Columbia Identity — Shibboleth IdP and CAS
Columbia University Information Technology operates the university's own identity infrastructure: a production Shibboleth Identity Provider publishing signed SAML 2.0 metadata anonymously under the InCommon entityID urn:mace:incommon:columbia.edu, and a CAS server handling browser single sign-on with UNI credentials and MFA. The metadata is the most substantial machine-readable artifact Columbia publishes about itself — two X.509 key descriptors, four SSO endpoints, three SAML bindings, a declared scope of columbia.edu and a logout handoff to CAS. It is readable by anyone and actionable by nobody outside the university: relying parties are registered by CUIT and there is no public or dynamic registration. No OpenID Connect discovery document is published.