diff --git a/nefed.xml b/nefed.xml index a3d86a9113b1d2ca56829cab4204a4e6406a4a30..c91291a6062084105b4d4c83b7ef6fe89af89fa5 100644 --- a/nefed.xml +++ b/nefed.xml @@ -29381,4 +29381,164 @@ and do *NOT* provide it in real time to your partners. </ContactPerson> </EntityDescriptor> + <EntityDescriptor entityID="http://nusystemchildsite-1.procurement3.ariba.com" + urn:name="Ariba-Buyer" urn:LogLevel="STANDARD" urn:isActive="true" + xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" + xmlns:urn="urn:sourceid.org:saml2:metadata-extension:v2"> + <Extensions> + <mdrpi:RegistrationInfo registrationAuthority="https://nebraska.edu/nefed" /> + <mdattr:EntityAttributes> + <saml:Attribute Name="http://macedir.org/entity-category" + NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <saml:AttributeValue> + https://nebraska.edu/category/registered-by-nefed</saml:AttributeValue> + </saml:Attribute> + <saml:Attribute Name="http://shibboleth.net/ns/attributes/releaseAllValues" + NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <saml:AttributeValue> + unNUID</saml:AttributeValue> + </saml:Attribute> + </mdattr:EntityAttributes> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="en">Ariba</mdui:DisplayName> + <mdui:Description xml:lang="en">Ariba</mdui:Description> + <mdui:InformationURL xml:lang="en">https://www.sap.com/about/company.html</mdui:InformationURL> + <mdui:PrivacyStatementURL xml:lang="en"> + https://www.sap.com/about/trust-center.html</mdui:PrivacyStatementURL> + </mdui:UIInfo> + <urn:EntityExtension LicenseGroup="" PFVersion="6.10.0.4"> + <urn:DigitialSignatureAliases includeX509inXmlSig="false" /> + <urn:Encryption> + <urn:EncryptionPolicy SLOEncryptSubjectNameID="false" EncryptSubjectNameID="false" + EncryptAssertion="false" + KeyTransportAlgorithm="http://www.w3.org/2001/04/xmlenc#rsa-1_5" + EncryptionAlgorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc" /> + <urn:DecryptionPolicy SLOSubjectNameIDEncrypted="false" AttributeEncrypted="false" + SubjectNameIDEncrypted="false" AssertionEncrypted="false" /> + </urn:Encryption> + <urn:Dependencies> + <urn:SigningKeyPairReference MD5Fingerprint="b920d1dd33f916abe4e2246e0d4f1875" /> + <urn:DsigVerificationCert /> + <urn:SecondaryDsigVerificationCert /> + <urn:DecryptionKeyPairReference /> + <urn:EncryptionCert /> + <urn:SoapAuth> + <soap:Incoming xmlns:soap="http://www.sourceid.org/2004/04/soapauth" /> + <soap:Outgoing xmlns:soap="http://www.sourceid.org/2004/04/soapauth" /> + </urn:SoapAuth> + </urn:Dependencies> + <urn:ConnectionTemplateProperties /> + </urn:EntityExtension> + </Extensions> + <SPSSODescriptor WantAssertionsSigned="true" AuthnRequestsSigned="true" + protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> + <Extensions> + <urn:RoleExtension