diff --git a/nefed.xml b/nefed.xml index e41aa24fd6937ee32ce9af4248c408d2c3e65858..950d05a8c05e05aa1243cf7e18772e2bd8a70a07 100644 --- a/nefed.xml +++ b/nefed.xml @@ -1045,7 +1045,8 @@ <EmailAddress>security@nebraska.edu</EmailAddress> </ContactPerson> </EntityDescriptor> - <EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" entityID="https://trueyoutest.nebraska.edu/shibboleth"> + <EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_5949a4673f99a7a63a1b77652f9af29f0e5e5cdc" + entityID="https://trueyoutest.nebraska.edu/shibboleth"> <Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport"> <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha512" /> <alg:DigestMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#sha384" /> @@ -1064,72 +1065,105 @@ <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1" /> <alg:SigningMethod Algorithm="http://www.w3.org/2000/09/xmldsig#dsa-sha1" /> <mdrpi:RegistrationInfo registrationAuthority="https://nebraska.edu/nefed" /> - <mdattr:EntityAttributes> - <saml:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> - <saml:AttributeValue> - https://nebraska.edu/category/registered-by-nefed</saml:AttributeValue> - </saml:Attribute> - <saml:Attribute Name="http://shibboleth.net/ns/attributes/releaseAllValues" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> - <saml:AttributeValue> - unNUID</saml:AttributeValue> - </saml:Attribute> - <saml:Attribute Name="urn:oasis:names:tc:SAML:profiles:subject-id:req" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> - <saml:AttributeValue>any</saml:AttributeValue> - </saml:Attribute> - </mdattr:EntityAttributes> - <mdui:UIInfo> - <mdui:DisplayName xml:lang="en">Test - TrueYou SelfService</mdui:DisplayName> - <mdui:Description xml:lang="en">Test TrueYou SelfService</mdui:Description> - <mdui:InformationURL xml:lang="en"> - https://sailpointttest.nebraska.edu</mdui:InformationURL> - <mdui:PrivacyStatementURL xml:lang="en"> - https://its.nebraska.edu/policies-processes/idm-privacy-policy</mdui:PrivacyStatementURL> - <mdui:Logo height="85" width="141" xml:lang="en"></mdui:Logo> - </mdui:UIInfo> + <mdattr:EntityAttributes> + <saml:Attribute Name="http://macedir.org/entity-category" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <saml:AttributeValue> + https://nebraska.edu/category/registered-by-nefed</saml:AttributeValue> + </saml:Attribute> + <saml:Attribute Name="http://shibboleth.net/ns/attributes/releaseAllValues" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <saml:AttributeValue> + unNUID</saml:AttributeValue> + </saml:Attribute> + <saml:Attribute Name="urn:oasis:names:tc:SAML:profiles:subject-id:req" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> + <saml:AttributeValue>any</saml:AttributeValue> + </saml:Attribute> + </mdattr:EntityAttributes> + <mdui:UIInfo> + <mdui:DisplayName