From 88a6c29eafb1cd41760d6c84469bc65b735361f0 Mon Sep 17 00:00:00 2001 From: "andrew.costa" <andrew.costa@nebraska.edu> Date: Wed, 31 Jul 2024 15:17:33 -0500 Subject: [PATCH] Draft: Resolve "Onboard AIMS Parking Management Metadata" --- nefed.xml | 132 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 132 insertions(+) diff --git a/nefed.xml b/nefed.xml index 1d61061..3e050eb 100644 --- a/nefed.xml +++ b/nefed.xml @@ -34555,4 +34555,136 @@ PRD49iI+tL/VkGo= <EmailAddress>security@nebraska.edu</EmailAddress> </ContactPerson> </EntityDescriptor> + <EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_98f5296c73b4ac19b81a24fcec1b6504a57af16a" entityID="https://unlauth.aimsparking.com/shibboleth"> + <Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224"/> + <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/> + <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1"/> + <mdrpi:RegistrationInfo registrationAuthority="https://nebraska.edu/nefed" /> + <mdattr:EntityAttributes> + <saml:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <saml:AttributeValue>https://nebraska.edu/category/registered-by-nefed</saml:AttributeValue> + </saml:Attribute> + <saml:Attribute Name="http://shibboleth.net/ns/attributes/releaseAllValues" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <saml:AttributeValue>unNUID</saml:AttributeValue> + </saml:Attribute> + </mdattr:EntityAttributes> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="en">AIMS Parking Management Software</mdui:DisplayName> + <mdui:Description xml:lang="en">AIMS Parking Management Software</mdui:Description> + <mdui:InformationURL xml:lang="en">https://aimsparking.com/about-us</mdui:InformationURL> + <mdui:PrivacyStatementURL xml:lang="en">https://aimsparking.com/amp-park-privacy-policy</mdui:PrivacyStatementURL> + </mdui:UIInfo> + </Extensions> + <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> + <Extensions> + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://unlauth.aimsparking.com/Shibboleth.sso/Login"/> + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://unlauth.aimsparking.com/Shibboleth.sso/Login" index="1"/> + </Extensions> + <KeyDescriptor use="signing"> + <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> + <ds:KeyName>unlauth.aimsparking.com</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=unlauth.aimsparking.com</ds:X509SubjectName> + <ds:X509Certificate> + MIIEFzCCAn+gAwIBAgIUJR7LMHOUMihmdyO9GCti4M/RGDwwDQYJKoZIhvcNAQEL + BQAwIjEgMB4GA1UEAxMXdW5sYXV0aC5haW1zcGFya2luZy5jb20wHhcNMjQwNzI5 + MTYzMDE0WhcNMzQwNzI3MTYzMDE0WjAiMSAwHgYDVQQDExd1bmxhdXRoLmFpbXNw + YXJraW5nLmNvbTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBALx1c72+ + jdmZ44LwhmVAAbY6JrOahqD3GTto+gWCTbFRk7c7I5gi/HUmvEW/jWiJn1gYF/rn + dDrg/e33ixvxMeZ1LNvMV2k2qjMwRBXn6rbtNAQ0Aw2Ywl9utL4uhf4Ll5KvTspc + 7sy7yk43f9bEaVbTu/B6AMWXSb8rE/AtW4xZSmU5i/JbOyxjoxDvTrQLdaCwsmML + UT5G60SdxUmUIlLjHcNgA+JmayE2n3rGN3vbvFp67LMh5v4wE/gt5QfFUpZYv9P8 + d7p09ytyIwTNCThWLV1NIGTBeb5+DNx0zIvsEH7zXG4LZDoalIlXmBQuXAQfpCkN + MXSW1aodvN4MZ4GYEoan12G0DQePfFVXMNjpWYovb/AG6wVDMira0KCfIAWyXM7p + /T+opyOLytMtX9S1LulxpndOuT8z6lMjpFZNMPHAfQcJLiS5wKVJb0nt+DLBOHQN + +C4zf1LS/HzhibMXvps5nOvOjCaThD96S6Wf0pda7sEGdflcdBU/uxXDuQIDAQAB + o0UwQzAiBgNVHREEGzAZghd1bmxhdXRoLmFpbXNwYXJraW5nLmNvbTAdBgNVHQ4E + FgQUrasnKS6ajzn/p0bcGoLoIoARPrMwDQYJKoZIhvcNAQELBQADggGBAF+hEoED + am6JpM+3KKCJdVmbJhF8WQELrNDdFFSoz9X5qCK6esOol31sl0VxIp2juoLHq70n + e99Kw0UJeDpSzLf7hh2ESSes2nMogtdtAFXn0o/O8ESJ83+VDhAfysjrvZQCM7pM + BA1atlkMpJlkjuWazDfQrxR2i3vCfFLO9qkEH6ChmZlOipiHBKzr5OYLQ2eiD466 + giwk6A02MoJ/z1M0Eyx6Bedgc4fUGi80vvKaC6wZVR5FpK1E0fTbTuaxVxyeFMUr + pffn5Dn+7Yc6nAzRzuikuQVzGoy0tA2mue67LPVV5bxXZMbtvMRDwsu4dfica7q8 + bkvJrw6OQF0G9s44getdWl6kiyyedLDEASzONF2q4bOm8Th7smzLdq4dwlpieJJV + xAsJqBmETN1pcMUPyrJb1tJBmRPTa9oJnl5D+oYzJ54UG0c+/lGwCJMGhUnfz+cn + 1H85bo3koNfz+j6Lo8/9etMK1RI/x5TXYY03NPCYHJ9yQZv+vzuMzcI1NA== + </ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + </KeyDescriptor> + <KeyDescriptor