...
Code Block | ||||||
---|---|---|---|---|---|---|
| ||||||
<?xml version="1.0" encoding="UTF-8"?> <AttributeFilterPolicyGroup id="ShibbolethFilterPolicy" xmlns="urn:mace:shibboleth:2.0:afp" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="urn:mace:shibboleth:2.0:afp http://shibboleth.net/schema/idp/shibboleth-afp.xsd"> <!-- REFEDS ReleaseAnonymous theAuthorization transient ID to anyoneEntity Category --> <AttributeFilterPolicy id="releaseTransientIdToAnyonereleaseToRefedsAnonymous"> <PolicyRequirementRule xsi:type="ANYEntityAttributeExactMatch" /> <AttributeRule attributeID="transientId"> attributeName="http://macedir.org/entity-category" attributeValue="https://refeds.org/category/anonymous" /> <AttributeRule attributeID="eduPersonScopedAffiliation"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> </AttributeFilterPolicy> <!-- GEANT Data protection Code of Conduct <AttributeRule attributeID="schacHomeOrganization"> <PermitValueRule xsi:type="ANY"/> </AttributeRule> </AttributeFilterPolicy> <!-- REFEDS Pseudonymous Authorization Entity Category --> <AttributeFilterPolicy id="releaseToCoCo"> <!-- Supports data minimalisation to prevent use together with anonymous --> <AttributeFilterPolicy id="releaseToRefedsPseudonymous"> <PolicyRequirementRule xsi:type="EntityAttributeExactMatchAND"> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="httphttps://wwwrefeds.geant.netorg/uri/dataprotection-code-of-conduct/v1category/pseudonymous" /> <AttributeRule attributeID="eduPersonTargetedID <Rule xsi:type="NOT"> <PermitValueRule <Rule xsi:type="EntityAttributeExactMatch" attributeName="AttributeInMetadatahttp://macedir.org/entity-category" onlyIfRequiredattributeValue="truehttps://refeds.org/category/anonymous" /> </AttributeRule> <AttributeRule attributeID="eduPersonPrincipalName"> </Rule> </PolicyRequirementRule> <AttributeRule attributeID="samlPairwiseID"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" ANY"/> </AttributeRule> <AttributeRule attributeID="eduPersonOrcideduPersonScopedAffiliation"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> ANY"/> </AttributeRule> <AttributeRule attributeID="schacHomeOrganization"> <PermitValueRule xsi:type="ANY"/> </AttributeRule> <AttributeRule attributeID="norEduPersonNINeduPersonAssurance"> <PermitValueRule xsi:type="ANDANY"> /> </AttributeRule> </AttributeFilterPolicy> <!-- REFEDS Personalized Access Entity Category --> <!-- Supports data minimalisation to prevent use together with anonymous and pseudonymous--> <AttributeFilterPolicy id="releaseToRefedsPersonalized"> <PolicyRequirementRule xsi:type="AND"> <Rule xsi:type="AttributeInMetadataEntityAttributeExactMatch" onlyIfRequiredattributeName="true" /> http://macedir.org/entity-category" attributeValue="https://refeds.org/category/personalized" /> <Rule xsi:type="NOT"> <Rule xsi:type="OR"> <Rule xsi:type="RegistrationAuthorityEntityAttributeExactMatch" registrarsattributeName="http://wwwmacedir.swamid.se/" /> </PermitValueRule> </AttributeRule> <AttributeRule attributeID="personalIdentityNumber"> org/entity-category" attributeValue="https://refeds.org/category/anonymous" /> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="https://refeds.org/category/pseudonymous" /> </Rule> </Rule> </PolicyRequirementRule> <AttributeRule attributeID="samlSubjectID"> <PermitValueRule xsi:type="ANDANY" /> <Rule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> <Rule xsi:type="RegistrationAuthority" registrars="http://www.swamid.se/" /> </PermitValueRule> </AttributeRule> <AttributeRule attributeID="schacDateOfBirth"> </AttributeRule> <AttributeRule attributeID="displayName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="givenName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="sn"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="mail"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="eduPersonAssurance"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="schacHomeOrganization"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> ANY" /> </AttributeRule> <AttributeRule attributeID="maileduPersonScopedAffiliation"> <PermitValueRule <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="truexsi:type="OR"> <Rule xsi:type="Value" value="faculty" caseSensitive="false" /> </AttributeRule> <AttributeRule attributeID="cn"> <PermitValueRule <Rule xsi:type="Value" value="student" caseSensitive="false"/> <Rule xsi:type="AttributeInMetadataValue" onlyIfRequiredvalue="truestaff" caseSensitive="false"/> <Rule xsi:type="Value" </AttributeRule> <AttributeRule attributeID="displayName"> <PermitValueRule value="alum" caseSensitive="false"/> <Rule xsi:type="Value" value="member" caseSensitive="false"/> <Rule xsi:type="AttributeInMetadataValue" onlyIfRequiredvalue="trueaffiliate" caseSensitive="false"/> <Rule xsi:type="Value" </AttributeRule> <AttributeRule attributeID="givenName"> <PermitValueRule value="employee" caseSensitive="false"/> <Rule xsi:type="AttributeInMetadataValue" onlyIfRequiredvalue="truelibrary-walk-in" caseSensitive="false"/> </PermitValueRule> </AttributeRule> </AttributeFilterPolicy> <!