xml:lang="en">Test + TrueYou SelfService</mdui:DisplayName> + <mdui:Description xml:lang="en">Test TrueYou SelfService</mdui:Description> + <mdui:InformationURL xml:lang="en"> + https://sailpointttest.nebraska.edu</mdui:InformationURL> + <mdui:PrivacyStatementURL xml:lang="en"> + https://its.nebraska.edu/policies-processes/idm-privacy-policy</mdui:PrivacyStatementURL> + <mdui:Logo height="85" width="141" xml:lang="en"></mdui:Logo> + </mdui:UIInfo> </Extensions> - <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol urn:oasis:names:tc:SAML:1.1:protocol urn:oasis:names:tc:SAML:1.0:protocol"> + <SPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <Extensions> - <init:RequestInitiator - xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" + <init:RequestInitiator xmlns:init="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Binding="urn:oasis:names:tc:SAML:profiles:SSO:request-init" Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/Login" /> - <idpdisc:DiscoveryResponse - xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" + <idpdisc:DiscoveryResponse xmlns:idpdisc="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Binding="urn:oasis:names:tc:SAML:profiles:SSO:idp-discovery-protocol" Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/Login" index="1" /> </Extensions> - <KeyDescriptor> + <KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> - <ds:KeyName> - uncsidiquit1</ds:KeyName> + <ds:KeyName>its-webapq.uncsdom.uneb.edu</ds:KeyName> <ds:X509Data> - <ds:X509SubjectName>CN=uncsidiquit1</ds:X509SubjectName> - <ds:X509Certificate> - MIID6zCCAlOgAwIBAgIJAMQhAxLAEHlnMA0GCSqGSIb3DQEBCwUAMBcxFTATBgNV - BAMTDHVuY3NpZGlxdWl0MTAeFw0xNzAyMDMxNTU0MzNaFw0yNzAyMDExNTU0MzNa - MBcxFTATBgNVBAMTDHVuY3NpZGlxdWl0MTCCAaIwDQYJKoZIhvcNAQEBBQADggGP - ADCCAYoCggGBAPBY8VKOf1i8IvOMTKqnPdUjNrB6GCR/7SBxu96cSB4oCzWf9nq5 - GtbisEyCFvF/pOWoVDHRfHor/a5FfbBzIXj/C9rJlAKtid0LDHpOtUPRYATyvNKC - 7cusvxJ5qeNs5xKW0pIpHvIjRmfamq5LkUNrblIepL6MtYvC9Nbhi2JtCqNOdZcp - CjAaVbLk+bp6JhI+kMyU43HuxvjJ30L9utRyLW3uxOPfWwgZKqb5oXaMoTnmPGp2 - JlDnAOd6lRF4XM14M1o1vc1HM5XD1kEf+hwrXDGUa295vg6ROphYRT2a1xPgBSHG - Ea1BxglOFWVD1RMqG4d2Og+5cwU2fJFmC3Rsvy6xkBKQsmNBFt6aGMQiQhjA/DK0 - ag6fOuxNGq1qF8oLIq+5OUnTHW1xXvs6EEySr6UaPUtMcqKTCszRNF1TuReYyYWU - MNhDMQLt+XfX+nKhtnBfRsOHYqEkintc4AzPHQXPtC6UXqr3oRwh5XIjLuD2jWni - Ra0bZ2Hh+p3+rwIDAQABozowODAXBgNVHREEEDAOggx1bmNzaWRpcXVpdDEwHQYD - VR0OBBYEFMFjE0AAKZylpKWtc9eq5c2aZ0K1MA0GCSqGSIb3DQEBCwUAA4IBgQCq - EcIE1622nDF1a4Qr9Jn58Le8xMpWGW7XxPS7O05zA244wOzM75MHPoW87xwmdpVS - 1MOsmYACvBEH4HdOYzl3jMpSnCE+dXF1yY+r1Pn2X5rhBaItr7TItB5uhaRmb16A - WMFHXvU/FRM91ZkE4wWHAgbScjWwvqhv/LGXzdEY2hB2welr510uArReMQSxomWZ - SRbrbWl/wrX9Dhb6+bUCKrg3cRbzyimmoc3jOVRa/BvFYBfsNGhrAJLMELnDMPiJ - KEiujMv6f8r0EL9mD8HwopWwW97MGNOpWQ0rkn0wQujo4s22xWRus+erd/mHRMBJ - lv2rn+wn7/N/U/hToLXgsupChYkBCT2Fx3B+3nRFqF8+arwePdEhi8ADtZgd+Zzj - 1eukV73h6dT10VQJLJZgdFoM3YRTSdXBD5xeFa9SeVWJmE0iypqvjbQDc6Ag7lKr - ysovLJPn5qAkBl4ZYlycrN0m8yW+6YasJLrnMiSr1ULr9J8lVSsOzXY6wGMXJ7E= + <ds:X509SubjectName>CN=its-webapq.uncsdom.uneb.edu</ds:X509SubjectName> + <ds:X509Certificate>MIIEIzCCAougAwIBAgIUUDFdhV+/nBGYMV6LIlFNBIq2QPAwDQYJKoZIhvcNAQEL + BQAwJjEkMCIGA1UEAxMbaXRzLXdlYmFwcS51bmNzZG9tLnVuZWIuZWR1MB4XDTIx + MDUxNzE3MzM0MFoXDTMxMDUxNTE3MzM0MFowJjEkMCIGA1UEAxMbaXRzLXdlYmFw + cS51bmNzZG9tLnVuZWIuZWR1MIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKC + AYEAx4Tuylh+SsPEO6ZNyUIAd7J7xQsGue+SLDyOs7sxvTcMtCTSN+ceWAOxfJYK + KcR8aPw67OtBQYXiH4aDIA6SuPNnuEbIoa+nknFvYD7d72at8njtGmJUNQ2OxAsN + IdDQGjzjMETSEDBQw9bX5tjHEjeXAJPpgWbudBBgyozBRNWrAmVGn+V/GA48g1lb + Ts50MHCv0xSbp+VTnNTfl6OvHm8QRzah12SdHKIHuZGPYm/whhXLdpP72uDli/Zr + LzH6YmjrN8Q+VQc9XZ1sc6S/87doVZrdvd2wkW2m0Fa4hTTiKtRvn6GHYlXiJ+88 + qLnnpkm/O4qBnaE4LtNK/U9uFncGM8Glmf9fiOK5/YryU9UrL9Ihhk0YL2nxz4mR + lpTn6frKwP6ANc10WBkPLPsR1m/DuBzA0EISqEpycSmdfUr54xoa6/8Ebq6PvmOK + 46pTAoS9M2M3ithjxUkF431DxmZIyi5X0qheHi4U/CfCKxxACIVvSHnpyjk6G+oY + z0KVAgMBAAGjSTBHMCYGA1UdEQQfMB2CG2l0cy13ZWJhcHEudW5jc2RvbS51bmVi + LmVkdTAdBgNVHQ4EFgQU08/9f1S4iHyN42svYeo8gR/uo3MwDQYJKoZIhvcNAQEL + BQADggGBADhh0/xLX7I527sdwjD8H64v2YZIq7GvVls1LOBwYsl3R3wtf72XPV+j + +FmEcaxOja6UfsZkkYUb0f4PIJo0zXHoXphVMgKvEPb1OiP643nYtFT+yGe1iCh3 + DJK6nPQl4fgp5pqxMUfyARkHEQSJdqcD9aSIjDpxnppqGOS3GPQEbhMaFvd5Qj40 + LOOp8+/VdMticXyToro7e17kusoEtWicgDHQtNDvkH+io/+tbFblT02oMyyGKVVS + iS88c6vdKQRSV2n4hXq2L8g7rOZp2hZLcCqHKJHR+O21XV4CYrYypoUIL1iLbtyN + mp3PYom3oHfI8LuqbHWAMrZtXLb/W0EoS4K09D0KDzX3ZSzxGIjkZ0zOyugK4Y2Y + +V5J02j+kalQ1WL4Gr1306Tj3/lyN+oWocbF2zY1XhhSSV5qlvwxalrTvZqfJHIU + sIXDvBtdOKFwyYLZjDcOgGV05A/kgQ0A77OoZK/rDqyUEblr4BFQBjsrAkN9ua2r + sRbIwL7b7w== + </ds:X509Certificate> + </ds:X509Data> + </ds:KeyInfo> + </KeyDescriptor> + <KeyDescriptor use="encryption"> + <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> + <ds:KeyName>its-webapq.uncsdom.uneb.edu</ds:KeyName> + <ds:X509Data> + <ds:X509SubjectName>CN=its-webapq.uncsdom.uneb.edu</ds:X509SubjectName> + <ds:X509Certificate>MIIEIzCCAougAwIBAgIUVitDIIBQDY3pDIZAPD9f+0mLXMAwDQYJKoZIhvcNAQEL + BQAwJjEkMCIGA1UEAxMbaXRzLXdlYmFwcS51bmNzZG9tLnVuZWIuZWR1MB4XDTIx + MDUxNzE3MzMzOFoXDTMxMDUxNTE3MzMzOFowJjEkMCIGA1UEAxMbaXRzLXdlYmFw + cS51bmNzZG9tLnVuZWIuZWR1MIIBojANBgkqhkiG9w0BAQEFAAOCAY8AMIIBigKC + AYEAo0R9YOeYZvZUIrNI5o64wzCptJYQt6Xf2jQfL4jRZkVLqyYIgz3Km8a8anZE + dWq0vo10ps01BGT5O8KlqgyA8fG7QF+DwHZ7sbDmXrUCZEWCZs3OrRVXzC3ktZZS + VSHXZlI/MABFr63SlvFw3e0GuwhFIezEyjPiaZNsuLR3QlsI/WxNGr8/RHS2VVHg + Wt+7IIAPdgxzMAnA8ppG4v7czv+eJFXpdkRMhwRdYXOxFgAmqlJlbSdOtdbzsn6F + 7dSfbEFMOMPoDtKjXDvxa52UE7zUqV420xxuVvSLHzMfTdqszP750fhIG2fL0h24 + Za8wpX3FHNi3ScNe+v2+XWw2n0E/yN8q39FW2Fcmo8uTj682t8aW++GotwQoXd8f + kZo8VXkjxUq/pesOdAroSGdSz/Lte5O7Pjm6ExDQIj+bvKmHNkXpWoFkE5Z3h3i7 + YL2hrfIgaU7jFLonjzrakljU2bxg2ZBsQdPCoZIysGfX37NwF53Hm5fZ43Fq5T6f + 6o3XAgMBAAGjSTBHMCYGA1UdEQQfMB2CG2l0cy13ZWJhcHEudW5jc2RvbS51bmVi + LmVkdTAdBgNVHQ4EFgQUJH1a+0uIx3lN0ZxXpAnHn5PW1n0wDQYJKoZIhvcNAQEL + BQADggGBAKFRdaQxmt+YBSLNuX+xHQBsbAxr30OZeGaVxvdOiVq+ChgRID2vyTjb + ddt+eUVBEcDvJ+2TT3h54/H8fkpkbw1njPX3ZfasUyBGqY62W4XU6e/s6wlfOoGK + ylZQC+5zKNMZw+b3qLa35RKE5LGBP9TNl61WQPOSLZXtYgmoVqdBElaMIwjVmKbe + C/uWuygQOAjoqdYknLy0VPYm00s5FoV7Q2VSOdabE4BGvJChWU6aHRX+NCWt5ESr + edooMsZ6kqCt05kfwrMr/NPLNFySieuDGr7aFHoA9GIrCWc6SmiyKRC9N1BYgFgB + EqyplCQ40zaf+TqO5NKz+bD5FJsq5FyOlGq1BtaXJCm3LUvXjS2PBs1b3T9P7qpP + eyzTX7jdER75Q8sqnsTqV+wFfzSrYhFBG1mRHsFj8TRbMxPlAZa3sBXqLLPzajo1 + TUvk1wFg/djg0d9fGsD/I9cnwUlYA1OhLRuO6M+9RjL/S5EK+I3FvnUOpMqUWAA7 + 3hjvjNPviw== </ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> + <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes128-gcm" /> + <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes192-gcm" /> + <EncryptionMethod Algorithm="http://www.w3.org/2009/xmlenc11#aes256-gcm" /> <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes128-cbc" /> <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes192-cbc" /> <EncryptionMethod Algorithm="http://www.w3.org/2001/04/xmlenc#aes256-cbc" /> @@ -1139,52 +1173,22 @@ </KeyDescriptor> <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/Artifact/SOAP" index="1" /> - <ArtifactResolutionService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" - Location="https://iga-tst.nebraska.edu/Shibboleth.sso/Artifact/SOAP" index="2" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" - Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SLO/SOAP" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" - Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SLO/Redirect" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" - Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SLO/POST" /> <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SLO/Artifact" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" - Location="https://iga-tst.nebraska.edu/Shibboleth.sso/SLO/SOAP" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" - Location="https://iga-tst.nebraska.edu/Shibboleth.sso/SLO/Redirect" /> <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" - Location="https://iga-tst.nebraska.edu/Shibboleth.sso/SLO/POST" /> - <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" - Location="https://iga-tst.nebraska.edu/Shibboleth.sso/SLO/Artifact" /> + Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SLO/POST" /> + <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" + Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SLO/Redirect" /> + <SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:SOAP" + Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SLO/SOAP" /> <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SAML2/POST" index="1" /> - <AssertionConsumerService - Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" - Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SAML2/POST-SimpleSign" - index="2" /> + <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" + Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SAML2/POST-SimpleSign" index="2" /> <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SAML2/Artifact" index="3" /> <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SAML2/ECP" index="4" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" - Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SAML/POST" index="5" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" - Location="https://trueyoutest.nebraska.edu/Shibboleth.sso/SAML/Artifact" index="6" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST" - Location="https://iga-tst.nebraska.edu/Shibboleth.sso/SAML2/POST" index="7" /> - <AssertionConsumerService - Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST-SimpleSign" - Location="https://iga-tst.nebraska.edu/Shibboleth.sso/SAML2/POST-SimpleSign" - index="8" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Artifact" - Location="https://iga-tst.nebraska.edu/Shibboleth.sso/SAML2/Artifact" index="9" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:PAOS" - Location="https://iga-tst.nebraska.edu/Shibboleth.sso/SAML2/ECP" index="10" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:browser-post" - Location="https://iga-tst.nebraska.edu/Shibboleth.sso/SAML/POST" index="11" /> - <AssertionConsumerService Binding="urn:oasis:names:tc:SAML:1.0:profiles:artifact-01" - Location="https://iga-tst.nebraska.edu/Shibboleth.sso/SAML/Artifact" index="12" /> </SPSSODescriptor> <Organization> <OrganizationName xml:lang="en">Test @@ -1193,26 +1197,6 @@ <OrganizationURL xml:lang="en"> https://trueyoutest.nebraska.edu</OrganizationURL> </Organization> - <ContactPerson contactType="technical"> - <GivenName>ITS IAM - Team</GivenName> - <EmailAddress>its-sec-iam@nebraska.edu</EmailAddress> - </ContactPerson> - <ContactPerson contactType="administrative"> - <GivenName>ITS - IAM Team</GivenName> - <EmailAddress>its-sec-iam@nebraska.edu</EmailAddress> - </ContactPerson> - <ContactPerson contactType="support"> - <GivenName>ITS - IAM Team</GivenName> - <EmailAddress>its-sec-iam@nebraska.edu</EmailAddress> - </ContactPerson> - <ContactPerson contactType="other" remd:contactType="http://refeds.org/metadata/contactType/security"> - <GivenName>ITS - Security</GivenName> - <EmailAddress>security@nebraska.edu</EmailAddress> - </ContactPerson> </EntityDescriptor> <EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" ID="_159e0ae8e582b8520af0b227dcbdfb8d5e3489ce" entityID="https://scheduling.nebraska.edu/shibboleth"> <Extensions xmlns:alg="urn:oasis:names:tc:SAML:metadata:algsupport">