diff --git a/ckan/config/dbca.ini b/ckan/config/dbca.ini index 91aff776b..db6097f4b 100644 --- a/ckan/config/dbca.ini +++ b/ckan/config/dbca.ini @@ -85,7 +85,8 @@ ckanext.saml2auth.idp_metadata.location = local # Path to a local file accessible on the server the service runs on # Ignore this config if the idp metadata location is set to: remote -ckanext.saml2auth.idp_metadata.local_path = /srv/app/saml/dbca_idp.xml +# Will be set via a environment variable CKANEXT__SAML2AUTH__IDP_METADATA__LOCAL_PATH +# ckanext.saml2auth.idp_metadata.local_path = /srv/app/saml/dbca_staging_idp.xml # Corresponding SAML user field for firstname ckanext.saml2auth.user_firstname = givenName @@ -108,7 +109,8 @@ ckanext.saml2auth.enable_ckan_internal_login = True # Entity ID (also know as Issuer) # Define the entity ID. Default is urn:mace:umu.se:saml:ckan:sp -ckanext.saml2auth.entity_id = urn:mace:umu.se:saml:ckan_dbca_staging:sp +# Will be set via a environment variable CKANEXT__SAML2AUTH__ENTITY_ID +#ckanext.saml2auth.entity_id = urn:mace:umu.se:saml:ckan_dbca_staging:sp # A list of string values that will be used to set the element of the metadata of an entity. # Default: urn:oasis:names:tc:SAML:2.0:nameid-format:persistent diff --git a/ckan/saml/dbca_prod_idp.xml b/ckan/saml/dbca_prod_idp.xml new file mode 100644 index 000000000..c31bae50e --- /dev/null +++ b/ckan/saml/dbca_prod_idp.xml @@ -0,0 +1,180 @@ + + + + + + + + + + + + + D1tzApXI6ZLVLrRRkXpJinrjjIM9Dw7R6Z4PX9uMeMM= + + + CDbBXKGtCiOqoa8VZ+lqfz1YKp3AminyFoiF3XqJMwwL4qyyK6YETOcuN7I7TA8dZnavscq+TjlrlP5F22F23ttB4OsbsU9Im6b1pZa3mUwqhjl60LfDEiA/DLt+nDMrW9vKQrJ4kC3JApKXI7fDkehzK+hlqamhAyM7fzQ4qUs4j5A2XtfRxhNY7D7at1fZhPyn4ltApzsWQ9+scDGfM2bk6PXXPL5wYQUxtzt4HoDgvk27QUs2XeGMm+FYFbHtwNOcWnvisVR4MZSJrmAScpboUUfZQVO2Z8cKX+vKzLXs48YpueChRQfspMDNJtHNSwWciOcDNGb9sWfmFG7Kgw== + + + MIIC8DCCAdigAwIBAgIQffsi+MjD7YxARMC68v57XjANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yNDA3MTkwNDE4MzJaFw0yNzA3MTkwNDE4MzJaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtjs5zxB/ZHe0lYbgpnenhx2ybF3y+5Hawq/W/peh30i8cGxODJrTNwMnDU3kn5rHGiIjfjoIZhCClPFNxqGj3SamIt/0R468ZH+PgR1SiZN2Qph/8H8sKErf8kir+30cIW7hUNsCAehePTZ3dwtNFDXKf8qUn464FKyRRM62wOZrIh3azgv+Q0gBtSifZdOmbnFv6bkMehFLAMicZ5HIcmgsp0oOsLdiYohUlFKTbz50PYw7R0xbnTaZ/HfKSRf1qsQ+KcNqyNsZqL9VXh5S2mLWWhT8ijJ5IimvHag+edlNPNOwMDCkC2vnWYiz3gcZAbJHJzPrBJ6a7n0hPDDJhQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQBlgBlnV4RG9gkUe1JdLslRWgVL9ecfA9cY4N4uf52GiI8zvb0Br4TESfns8r0QXYvZD3XcYOm5sTyk0d2bEPmhAenV8xhXE7hv0aLnJA12LhTgMryA8BTKnk79hpfE3h3KTZHfWfnfch4kL7l0gH6BFCC4aRi+Ka9agI8d6UFh3XriuJgjaZb5ElYErf0rWrEOV1U1ULIOct1m4I26mO8aUhkvqmTokEcRGChSXdwUmU3TGiJugUfHmAlw5sq6Ui9d9nrTbpZX+WjkCGnhK7JD/wrYydaFaC4tlK8+YMwW2yhO6j3MYQcXxR6khVeFnMT9y8h73J6IglQk1U9f5fyc + + + + + + + + MIIC8DCCAdigAwIBAgIQffsi+MjD7YxARMC68v57XjANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yNDA3MTkwNDE4MzJaFw0yNzA3MTkwNDE4MzJaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtjs5zxB/ZHe0lYbgpnenhx2ybF3y+5Hawq/W/peh30i8cGxODJrTNwMnDU3kn5rHGiIjfjoIZhCClPFNxqGj3SamIt/0R468ZH+PgR1SiZN2Qph/8H8sKErf8kir+30cIW7hUNsCAehePTZ3dwtNFDXKf8qUn464FKyRRM62wOZrIh3azgv+Q0gBtSifZdOmbnFv6bkMehFLAMicZ5HIcmgsp0oOsLdiYohUlFKTbz50PYw7R0xbnTaZ/HfKSRf1qsQ+KcNqyNsZqL9VXh5S2mLWWhT8ijJ5IimvHag+edlNPNOwMDCkC2vnWYiz3gcZAbJHJzPrBJ6a7n0hPDDJhQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQBlgBlnV4RG9gkUe1JdLslRWgVL9ecfA9cY4N4uf52GiI8zvb0Br4TESfns8r0QXYvZD3XcYOm5sTyk0d2bEPmhAenV8xhXE7hv0aLnJA12LhTgMryA8BTKnk79hpfE3h3KTZHfWfnfch4kL7l0gH6BFCC4aRi+Ka9agI8d6UFh3XriuJgjaZb5ElYErf0rWrEOV1U1ULIOct1m4I26mO8aUhkvqmTokEcRGChSXdwUmU3TGiJugUfHmAlw5sq6Ui9d9nrTbpZX+WjkCGnhK7JD/wrYydaFaC4tlK8+YMwW2yhO6j3MYQcXxR6khVeFnMT9y8h73J6IglQk1U9f5fyc + + + + + + Name + The mutable display name of the user. + + + Subject + An immutable, globally unique, non-reusable identifier of the user that is unique to the application for which a token is issued. + + + Given Name + First name of the user. + + + Surname + Last name of the user. + + + Display Name + Display name of the user. + + + Nick Name + Nick name of the user. + + + Authentication Instant + The time (UTC) when the user is authenticated to Windows Azure Active Directory. + + + Authentication Method + The method that Windows Azure Active Directory uses to authenticate users. + + + ObjectIdentifier + Primary identifier for the user in the directory. Immutable, globally unique, non-reusable. + + + TenantId + Identifier for the user's tenant. + + + IdentityProvider + Identity provider for the user. + + + Email + Email address of the user. + + + Groups + Groups of the user. + + + External Access Token + Access token issued by external identity provider. + + + External Access Token Expiration + UTC expiration time of access token issued by external identity provider. + + + External OpenID 2.0 Identifier + OpenID 2.0 identifier issued by external identity provider. + + + GroupsOverageClaim + Issued when number of user's group claims exceeds return limit. + + + Role Claim + Roles that the user or Service Principal is attached to + + + RoleTemplate Id Claim + Role template id of the Built-in Directory Roles that the user is a member of + + + + + https://login.microsoftonline.com/7b934664-cdcf-4e28-a3ee-1a5bcca0a1b6/wsfed + + + + + https://login.microsoftonline.com/7b934664-cdcf-4e28-a3ee-1a5bcca0a1b6/wsfed + + + + + + + + MIIC8DCCAdigAwIBAgIQffsi+MjD7YxARMC68v57XjANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yNDA3MTkwNDE4MzJaFw0yNzA3MTkwNDE4MzJaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtjs5zxB/ZHe0lYbgpnenhx2ybF3y+5Hawq/W/peh30i8cGxODJrTNwMnDU3kn5rHGiIjfjoIZhCClPFNxqGj3SamIt/0R468ZH+PgR1SiZN2Qph/8H8sKErf8kir+30cIW7hUNsCAehePTZ3dwtNFDXKf8qUn464FKyRRM62wOZrIh3azgv+Q0gBtSifZdOmbnFv6bkMehFLAMicZ5HIcmgsp0oOsLdiYohUlFKTbz50PYw7R0xbnTaZ/HfKSRf1qsQ+KcNqyNsZqL9VXh5S2mLWWhT8ijJ5IimvHag+edlNPNOwMDCkC2vnWYiz3gcZAbJHJzPrBJ6a7n0hPDDJhQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQBlgBlnV4RG9gkUe1JdLslRWgVL9ecfA9cY4N4uf52GiI8zvb0Br4TESfns8r0QXYvZD3XcYOm5sTyk0d2bEPmhAenV8xhXE7hv0aLnJA12LhTgMryA8BTKnk79hpfE3h3KTZHfWfnfch4kL7l0gH6BFCC4aRi+Ka9agI8d6UFh3XriuJgjaZb5ElYErf0rWrEOV1U1ULIOct1m4I26mO8aUhkvqmTokEcRGChSXdwUmU3TGiJugUfHmAlw5sq6Ui9d9nrTbpZX+WjkCGnhK7JD/wrYydaFaC4tlK8+YMwW2yhO6j3MYQcXxR6khVeFnMT9y8h73J6IglQk1U9f5fyc + + + + + + https://sts.windows.net/7b934664-cdcf-4e28-a3ee-1a5bcca0a1b6/ + + + + + https://login.microsoftonline.com/7b934664-cdcf-4e28-a3ee-1a5bcca0a1b6/wsfed + + + + + https://login.microsoftonline.com/7b934664-cdcf-4e28-a3ee-1a5bcca0a1b6/wsfed + + + + + + + + MIIC8DCCAdigAwIBAgIQffsi+MjD7YxARMC68v57XjANBgkqhkiG9w0BAQsFADA0MTIwMAYDVQQDEylNaWNyb3NvZnQgQXp1cmUgRmVkZXJhdGVkIFNTTyBDZXJ0aWZpY2F0ZTAeFw0yNDA3MTkwNDE4MzJaFw0yNzA3MTkwNDE4MzJaMDQxMjAwBgNVBAMTKU1pY3Jvc29mdCBBenVyZSBGZWRlcmF0ZWQgU1NPIENlcnRpZmljYXRlMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAtjs5zxB/ZHe0lYbgpnenhx2ybF3y+5Hawq/W/peh30i8cGxODJrTNwMnDU3kn5rHGiIjfjoIZhCClPFNxqGj3SamIt/0R468ZH+PgR1SiZN2Qph/8H8sKErf8kir+30cIW7hUNsCAehePTZ3dwtNFDXKf8qUn464FKyRRM62wOZrIh3azgv+Q0gBtSifZdOmbnFv6bkMehFLAMicZ5HIcmgsp0oOsLdiYohUlFKTbz50PYw7R0xbnTaZ/HfKSRf1qsQ+KcNqyNsZqL9VXh5S2mLWWhT8ijJ5IimvHag+edlNPNOwMDCkC2vnWYiz3gcZAbJHJzPrBJ6a7n0hPDDJhQIDAQABMA0GCSqGSIb3DQEBCwUAA4IBAQBlgBlnV4RG9gkUe1JdLslRWgVL9ecfA9cY4N4uf52GiI8zvb0Br4TESfns8r0QXYvZD3XcYOm5sTyk0d2bEPmhAenV8xhXE7hv0aLnJA12LhTgMryA8BTKnk79hpfE3h3KTZHfWfnfch4kL7l0gH6BFCC4aRi+Ka9agI8d6UFh3XriuJgjaZb5ElYErf0rWrEOV1U1ULIOct1m4I26mO8aUhkvqmTokEcRGChSXdwUmU3TGiJugUfHmAlw5sq6Ui9d9nrTbpZX+WjkCGnhK7JD/wrYydaFaC4tlK8+YMwW2yhO6j3MYQcXxR6khVeFnMT9y8h73J6IglQk1U9f5fyc + + + + + + + + \ No newline at end of file diff --git a/ckan/saml/dbca_idp.xml b/ckan/saml/dbca_staging_idp.xml similarity index 100% rename from ckan/saml/dbca_idp.xml rename to ckan/saml/dbca_staging_idp.xml