-- Rule to honour Subject ID requirement tag <AttributeRule attributeID="sn"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="eduPersonAssurance"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="eduPersonScopedAffiliation"> <PermitValueRule xsi:type="AND"> <Rule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> <Rule xsi:type="OR"> in metadata. Used in combination with Geant/Refeds Code of Conduct v* --> <!-- Code of Conduct can be combined with other entity categories --> <!-- Supports data minimalisation to prevent subject-id and pairwise-id being released together --> <AttributeFilterPolicy id="subject-identifiers"> <PolicyRequirementRule xsi:type="OR"> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="http://www.geant.net/uri/dataprotection-code-of-conduct/v1" /> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="https://refeds.org/category/code-of-conduct/v2" /> </PolicyRequirementRule> <AttributeRule attributeID="samlPairwiseID"> <PermitValueRule xsi:type="AND"> <Rule xsi:type="Value" value="faculty" ignoreCase="true" /> NOT"> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="https://refeds.org/category/personalized" /> </Rule> <Rule xsi:type="Value" value="student" ignoreCase="trueOR"> <Rule xsi:type="EntityAttributeExactMatch" attributeName="urn:oasis:names:tc:SAML:profiles:subject-id:req" attributeNameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" attributeValue="pairwise-id" /> <Rule <Rule xsi:type="Value" value="staff" ignoreCase="true" /> xsi:type="EntityAttributeExactMatch" attributeName="urn:oasis:names:tc:SAML:profiles:subject-id:req" attributeNameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" attributeValue="any" /> </Rule> </PermitValueRule> </AttributeRule> <AttributeRule attributeID="samlSubjectID"> <PermitValueRule xsi:type="AND"> <Rule xsi:type="Value" value="alum" ignoreCase="true" /> NOT"> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="https://refeds.org/category/pseudonymous" /> </Rule> <Rule xsi:type="ValueEntityAttributeExactMatch" value="member" ignoreCase="trueattributeName="urn:oasis:names:tc:SAML:profiles:subject-id:req" attributeNameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri" attributeValue="subject-id" /> </PermitValueRule> </AttributeRule> </AttributeFilterPolicy> <!-- GEANT Data protection Code of Conduct or REFEDS Data Protection Code of Conduct Entity Category --> <AttributeFilterPolicy id="releaseToCodeOfConduct"> <PolicyRequirementRule xsi:type="OR"> <Rule xsi:type="ValueEntityAttributeExactMatch" valueattributeName="affiliatehttp://macedir.org/entity-category" ignoreCaseattributeValue="true" /> http://www.geant.net/uri/dataprotection-code-of-conduct/v1" /> <Rule xsi:type="ValueEntityAttributeExactMatch" valueattributeName="employeehttp://macedir.org/entity-category" ignoreCaseattributeValue="truehttps://refeds.org/category/code-of-conduct/v2" /> <Rule </PolicyRequirementRule> <AttributeRule attributeID="eduPersonTargetedID"> <PermitValueRule xsi:type="ValueAttributeInMetadata" valueonlyIfRequired="library-walk-in" ignoreCase="true" /> </Rule> </PermitValueRule> </AttributeRule> true" /> </AttributeRule> <AttributeRule attributeID="eduPersonPrincipalName"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="eduPersonAffiliationeduPersonOrcid"> <PermitValueRule <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="onorEduPersonNIN"> <PermitValueRule <PermitValueRule xsi:type="AND"> <Rule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <Rule xsi:type="RegistrationAuthority" registrars="http://www.swamid.se/" /> </PermitValueRule> </AttributeRule> <AttributeRule attributeID="norEduOrgAcronympersonalIdentityNumber"> <PermitValueRule <PermitValueRule xsi:type="AND"> <Rule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <Rule xsi:type="RegistrationAuthority" registrars="http://www.swamid.se/" /> </PermitValueRule> </AttributeRule> <AttributeRule attributeID="cschacDateOfBirth"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="comail"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="schacHomeOrganizationcn"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="schacHomeOrganizationTypedisplayName"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> </AttributeFilterPolicy> <!