Shibboleth Identity Provider (SAML 2.0 metadata)

The University of Sydney's federation entity serves signed SAML 2.0 metadata from federation.sydney.edu.au: entityID https://federation.sydney.edu.au/idp/shibboleth, an IDPSSODescriptor advertising urn:oasis:names:tc:SAML:2.0:protocol, the Shibboleth metadata extension shibmd:Scope=sydney.edu.au, an idp-signing.crt key the institution issued itself in 2018, and Redirect, POST and POST-SimpleSign SingleSignOnService bindings. The entity appears in the Australian Access Federation aggregate as "The University of Sydney" and in the eduGAIN interfederation aggregate. Operator is TENANT, not institution, and the DNS says so: federation.sydney.edu.au CNAMEs to d007b274d34f1a4319cafeaf6941cfa7.idp-cname.aaf.edu.au and answers from CloudFront + an AWS ALB running Jetty 12.1.0 under an Amazon-issued certificate — the AAF Rapid IdP hosted identity service, not university-run infrastructure. The federation membership, the entityID, the scope and the signing key are the university's; the running software is AAF's. This is still the only openly machine-readable artifact served under a University of Sydney hostname, and it is not consumable by third-party developers — relying parties must be registered service providers in AAF or eduGAIN.

API entry from apis.yml

apis.yml Raw ↑
aid: university-of-sydney:identity-federation
name: Shibboleth Identity Provider (SAML 2.0 metadata)
x-operator: tenant
x-vendor: Australian Access Federation (Rapid IdP)
x-surface-class: IdentityFederation
description: 'The University of Sydney''s federation entity serves signed SAML 2.0 metadata from federation.sydney.edu.au:
  entityID https://federation.sydney.edu.au/idp/shibboleth, an IDPSSODescriptor advertising urn:oasis:names:tc:SAML:2.0:protocol,
  the Shibboleth metadata extension shibmd:Scope=sydney.edu.au, an idp-signing.crt key the institution
  issued itself in 2018, and Redirect, POST and POST-SimpleSign SingleSignOnService bindings. The entity
  appears in the Australian Access Federation aggregate as "The University of Sydney" and in the eduGAIN
  interfederation aggregate. Operator is TENANT, not institution, and the DNS says so: federation.sydney.edu.au
  CNAMEs to d007b274d34f1a4319cafeaf6941cfa7.idp-cname.aaf.edu.au and answers from CloudFront + an AWS
  ALB running Jetty 12.1.0 under an Amazon-issued certificate — the AAF Rapid IdP hosted identity service,
  not university-run infrastructure. The federation membership, the entityID, the scope and the signing
  key are the university''s; the running software is AAF''s. This is still the only openly machine-readable
  artifact served under a University of Sydney hostname, and it is not consumable by third-party developers
  — relying parties must be registered service providers in AAF or eduGAIN.'
humanURL: https://federation.sydney.edu.au/idp/shibboleth
baseURL: https://federation.sydney.edu.au/idp/
tags:
- Identity Federation
- SAML
- Shibboleth
- eduGAIN
- AAF
- Rapid IdP
- Tenant
- Authentication
properties:
- type: Authentication
  url: authentication/university-of-sydney-authentication.yml
- type: Conformance
  url: conformance/university-of-sydney-education-standards.yml