From e175f8a942d3f67c5f675080a1b65e73810dce52 Mon Sep 17 00:00:00 2001 From: Ryan Rumbaugh <rrumbaugh@nebraska.edu> Date: Tue, 26 Sep 2023 13:42:44 -0500 Subject: [PATCH] Draft: Resolve "Remove decommissioned trueyoudev SP" --- nefed.xml | 133 ------------------------------------------------------ 1 file changed, 133 deletions(-) diff --git a/nefed.xml b/nefed.xml index 9f0eb45..07bab27 100644 --- a/nefed.xml +++ b/nefed.xml @@ -2068,139 +2068,6 @@ <EmailAddress>security@nebraska.edu</EmailAddress> </ContactPerson> </EntityDescriptor> - <EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_cceea67875429ed32ab35cbce8248f53d394c1b6" entityID="https://trueyoudev.nebraska.edu/shibboleth"> - <Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"> - <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512" /> - <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384" /> - <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" /> - <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha224" /> - <alg:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha512" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha384" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha256" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha224" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha512" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha384" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2009/xmldsig11#dsa-sha256" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#ecdsa-sha1" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" /> - <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1" /> - </Extensions> - <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol"> - <Extensions> - <init:RequestInitiator - xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" - Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/Login" /> - <idpdisc:DiscoveryResponse - xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" - Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/Login" index="1" /> - </Extensions> - <KeyDescriptor use="signing"> - <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> - <ds:KeyName> - its-iam-sp-da1.nebraska.edu</ds:KeyName> - <ds:X509Data> - <ds:X509SubjectName>CN=its-iam-sp-da1.nebraska.edu</ds:X509SubjectName> - <ds:X509Certificate>MIIEGDCCAoCgAwIBAgIJANLwqRc9Cig8MA0GCSqGSIb3DQEBCwUAMCYxJDAiBgNV - BAMTG2l0cy1pYW0tc3AtZGExLm5lYnJhc2thLmVkdTAeFw0yMDAxMjIyMjE2NTVa - Fw0zMDAxMTkyMjE2NTVaMCYxJDAiBgNVBAMTG2l0cy1pYW0tc3AtZGExLm5lYnJh - c2thLmVkdTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAMrNDG2x50k1 - 84FcyLZ3pAyq+4B08HpXRV5Ei1O1PuOIbAJ7jZBvPvaSHfZ3SYh+RXr8L9S0xp5J - 7UDQfLNPhDV5CnncESMVw1UlOQfZ+rtgCFnlBTbSUfxIUU0XrvVF26RVTWgMR4Wp - dp64emSYWg74WLyD2CDpzbPU7E1041bfosOHQmFFqvsH28ds/T/ffLXMrqUaJAm6 - /sY7GCOzSi6sRmpFOr41r5aRq7SlUB1wEkZmwRjXJ+sSCMBIH/TdweWkqCsRdn8j - yaAfITOWJkjA3KNdH4/892G3aWbXz3X/W0ohJUKl+ZrU2X84rW0Pm8TDASQTYrCk - 3XPs0Oof6awwcB+e3+fDrj0lshkKC+Qrq2Qy2quw+YeAWrRVK9jg/gKNeCuaSQse - XCVOYJSlfLEzkEOyX8XYOGIBflEy8Ii3BBS5JLck0L7GQ9p9croUzJOijQiwXtZ7 - mEpj1sVypqV67qHDp42ZSM4s2btL6oep0oxn41euIkkuVuS9iTichwIDAQABo0kw - RzAmBgNVHREEHzAdghtpdHMtaWFtLXNwLWRhMS5uZWJyYXNrYS5lZHUwHQYDVR0O - BBYEFMRkl7f9D0dkuAeYoRTNtkDtTcWwMA0GCSqGSIb3DQEBCwUAA4IBgQBUq8of - ZUMYmDuEAo1X+aQz3IlNuQTbz8zWnTxHCRBwpB/DtREJI6kPhHSSxG4obiM8nM3n - rr2ejW+b7Km8mT3ZkAAWdqz7820+W7K+86xJtINwTEOq78gG06R95ui7uGkWsvHd - gQCx32QQPDtv5gyk+9+Q0TiYPc9vrOw62CBIoebFKHQsjUZI4ibi7ms6XfM2yAlL - wrrjSTujrMCsF5RHnX9CMxvohWM2Yn9fXTXMUwOqJnbVLuWMAhEouni61V2r2yOA - EwFNgJJTJ8SLBW1fK9+M7rCJoxypphUBS5SUxLpnhmWYJ/o3GQaCgWY37ZIOscFQ - J6H2NV0guSE5WvEJyZYjd3fXzYX7kr1wrZ7Dr++pE7FjBgvxWGBLZphJxXFOJg3t - wbMTBHCmG1gBY78c21+S/o+mC7ZZIa5R+pm2eSON6waeh5tUeEg0gs0S78+kGM6x - lLkZh91oTvV3asTPJP/0Zg3TjN2T95CNdlT88Q2Y3LA7qYwrV4Y2EeZC78c= - </ds:X509Certificate> - </ds:X509Data> - </ds:KeyInfo> - </KeyDescriptor> - <KeyDescriptor