-- REFEDS Research and Schoolarship --> <AttributeFilterPolicy id="releaseToRandS"> <PolicyRequirementRule <AttributeRule attributeID="givenName"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="sn"> <PermitValueRule xsi:type="EntityAttributeExactMatchAttributeInMetadata" attributeName="http://macedir.org/entity-category" attributeValue="http://refeds.org/category/research-and-scholarship onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="eduPersonAssurance"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> <!-- Alternative configuration examples for ePTID. See the static variables section of the attribute resolver. <AttributeRule attributeID="eduPersonTargetedID"> <PermitValueRule </AttributeRule> <AttributeRule attributeID="eduPersonScopedAffiliation"> <PermitValueRule xsi:type="AND"> <Rule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> <Rule xsi:type="OR"> <Rule xsi:type="NOTValue"> value="faculty" caseSensitive="false" /> <Rule xsi:type="Value" value="https://refeds.org/assurance/ID/eppn-unique-no-reassignstudent" attributeIDcaseSensitive="eduPersonAssurancefalse" /> <Rule xsi:type="Value" value="staff" </PermitValueRule> </AttributeRule> --> <!-- <AttributeRule attributeID="eduPersonTargetedID"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> --> <AttributeRule attributeID="displayName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="givenName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="sn"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="mail"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="eduPersonAssurance"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="eduPersonPrincipalName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="eduPersonScopedAffiliation"> <PermitValueRule xsi:type="OR"> <Rule xsi:type="Value" value="faculty" ignoreCase="true" /> caseSensitive="false" /> <Rule xsi:type="Value" value="alum" caseSensitive="false" /> <Rule xsi:type="Value" value="member" caseSensitive="false" /> <Rule xsi:type="Value" value="affiliate" caseSensitive="false" /> <Rule xsi:type="Value" value="employee" caseSensitive="false" /> <Rule xsi:type="Value" value="library-walk-in" caseSensitive="false" /> </Rule> </PermitValueRule> </AttributeRule> <AttributeRule attributeID="eduPersonAffiliation"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="o"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="norEduOrgAcronym"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="c"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="co"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="schacHomeOrganization"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> <AttributeRule attributeID="schacHomeOrganizationType"> <PermitValueRule xsi:type="AttributeInMetadata" onlyIfRequired="true" /> </AttributeRule> </AttributeFilterPolicy> <!-- REFEDS Research and Scholarship Entity Category --> <AttributeFilterPolicy id="releaseToRefedsResearchAndScholarship"> <PolicyRequirementRule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="http://refeds.org/category/research-and-scholarship" /> <AttributeRule attributeID="eduPersonTargetedID"> <PermitValueRule xsi:type="NOT"> <Rule xsi:type="Value" value="studenthttps://refeds.org/assurance/ID/eppn-unique-no-reassign" ignoreCaseattributeID="trueeduPersonAssurance" /> </PermitValueRule> </AttributeRule> <AttributeRule <Rule attributeID="displayName"> <PermitValueRule xsi:type="Value" value="staff" ignoreCase="true" /> <Rule ANY" /> </AttributeRule> <AttributeRule attributeID="givenName"> <PermitValueRule xsi:type="Value" value="alum" ignoreCase="true" /> <Rule ANY" /> </AttributeRule> <AttributeRule attributeID="sn"> <PermitValueRule xsi:type="ValueANY" value/> </AttributeRule> <AttributeRule attributeID="member" ignoreCase="truemail"> <PermitValueRule xsi:type="ANY" /> <Rule </AttributeRule> <AttributeRule attributeID="eduPersonAssurance"> <PermitValueRule xsi:type="ValueANY" value/> </AttributeRule> <AttributeRule attributeID="affiliate" ignoreCase="trueeduPersonPrincipalName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="eduPersonScopedAffiliation"> <PermitValueRule xsi:type="OR"> <Rule xsi:type="Value" value="employeefaculty" ignoreCasecaseSensitive="truefalse" /> <Rule xsi:type="Value" value="library-walk-instudent" ignoreCasecaseSensitive="truefalse" /> <Rule xsi:type="Value" </PermitValueRule> </AttributeRule> </AttributeFilterPolicy> <!