ArtifactTimeoutSeconds="60"> + <urn:IncomingBindings SOAP="false" Redirect="true" POST="true" Artifact="false" /> + <urn:EnabledProfiles SPInitiatedSLO="false" SPInitiatedSSO="true" + IDPInitiatedSLO="false" IDPInitiatedSSO="true" /> + <urn:SP ConnectionTargetType="Standard" AssertionValidityBeforeMinutes="5" + AssertionValidityAfterMinutes="5"> + <urn:AdapterToAssertionMapping AdapterInstanceId="Composite" + AbortIfNotFoundInAnyDataSources="false"> + <urn:DefaultAttributeMapping> + <urn:AttributeMap Value="mail" AttributeSourceId="CUSTOM-LDAP" + Type="LDAP" Name="SAML_SUBJECT" /> + <urn:AttributeSource + DataSourceId="LDAP-5C14D8F805F301B74FF88CB1D36E1C1ACEAD216D" + Type="LDAP" Description="LDAPMail" Id="LDAP"> + <urn:Parameter Value="SUBTREE_SCOPE" Name="search_scope" /> + <urn:Parameter Value="DC=CUSTOM,DC=Com" Name="search_base" /> + <urn:Parameter Value="sAMAccountName=${Username}" Name="filter" /> + </urn:AttributeSource> + <urn:AttributeSource + DataSourceId="LDAP-5C14D8F805F301B74FF88CB1D36E1C1ACEAD216D" + Type="LDAP" Description="SDLDAPMail" Id="SDLDAP"> + <urn:Parameter Value="SUBTREE_SCOPE" Name="search_scope" /> + <urn:Parameter Value="DC=SDCUSTOM,DC=CUSTOM,DC=Com" + Name="search_base" /> + <urn:Parameter Value="sAMAccountName=${Username}" Name="filter" /> + </urn:AttributeSource> + <urn:TokenAuthorizationIssuanceCriteria /> + </urn:DefaultAttributeMapping> + </urn:AdapterToAssertionMapping> + <urn:NameIdentifierMappingType IncludeAdditionalTransientAttributes="false" + IncludeAdditionalAttributes="false" /> + </urn:SP> + </urn:RoleExtension> + </Extensions> + <KeyDescriptor use="signing"> + <ds:KeyInfo> + <ds:X509Data> + <ds:X509Certificate>MIIG9DCCBdygAwIBAgIQCGmpDRH524tIvKOgRb7Y5TANBgkqhkiG9w0BAQsFADBP + MQswCQYDVQQGEwJVUzEVMBMGA1UEChMMRGlnaUNlcnQgSW5jMSkwJwYDVQQDEyBE + aWdpQ2VydCBUTFMgUlNBIFNIQTI1NiAyMDIwIENBMTAeFw0yMzAzMDQwMDAwMDBa + Fw0yNDAzMDUyMzU5NTlaMGUxCzAJBgNVBAYTAkRFMRswGQYDVQQIDBJCYWRlbi1X + w7xydHRlbWJlcmcxETAPBgNVBAcTCFdhbGxkb3JmMQ8wDQYDVQQKEwZTQVAgU0Ux + FTATBgNVBAMTDHMzLmFyaWJhLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCC + AQoCggEBALLTX0cQPWi6x62UG6FaBkTHqN+6W90x17XJnXFB9R2aRGpsCgYyYOYm + B+Lb6GA9nkMs3HmoH+dQ9TBZYdko0cVQTaH673kdcJlxvIVIWCpDCdB+pNwPGHPT + K91iU8DgAstfGW2GTpJocnO0MLaWdRam1E/4qjsNT3kxzmPq/PDH9pUfx8XVp1M7 + wjd2HZyt2BkDwFgZMmV+EzbnOCqMjRPl6DZY5Jo1op6ZwisjxOHnq4lyAmb71v2T + jKWs9ozBiEYyaIYnOATlgHb8tSnP+fOr19VPjemxNL8Xv8AyLOShTOC4TyUNBUJg + b+npThN3Ppp6dU2pLXyX6aMZT80lZGECAwEAAaOCA7QwggOwMB8GA1UdIwQYMBaA + FLdrouqoqoSMeeq02g+YssWVdrn0MB0GA1UdDgQWBBSycUod1nYjbQnDKku32CdO + +9e3GjBfBgNVHREEWDBWggxzMy5hcmliYS5jb22CFSouc291cmNpbmczLmFyaWJh + LmNvbYIYKi5wcm9jdXJlbWVudDMuYXJpYmEuY29tghUqLnN1cHBsaWVyMy5hcmli + YS5jb20wDgYDVR0PAQH/BAQDAgWgMB0GA1UdJQQWMBQGCCsGAQUFBwMBBggrBgEF + BQcDAjCBjwYDVR0fBIGHMIGEMECgPqA8hjpodHRwOi8vY3JsMy5kaWdpY2VydC5j + b20vRGlnaUNlcnRUTFNSU0FTSEEyNTYyMDIwQ0ExLTQuY3JsMECgPqA8hjpodHRw + Oi8vY3JsNC5kaWdpY2VydC5jb20vRGlnaUNlcnRUTFNSU0FTSEEyNTYyMDIwQ0Ex + LTQuY3JsMD4GA1UdIAQ3MDUwMwYGZ4EMAQICMCkwJwYIKwYBBQUHAgEWG2h0dHA6 + Ly93d3cuZGlnaWNlcnQuY29tL0NQUzB/BggrBgEFBQcBAQRzMHEwJAYIKwYBBQUH + MAGGGGh0dHA6Ly9vY3NwLmRpZ2ljZXJ0LmNvbTBJBggrBgEFBQcwAoY9aHR0cDov + L2NhY2VydHMuZGlnaWNlcnQuY29tL0RpZ2lDZXJ0VExTUlNBU0hBMjU2MjAyMENB + MS0xLmNydDAJBgNVHRMEAjAAMIIBfgYKKwYBBAHWeQIEAgSCAW4EggFqAWgAdQDu + zdBk1dsazsVct520zROiModGfLzs3sNRSFlGcR+1mwAAAYavDUtGAAAEAwBGMEQC + IDaMKqbPHD5NhJy2dXepRB8xhRoMZX8kWWO2suXEYhiqAiB3JdLk0wS4CgOmPauy + 8ThMsvaTSlcIKX5ZRW7/9DjF5QB3AHPZnokbTJZ4oCB9R53mssYc0FFecRkqjGuA + EHrBd3K1AAABhq8NS2oAAAQDAEgwRgIhAJrqpgiOpujfqRxHT5WdBx1g3IAd9SZX + w56hqbND1odfAiEAoxQ4nrJ+nEMVrk0OhYvyu3Rt5b3CVcXgQhlo4qHoYuEAdgBI + sONr2qZHNA/lagL6nTDrHFIBy1bdLIHZu7+rOdiEcwAAAYavDUsyAAAEAwBHMEUC + IDdrZxjB05MTL5B2AIkNt5OjcrddVTnFOVHmeUyOXF6sAiEAoy6LPzIVBNre3lO7 + uRAV/IfW4CeZZvV5VseEb1bbLL8wDQYJKoZIhvcNAQELBQADggEBAAgp4gziFdp3 + tOV6pIwHyR0OIz9eNwZVNHpGUWtVfifHdE842B2byMYOa4uq0RSKAlxqKvFH+gpi + nnPCaMnXMrLOqWvlIGwfP6o0SmRg5iPhVJVjgBgjsOLbzeNCjQRpnQocBDY+Xneo + tENQjRcGLJv1+2/RBWxJ+jDAR/7v2aanuHAApYWQ7WMXG7Lw+Q+1knTqvv7YITbs + 9a82XSTARWfSPvGSEVIVekFoJHRKexE6nPfZnLqhMpI9J4cdOzlFeDO8J+RNxpap + Gk3Mp05d1eUmuSx+la30QAXkFgNXDP3Cp3JSKyG5A6EWjhXTyuNZcI/ffo6tjNWg + 9ARKbvQ4wdg=</ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + </KeyDescriptor> + <NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:emailAddress</NameIDFormat> + <AssertionConsumerService isDefault="true" + Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" + Location="https://s3.ariba.com/Buyer/Main/ad/samlAuth/SSOActions?realm=nusystemchildsite-1" + index="1" /> + </SPSSODescriptor> + <Organization> + <OrganizationName xml:lang="en">Ariba</OrganizationName> + <OrganizationDisplayName xml:lang="en">Ariba</OrganizationDisplayName> + <OrganizationURL xml:lang="en">https://www.ariba.com/</OrganizationURL> + </Organization> + <ContactPerson contactType="technical"> + <GivenName>Roger Korth</GivenName> + <EmailAddress>rdkorth@nebraska.edu</EmailAddress> + </ContactPerson> + <ContactPerson contactType="support"> + <GivenName>Roger Korth</GivenName> + <EmailAddress>rdkorth@nebraska.edu</EmailAddress> + </ContactPerson> + <ContactPerson contactType="administrative"> + <GivenName>Edwin Mukusha</GivenName> + <EmailAddress>emukusha@nebraska.edu</EmailAddress> + </ContactPerson> + <ContactPerson contactType="other" + remd:contactType="http://refeds.org/metadata/contactType/security"> + <GivenName>ITS + Security</GivenName> + <EmailAddress>security@nebraska.edu</EmailAddress> + </ContactPerson> + </EntityDescriptor> </EntitiesDescriptor>