use="encryption"> - <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> - <ds:KeyName> - its-iam-sp-da1.nebraska.edu</ds:KeyName> - <ds:X509Data> - <ds:X509SubjectName>CN=its-iam-sp-da1.nebraska.edu</ds:X509SubjectName> - <ds:X509Certificate>MIIEGDCCAoCgAwIBAgIJAKkojpVnlgmSMA0GCSqGSIb3DQEBCwUAMCYxJDAiBgNV - BAMTG2l0cy1pYW0tc3AtZGExLm5lYnJhc2thLmVkdTAeFw0yMDAxMjIyMjE2NTVa - Fw0zMDAxMTkyMjE2NTVaMCYxJDAiBgNVBAMTG2l0cy1pYW0tc3AtZGExLm5lYnJh - c2thLmVkdTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAL5Aw4sccyws - 6YZlTazAsmwDHuoPi0DANNc6C1T7KtBah3kDcXSL2ZdlEs7/cc6Aw4IQ3XLScRn+ - qFdKLYL8ofW9db9PC4iZan/BSusznjpHYMkZbnz57+Vr4Ykwl8TiNqa+nk5lHTxE - g6/4LXBpK2nXc7QVFwt/IF/to977e+dl0o2fUmFIgsm//u4ugAFQX+3UvwEN9241 - UwOLG+lIg5NTJpVAll/td/stqmkOo/M/tnMmGk3Fbc3DZrUrUN/hKg3YhgKxlgNn - sEeDLjw8BOsNO4drhFUDE2VN+O4ukRVg/4yaPy+2BBkIcq2qmBSeypGNDQHHEH1J - ZNyC0X/2WCL0LPUFv7SkCr5Vep53lSbLCbAl6thikRoS/hA2CwSwEFUABQ6lfGmr - SIWKHmt7vYrZNT+vR6WexHRZ+rckQxpB+pvPs17uF+DAslRIqzbJnu2ywv5//iyQ - pLimZw0lh+kWNIW0SWdOeF9kPoEpgjFszTo19PS78OzeZ53EeU5LZwIDAQABo0kw - RzAmBgNVHREEHzAdghtpdHMtaWFtLXNwLWRhMS5uZWJyYXNrYS5lZHUwHQYDVR0O - BBYEFN1oZi+SPw+yEN0JsA51siYOAtoFMA0GCSqGSIb3DQEBCwUAA4IBgQAPwkhw - 2/GAwd3T+pzk9e9Azq0T63FFV5ZOuOcFD4SiqyWq7cKwoA6SDNadYvmtq3+ZBr1y - RV+ktBj7JivKQTakduwWiJRcCB43ILd42yC5S5r6nz+tilq5IOyI6Oh/xMzrfruI - vPXZDHKjcVOm5eYU5aBW561bNLVJUhHGgdxv20LNgf67e/YpBrG33zOJXDSk/3rU - PopO5qDqMoKrcxhwjZT/h15Qmwk4QwsmeBWVIJQr+wsPGcOCUr+xab0UzSwGyVNe - rRNYS/pdr4vD/BIrjWbhwPNe9OFAkHRIMGKSrfO0zoR8L2k6QioaU8I7cWLKLAYM - h66732gmoQlVNCb87oTqEjyP4w13exoTMNGgA86WfELEiNR52xaEdC7xA5gdg9BC - xhADCpSr9/uifBMAowomcXYlY31bjS6XK7yzvPokh7Zg23o307jaDug+ULoiyrjP - yVX+/r+FBx+Rvq039NawiVIwSyAT0GMPxkzALmxazlCukyD1icqEzMhRzrQ= - </ds:X509Certificate> - </ds:X509Data> - </ds:KeyInfo> - <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm" /> - <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm" /> - <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm" /> - <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc" /> - <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc" /> - <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc" /> - <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#tripledes-cbc" /> - <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#rsa-oaep" /> - <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#rsa-oaep-mgf1p" /> - </KeyDescriptor> - <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/Artifact/SOAP" index="1" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/SLO/SOAP" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/SLO/Redirect" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/SLO/POST" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/SLO/Artifact" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/SAML2/POST" index="1" /> - <AssertionConsumerService - Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/SAML2/POST-SimpleSign" - index="2" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/SAML2/Artifact" index="3" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/SAML2/ECP" index="4" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/SAML/POST" index="5" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" - Location="https://trueyoudev.nebraska.edu/Shibboleth.sso/SAML/Artifact" index="6" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" - Location="https://its-iam-sp-da1.nebraska.edu/Shibboleth.sso/SAML2/POST" index="7" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" - Location="https://its-iam-sp-da2.nebraska.edu/Shibboleth.sso/SAML2/POST" index="8" /> - </SPSSODescriptor> - </EntityDescriptor> <ns3:EntityDescriptor xmlns:ns3="urn:oasis:names:tc:SAML:2.0:metadata" xmlns="http://www.w3.org/2000/09/xmldsig#" xmlns:ns2="http://www.w3.org/2001/04/xmlenc#" -- GitLab