-- ESI European Student Identifier --> <AttributeFilterPolicy id="entity-category-european-student-identifier"> <PolicyRequirementRule xsi:type="OR"> value="staff" caseSensitive="false" /> <Rule xsi:type="Value" value="alum" caseSensitive="false" /> <Rule xsi:type="Value" value="member" caseSensitive="false" /> <Rule xsi:type="Value" value="affiliate" caseSensitive="false" /> <Rule xsi:type="Value" value="employee" caseSensitive="false" /> <Rule xsi:type="EntityAttributeExactMatchValue" value="library-walk-in" caseSensitive="false" /> </PermitValueRule> </AttributeRule> </AttributeFilterPolicy> <!-- ESI European Student Identifier --> <AttributeFilterPolicy id="entity-category-european-student-identifier"> <PolicyRequirementRule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="https://myacademicid.org/entity-categories/esi" /> <AttributeRule <Rule xsiattributeID="schacPersonalUniqueCode"> <PermitValueRule xsi:type="RequesterValueRegex" valueregex="https://proxy.prod.erasmus.eduteams.org/metadata/backend.xml^urn:schac:personalUniqueCode:int:esi:.*" /> </PolicyRequirementRule> <AttributeRule attributeID="schacPersonalUniqueCode"> <PermitValueRule </AttributeRule> </AttributeFilterPolicy> <!-- DEPRECATED entity-category-swamid-research-and-education --> <AttributeFilterPolicy id="entity-category-research-and-education"> <PolicyRequirementRule xsi:type="ValueRegex" regex="^urn:schac:PersonalUniqueCode:int:esi:.*" /> </AttributeRule> </AttributeFilterPolicy> <!-- DEPRECATED entity-category-swamid-research-and-education WILL BE REMOVED 2020-10-31 --> <AttributeFilterPolicy id="entity-category-research-and-education"> <PolicyRequirementRule xsi:type="AND"> <Rule xsi:type="OR"> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="http://www.swamid.se/category/eu-adequate-protection" /> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="http://www.swamid.se/category/nren-service" /> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="http://www.swamid.se/category/hei-service" /> </Rule> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="http://www.swamid.se/category/research-and-education" /> </PolicyRequirementRule> <AttributeRule attributeID="givenName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="sn"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="displayName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="cn"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="eduPersonPrincipalName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="eduPersonAssurance"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="mail"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="eduPersonScopedAffiliation"> <PermitValueRule xsi:type="OR"> <Rule xsi:type="Value" value="faculty" ignoreCase="true" /> <Rule xsi:type="Value" value="student" ignoreCase="true" /> <Rule xsi:type="Value" value="staff" ignoreCase="true" /> <Rule xsi:type="Value" value="alum" ignoreCase="true" /> <Rule xsi:type="Value" value="member" ignoreCase="true" /> <Rule xsi:type="Value" value="affiliate" ignoreCase="true" /> <Rule xsi:type="Value" value="employee" ignoreCase="true" /> <Rule xsi:type="Value" value="library-walk-in" ignoreCase="true" /> </PermitValueRule> </AttributeRule> <AttributeRule attributeID="o"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="norEduOrgAcronym"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="c"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="co"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="schacHomeOrganization"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> </AttributeFilterPolicy> <!-- DEPRECATED entity-category-sfs-1993-1153 WILL BE REMOVED 2020-10-31--> <AttributeFilterPolicy id="entity-category-sfs-1993-1153"> <PolicyRequirementRule xsi:type="EntityAttributeExactMatch" AND"> <Rule xsi:type="OR"> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="http://www.swamid.se/category/eu-adequate-protection" /> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="http://www.swamid.se/category/nren-service" /> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="http://www.swamid.se/category/hei-service" /> </Rule> <Rule xsi:type="EntityAttributeExactMatch" attributeName="http://macedir.org/entity-category" attributeValue="http://www.swamid.se/category/sfsresearch-1993and-1153education" /> </PolicyRequirementRule> <AttributeRule attributeID="norEduPersonNINgivenName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="eduPersonAssurance"> <AttributeRule attributeID="sn"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> </AttributeFilterPolicy> <!