diff --git a/nefed.xml b/nefed.xml index e288e5ff489ca7b0b4329ee1395db830917f9b81..a2dce407e690af0771439160f304554b542db3b0 100644 --- a/nefed.xml +++ b/nefed.xml @@ -760,148 +760,6 @@ <EmailAddress>ITS-NeSIS-Security@nebraska.edu</EmailAddress> </ContactPerson> </EntityDescriptor> - <EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_0a05f240d403d0bfbca9b8c37133afc6bafeb195" entityID="https://trueyou.nebraska.edu/shibboleth"> - <Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"> - <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512" /> - <alg:DigestMethod Algorithm="http://www.w4.org/2001/04/xmldsig-more#sha384" /> - <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" /> - <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224" /> - <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1" /> - <mdrpi:RegistrationInfo registrationAuthority="https://nebraska.edu/nefed" /> - <mdattr:EntityAttributes> - <saml:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> - <saml:AttributeValue> - https://nebraska.edu/category/registered-by-nefed</saml:AttributeValue> - </saml:Attribute> - <saml:Attribute Name="http://shibboleth.net/ns/attributes/releaseAllValues" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> - <saml:AttributeValue> - unNUID</saml:AttributeValue> - </saml:Attribute> - </mdattr:EntityAttributes> - <mdui:UIInfo> - <mdui:DisplayName xml:lang="en">TrueYou - SelfService</mdui:DisplayName> - <mdui:Description xml:lang="en">TrueYou SelfService</mdui:Description> - <mdui:InformationURL xml:lang="en"> - https://trueyou.nebraska.edu</mdui:InformationURL> - <mdui:PrivacyStatementURL xml:lang="en"> - https://its.nebraska.edu/policies-processes/idm-privacy-policy</mdui:PrivacyStatementURL> - <mdui:Logo height="85" width="141" xml:lang="en"></mdui:Logo> - </mdui:UIInfo> - </Extensions> - <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol"> - <Extensions> - <init:RequestInitiator - xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" - Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/Login" /> - <idpdisc:DiscoveryResponse - xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" - Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/Login" index="1" /> - </Extensions> - <KeyDescriptor> - <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> - <ds:KeyName> - uncsidiquip1</ds:KeyName> - <ds:X509Data> - <ds:X509SubjectName>CN=uncsidiquip1</ds:X509SubjectName> - <ds:X509Certificate> - MIID6zCCAlOgAwIBAgIJAPuP1wvhzigRMA0GCSqGSIb3DQEBCwUAMBcxFTATBgNV - BAMTDHVuY3NpZGlxdWlwMTAeFw0xNzAzMjAxMjM0NTFaFw0yNzAzMTgxMjM0NTFa - MBcxFTATBgNVBAMTDHVuY3NpZGlxdWlwMTCCAaIwDQYJKoZIhvcNAQEBBQADggGP - ADCCAYoCggGBALE2zM2/VY2wlLTN1/mdmvqN26HZSYU7IlA9+i+om61wdjL+ZKFJ - xxp6ycvhMBwhitph9rBEeLi23KrrxEEmssxQbwhqLJuPCvMzyeaEakW8maswyiw7 - Ee72taoY4L5qYhrcCvo/9g+UWGGz3FPrJthf0joF5KeWhRgW4k9SVrRAJMWz0OLT - X88R6yRgYDX0g+F1aNHwCLbFo+85+0h2CK5QkKwiB8XVrcaplEX9OmigfQFu5BGf - TcXd/Hm1p/9TEcvaxy9J6gyKN00BFReeRXoE8pG1AEyqRKEvqgufgGJVb+xJj88y - K/q6qoqUR4vZ3z3fGbhyXDFY0o9A9cidW+pWvhEh1P90dUdi7CPnOx6+97GsLJGZ - aGhojpwO+QAwYd9MW4IDetevYTK3iMsr0DWWrbvzS0dnvPUASFGuMWj+ISoSy+cA - K53/kZoTu+nHJ7BKLYcKZ4oeL0A3Kguqf4vRGxncGx6KpJCamqGB62uXsAqZ3m5w - q+OTXnHz4gEQ2QIDAQABozowODAXBgNVHREEEDAOggx1bmNzaWRpcXVpcDEwHQYD - VR0OBBYEFN3hdSMt60Cg00SCAKrr9kTNBuTaMA0GCSqGSIb3DQEBCwUAA4IBgQAH - qh8bLny1cJIqCp9T3Yb0EnADSXzo/n084QGVf5buC0A9elreAOSP2HqvZt+cDN93 - VAgXPq9UOhjgY9t4EEVAHp7c2t5PCO/6VF4z6YAmXxxV6VT6HBhEMy6u4bn0JUBO - DLbD7EtbLVNc1kvfDupLPf7IZLa6YRwCa7omn0HVY/2difeoRqoIIl3QCr5Ea5dM - /a8+yVI3UKUUgBE8W7VIK7gTaTlz1uyyi1hL1q23Wei6jYi+rhkBM/LfdFqL5cv7 - tQlfEuwRjl30/pgcqZI+ZQGJDpHiQ4EwOd3/GXFYH3XeSaNWIJrpAOfcxsjoJ9M6 - TDsEb19pJvYbheOeTemqXlBxVjJrr4jWK6qgd2MrcT4BP5+4+6SnDXvW0nxK0sDZ - a+jIc1Q6jNcz9g5bUjvl77mAQGHDt+DZvbr9B17NS2bAbmlQ3K30p3HtKFhvdjtR - kC0u/BIVhoV36TGC9PUakSNNpLRQw30h8pOTLLBfj1UROO5zlN67a6sjupJkc4M= - </ds:X509Certificate> - </ds:X509Data> - </ds:KeyInfo> - <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc" /> - <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc" /> - <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc" /> - <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc" /> - <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep" /> - <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p" /> - </KeyDescriptor> - <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/Artifact/SOAP" index="1" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/SLO/SOAP" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/SLO/Redirect" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/SLO/POST" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/SLO/Artifact" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/SAML2/POST" index="1" /> - <AssertionConsumerService - Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/SAML2/POST-SimpleSign" - index="2" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/SAML2/Artifact" index="3" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/SAML2/ECP" index="4" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/SAML/POST" index="5" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" - Location="https://trueyou.nebraska.edu/Shibboleth.sso/SAML/Artifact" index="6" /> - </SPSSODescriptor> - <Organization> - <OrganizationName xml:lang="en">TrueYou - SelfService</OrganizationName> - <OrganizationDisplayName xml:lang="en">TrueYou SelfService</OrganizationDisplayName> - <OrganizationURL xml:lang="en"> - https://trueyou.nebraska.edu</OrganizationURL> - </Organization> - <ContactPerson contactType="technical"> - <GivenName>ITS IAM Team</GivenName> - <EmailAddress> - its-sec-iam@nebraska.edu</EmailAddress> - </ContactPerson> - <ContactPerson contactType="administrative"> - <GivenName>ITS IAM Team</GivenName> - <EmailAddress> - its-sec-iam@nebraska.edu</EmailAddress> - </ContactPerson> - <ContactPerson contactType="support"> - <GivenName>ITS IAM Team</GivenName> - <EmailAddress> - its-sec-iam@nebraska.edu</EmailAddress> - </ContactPerson> - <ContactPerson contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security"> - <GivenName>ITS Security</GivenName> - <EmailAddress> - security@nebraska.edu</EmailAddress> - </ContactPerson> - </EntityDescriptor> <EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_7339fe51c5875e28943c979993d27bae9c3fa2b9" entityID="https://sailpointtest.nebraska.edu/shibboleth"> <Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"> <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512" /> @@ -32260,7 +32118,7 @@ </AttributeConsumingService> </SPSSODescriptor> </EntityDescriptor> - <EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_0a05f240d403d0bfbca9b8c37133afc6bafeb195" entityID="https://its-webprd.nebraska.edu/shibboleth"> + <EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_0a05f240d403d0bfbca9b8c37133afc6bafeb195" entityID="https://trueyou.nebraska.edu/shibboleth"> <Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"> <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> @@ -32296,8 +32154,8 @@ </Extensions> <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <Extensions> - <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://trueyou2.nebraska.edu/Shibboleth.sso/Login"/> - <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://trueyou2.nebraska.edu/Shibboleth.sso/Login" index="1"/> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://trueyou.nebraska.edu/Shibboleth.sso/Login"/> + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://trueyou.nebraska.edu/Shibboleth.sso/Login" index="1"/> </Extensions> <KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> @@ -32372,15 +32230,15 @@ <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> </KeyDescriptor> - <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://trueyou2.nebraska.edu/Shibboleth.sso/Artifact/SOAP" index="1"/> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://trueyou2.nebraska.edu/Shibboleth.sso/SLO/Artifact"/> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://trueyou2.nebraska.edu/Shibboleth.sso/SLO/POST"/> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://trueyou2.nebraska.edu/Shibboleth.sso/SLO/Redirect"/> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://trueyou2.nebraska.edu/Shibboleth.sso/SLO/SOAP"/> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://trueyou2.nebraska.edu/Shibboleth.sso/SAML2/POST" index="1"/> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://trueyou2.nebraska.edu/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://trueyou2.nebraska.edu/Shibboleth.sso/SAML2/Artifact" index="3"/> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://trueyou2.nebraska.edu/Shibboleth.sso/SAML2/ECP" index="4"/> + <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://trueyou.nebraska.edu/Shibboleth.sso/Artifact/SOAP" index="1"/> + <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://trueyou.nebraska.edu/Shibboleth.sso/SLO/Artifact"/> + <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://trueyou.nebraska.edu/Shibboleth.sso/SLO/POST"/> + <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://trueyou.nebraska.edu/Shibboleth.sso/SLO/Redirect"/> + <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://trueyou.nebraska.edu/Shibboleth.sso/SLO/SOAP"/> + <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://trueyou.nebraska.edu/Shibboleth.sso/SAML2/POST" index="1"/> + <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://trueyou.nebraska.edu/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/> + <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://trueyou.nebraska.edu/Shibboleth.sso/SAML2/Artifact" index="3"/> + <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://trueyou.nebraska.edu/Shibboleth.sso/SAML2/ECP" index="4"/> </SPSSODescriptor> <Organization> <OrganizationName xml:lang="en-US">