TU Dresden Identity Provider (Shibboleth SAML 2.0 + OpenID Connect)
The university's own Shibboleth identity provider, operated by ZIH, and the surface class this pipeline exists to surface: institution-operated by definition, fully machine-readable, and almost never catalogued. The SAML 2.0 metadata document at /idp/shibboleth carries an IDPSSODescriptor with four SingleSignOnService bindings — HTTP-POST, HTTP-POST-SimpleSign, HTTP-Redirect and SOAP ECP on port 8443 — plus four signing and encryption KeyDescriptors. REFEDS MET confirms the entity is exported from DFN-AAI into eduGAIN and republished by the InCommon, SWAMID and UK Access Management federations, and that it holds both the REFEDS Research and Scholarship entity category and SIRTFI. The same IdP now also speaks OpenID Connect, correcting the June 2026 profile which recorded OIDC as planned but unavailable: /.well-known/openid-configuration returns issuer https://idp.tu-dresden.de, response_types [code], grant_types [authorization_code], scopes [openid], four token-endpoint auth methods including private_key_jwt, and claims_supported carrying the eduPerson set — eduPersonPrincipalName, eduPersonScopedAffiliation, eduPersonAssurance and eduPersonEntitlement. /idp/profile/oidc/keyset serves a three-key JWKS.