-- Examples of entityId based release to Service Providers --> <!-- Release to testshib.org --> <!-- <AttributeFilterPolicy id="testShib"> <PolicyRequirementRule <AttributeRule attributeID="displayName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="cn"> <PermitValueRule xsi:type="Requester" value="https://sp.testshib.org/shibboleth-spANY" /> </AttributeRule> <AttributeRule attributeID="givenNameeduPersonPrincipalName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="commonNameeduPersonAssurance"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="surnamemail"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="principaleduPersonScopedAffiliation"> <PermitValueRule xsi:type="OR"> <Rule xsi:type="Value" value="faculty" <PermitValueRulecaseSensitive="false" /> <Rule xsi:type="ANY"Value" value="student" caseSensitive="false" /> <Rule xsi:type="Value" </AttributeRule> </AttributeFilterPolicy> --> <!-- NyA-webben UHR --> <!-- <AttributeFilterPolicy id="releaseNyAwebbenEntitlement"> <PolicyRequirementRulevalue="staff" caseSensitive="false" /> <Rule xsi:type="Value" value="alum" caseSensitive="false" /> <Rule xsi:type="ORValue"> value="member" caseSensitive="false" /> <Rule xsi:type="RequesterValue" value="https://expert.antagning.se/ecs-spaffiliate" caseSensitive="false" /> <Rule xsi:type="RequesterValue" value="https://expert.testa.antagning.se/ecs-sp="employee" caseSensitive="false" /> <Rule xsi:type="Value" value="Requesterlibrary-walk-in" valuecaseSensitive="https://expert.testb.antagning.se/ecs-spfalse" /> </PolicyRequirementRule>PermitValueRule> </AttributeRule> <AttributeRule attributeID="NyAwebbenEntitlemento"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="norEduOrgAcronym"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> </AttributeFilterPolicy> --> <!-- TCS - Digicert until 2020-04-30 --> <!-- New TCS Personal --> <!-- <AttributeFilterPolicy id="releaseTcsPersonalEntitlement"> <PolicyRequirementRule xsi:type="Requester" value="https://www.digicert.com/sso" /> <AttributeRule attributeID="displayName"> <AttributeRule attributeID="co"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="c"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="schacHomeOrganization"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> </AttributeFilterPolicy> <!-- DEPRECATED entity-category-sfs-1993-1153 <AttributeRule attributeID="eduPersonPrincipalName"> <PermitValueRule--> <AttributeFilterPolicy id="entity-category-sfs-1993-1153"> <PolicyRequirementRule xsi:type="ANYEntityAttributeExactMatch"/> </AttributeRule> <AttributeRule attributeID="tcsPersonalEntitlement"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> attributeName="http://macedir.org/entity-category" attributeValue="http://www.swamid.se/category/sfs-1993-1153" /> <AttributeRule attributeID="mailnorEduPersonNIN"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="schacHomeOrganizationeduPersonAssurance"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> </AttributeFilterPolicy> --> <!-- TCS - Sectigo 2020-05-01 and forward --> <!-- Please see https://wiki.sunet.se/display/SWAMID/SAML-konfiguration+Sunet+TCS --> </AttributeFilterPolicy> <!-- for information on how to create a resolver for tcsPersonalEntitlement. Sectigo --> <!-- <AttributeFilterPolicy id="releaseSectigoAttributeBundle"> <PolicyRequirementRule xsi:type="Requester" value="https://cert-manager.com/shibboleth" /> <AttributeRule attributeID="eduPersonPrincipalName"> <AttributeRule attributeID="eduPersonPrincipalName"> <PermitValueRule xsi:type="ANY"/> </AttributeRule> <AttributeRule attributeID="displayName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="givenName"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="mail"> <PermitValueRule xsi:type="ANY" /> </AttributeRule> <AttributeRule attributeID="sn"> <PermitValueRule xsi:type="ANY"/> </AttributeRule> <AttributeRule attributeID="schacHomeOrganization"> <PermitValueRule xsi:type="ANY"/> </AttributeRule> <AttributeRule attributeID="tcsPersonalEntitlement"> <PermitValueRule xsi:type="ANY"/> </AttributeRule> < </AttributeFilterPolicy> --> <!-- PLACEHOLDER DO NOT REMOVE --> </AttributeFilterPolicyGroup> |
...