University of Tübingen Shibboleth Identity Provider (DFN-AAI / eduGAIN)
Institution-operated Shibboleth SAML 2.0 identity provider, registered in DFN-AAI — the German national research and education identity federation — and published as machine-readable metadata through the federation's MDQ service. EntityID https://idp.uni-tuebingen.de/shibboleth, DisplayName "Universität Tübingen" / "University of Tübingen", shibmd:Scope uni-tuebingen.de, registered 2009-05-26 under registrationAuthority https://www.aai.dfn.de and exported to eduGAIN. SSO endpoints: /idp/profile/SAML2/POST/SSO, /idp/profile/SAML2/Redirect/SSO and /idp/profile/SAML2/SOAP/ECP, plus a SAML 2.0 AttributeAuthorityDescriptor with a SOAP AttributeService. NameID formats persistent and transient. The signing certificate is issued to CN=idp.uni-tuebingen.de, OU=ZDV, O=Universitaet Tuebingen — the university's own computing centre holds the key. Entity attributes assert REFEDS Research & Scholarship support, SIRTFI and SIRTFI2 assurance certification, and membership of bwIDM, the Baden-Württemberg federated identity programme (independently corroborated by the bwIDM link in FDAT's own footer). A federation is shared by definition; the IdP behind it is entirely the institution's, and this is the strongest institution-operated machine surface the university has. RETRIEVAL WARNING: the DFN MDQ service answers 200 with a signed but EMPTY EntitiesDescriptor for an unregistered entityID — the plausible-looking https://idp.uni-tuebingen.de/idp/shibboleth is exactly such a false 200.