" />
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.force.com/facultyearlyalerts/services/auth/sp/saml2/logout" />
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://unlincoln.force.com/facultyearlyalerts/services/auth/sp/saml2/logout" />
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.force.com/SSH/services/auth/sp/saml2/logout" />
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://unlincoln.force.com/SSH/services/auth/sp/saml2/logout" />
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.force.com/SSHKiosks/services/auth/sp/saml2/logout" />
+           <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://unlincoln.force.com/SSHKiosks/services/auth/sp/saml2/logout" />
+           <NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</NameIDFormat>
+           <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.my.salesforce.com" index="0" isDefault="true" />
+           <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.force.com/appointments/login" index="1" />
+           <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.force.com/portal/login" index="2" />
+           <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.force.com/facultyearlyalerts/login" index="3" />
+           <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.force.com/SSH/login" index="4" />
+           <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlincoln.force.com/SSHKiosks/login" index="5" />
+           <AttributeConsumingService index="0" isDefault="true">
+              <ServiceName xmlns:xml="http://www.w3.org/XML/1998/namespace" xml:lang="en">Salesforce.com</ServiceName>
+              <RequestedAttribute Name="unlCrmStudentNuid" isRequired="true" />
+           </AttributeConsumingService>
+        </SPSSODescriptor>
+        <Organization>
+           <OrganizationName xml:lang="en-US">Lincoln Student Success Hub</OrganizationName>
+           <OrganizationDisplayName xml:lang="en-US">Lincoln Student Success Hub</OrganizationDisplayName>
+           <OrganizationURL xml:lang="en-US">https://unlincoln.force.com/SSH</OrganizationURL>
+        </Organization>
+        <ContactPerson contactType="technical">
+           <GivenName>Erik Johnson</GivenName>
+           <EmailAddress>erik.johnson@unl.edu</EmailAddress>
+        </ContactPerson>
+        <ContactPerson contactType="support">
+           <GivenName>Erik Johnson</GivenName>
+           <EmailAddress>erik.johnson@unl.edu</EmailAddress>
+        </ContactPerson>
+        <ContactPerson contactType="administrative">
+           <GivenName>Erik Johnson</GivenName>
+           <EmailAddress>erik.johnson@unl.edu</EmailAddress>
+        </ContactPerson>
+        <ContactPerson contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security">
+           <GivenName>ITS Security</GivenName>
+           <EmailAddress>security@nebraska.edu</EmailAddress>
+        </ContactPerson>
+     </EntityDescriptor>
 </EntitiesDescriptor>
\ No newline at end of file
-- 
GitLab