use="encryption"> + <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> + <ds:KeyName>unlauth.aimsparking.com</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=unlauth.aimsparking.com</ds:X509SubjectName> + <ds:X509Certificate> + MIIEFzCCAn+gAwIBAgIUNJ8E4Z3AplTgHG65w5ZCa4mHNJswDQYJKoZIhvcNAQEL + BQAwIjEgMB4GA1UEAxMXdW5sYXV0aC5haW1zcGFya2luZy5jb20wHhcNMjQwNzI5 + MTYzMDE2WhcNMzQwNzI3MTYzMDE2WjAiMSAwHgYDVQQDExd1bmxhdXRoLmFpbXNw + YXJraW5nLmNvbTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAJmwNkm4 + OstMBXr+bBJpncEFDesaD6CyjyPiIzdfq9Qer2Tpe79eVLESUUQu2viORIf2K5dY + 4voECSVcruz0oMmD3COSlUnqWBx7+iE3TcThyv9Su3xwy8Kv3Cns1RTvVVGvF/Nw + fzWpIx9r0vBoCLnjgSAqLpji8BZWFz6r6GCFOHz9JvAo479lkPPj9qIWMUVsRSn3 + 4mhoYIIRDnexLYp6oNfriVC+BMclpJ3KAYDfjTVinVtn0c6dR4mJAZFm0woP/eIw + MmagY7pafbCnuYkXat+ZuL4mUQYp/nHNxR8VmRej4gArxGBAHhojJG72f9Ks/WS3 + TZsBbknuMhoTUTaMAX89mC1+uQx7fuA4fboIoeVhqNbB6PqF3p8wEN/LUNKyn+Q0 + rt439OsyH+oQbkfODeMgQdewI3AyFQssdV6WJ9kPLpvSgcyb0XrVMbOr3RmwMIzB + +FttXOZpx1JKXSiqpCS+zFLQwK5AXOKO6FXX9PF+3y3pi9JFvwQkb3HEiwIDAQAB + o0UwQzAiBgNVHREEGzAZghd1bmxhdXRoLmFpbXNwYXJraW5nLmNvbTAdBgNVHQ4E + FgQUyMkuxMvO+UGsqUN5pqIqU48xJ1swDQYJKoZIhvcNAQELBQADggGBAA7pv6HU + JrTnM6N5qzowOXX7QQEe+psfiB9/hdfs4S87BOhMQrhIOIxyKJTXEnci275EvLnu + 0IlLYDiHEqEEc+xTiGkSbM0TwMzoOcnukY6xjaGEJFFxSBJA1tKeNKu5fr3CYBfO + BTWoSH6pr3B2v5kE+fD+Zgq9eueRrx8WTJRKYoY9EqKwpiIq1d4YheG7ErQmPQO2 + 0rAEjmKLS1dKfdr47dOZd6CI9F8tDEK/y93Gji0qeRYBpQuCvgXWc5FV00YoiZ/c + VKy1ZQvrvKClmdUmovNb5nqVrAwiZEv93YVdEYxeckMpNru7uOFwYaHaoKKwOoxV + tgUhOo6Wuo5MYuAyKUngy0QEmq66lrtAdrxxTWGlRKP/hlNkt+1xs+XK7sfA53YA + EGTntSFGLfT6wktPzYWd+gl+m6tpPAHkcVelC6i8LkEr59ckwuzFe9ttqp4JgNM/ + DlBPXoISoxje8/SChjG3QWT81DhZ1dwko8AQ8AMxP9CcHa1ItU+NTU2vGw== + </ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm"/> + <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm"/> + <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm"/> + <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc"/> + <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc"/> + <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc"/> + <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc"/> + <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep"/> + <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p"/> + </KeyDescriptor> + <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://unlauth.aimsparking.com/Shibboleth.sso/Artifact/SOAP" index="1"/> + <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://unlauth.aimsparking.com/Shibboleth.sso/SLO/SOAP"/> + <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://unlauth.aimsparking.com/Shibboleth.sso/SLO/Redirect"/> + <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlauth.aimsparking.com/Shibboleth.sso/SLO/POST"/> + <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://unlauth.aimsparking.com/Shibboleth.sso/SLO/Artifact"/> + <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://unlauth.aimsparking.com/Shibboleth.sso/SAML2/POST" index="1"/> + <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" Location="https://unlauth.aimsparking.com/Shibboleth.sso/SAML2/POST-SimpleSign" index="2"/> + <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://unlauth.aimsparking.com/Shibboleth.sso/SAML2/Artifact" index="3"/> + <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://unlauth.aimsparking.com/Shibboleth.sso/SAML2/ECP" index="4"/> + </SPSSODescriptor> + <Organization xml:lang="en"> + <OrganizationName xml:lang="en">AIMS Parking Management Software</OrganizationName> + <OrganizationDisplayName xml:lang="en">AIMS Parking Management Software</OrganizationDisplayName> + <OrganizationURL xml:lang="en">https://aimsparking.com/</OrganizationURL> + </Organization> + <ContactPerson contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security"> + <GivenName>ITS Security</GivenName> + <EmailAddress>security@nebraska.edu</EmailAddress> + </ContactPerson> + </EntityDescriptor> </EntitiesDescriptor> -- GitLab