Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

De to services Bst2Idws og JWT2Idws minder om hinanden i opbygning af requests, understøttede claims og valideringer. Disse beskrives derfor under et i afsnittet om claims og valideringer. JWT2OIOSaml beskrives for sig selv.

 BST tokens

Bst2Idws servicen tager imod 3 typer af BST tokens. For hver token udsteder (issuer), konfigureres token typen i tabellen sts_audconf.trustedIdpCitizenConfiguration.

Nedenfor ses en oversigt over de 3 tokens og deres attributter.

...

Attribut

...

OIO2BST

...

OIO2BST-LEGACY

...

OIO3BST

...

Issuer (IdP/STS der har udstedt tokenet)

...

Ja

...

Ja

...

Ja

...

LoA (Sikringsniveau/AssuranceLevel angivet som NSIS- eller NIST-niveau) 

...

Ja (NIST)

...

Ja (NIST)*

...

Ja (NSIS)

...

PID

...

Nej

...

Ja

...

Nej

...

CPR

...

Ja

...

Nej

...

Ja

...

Common Name (CN)

...

Nej

...

Nej (per 14/6)

...

Nej

...

Audience/scope

...

’SOSI-STS’

...

’NL STS’

...

’SOSI-STS’

Claims og valideringer for veksling til IDWS tokens (Bst2Idws og JWT2Idws)

I forhold til berigelse af det udstedte IDWS token er der mulighed for at medsende følgende claims til:

  • dk:gov:saml:attribute:CprNumberIdentifier: Obligatorisk (for bst2idws) angivelse af brugerens CPR nummer.
  • dk:healthcare:saml:attribute:OnBehalfOf: Optionel angivelse af et CPR nummer på en anden borger, som man ønsker at agere udfra fuldmagtstildelinger som.

Udover claims, skal der i forespørgslen angives et audience (som beskriver hvilken service det udstedte IDWS token skal bruges til). I NSP sammenhæng opereres der med følgende audiences:

  • https://audience.nspop.dk/dds: Dokumentdelingsservicen
  • https://audience.nspop.dk/minspaerring: MinSpærring
  • https://audience.nspop.dk/minlog: MinLog2
  • https://fmk: FMK

I eksemplerne nedenfor vises der eksempler på vekslinger af bootstraptoken til Idws og JWT til Idws. I eksemplet med bootstraptoken er der ydermere vist eksempler på anvendelsen af claims til både CPR for den kaldende bruger samt fuldmagt.

Service Endpoints

Afhængig af miljø udstilles tjenesten på:

http://<sts-host>:<port>/sts/services/Bst2Idws

http://<sts-host>:<port>/sts/services/JWT2Idws
http://<sts-host>:<port>/sts/services/JWT2OIOSaml

Eksempler på requests

I det følgende gives eksempler på følgende typer af requests:

  • Omveksling af borger bootstrap token til IDWS token (med angivelse af anden borgers CPR nummer for fuldmagtstildelinger)
  • Omveksling af borger JWT til IDWS token: Mangler for nuværende
  • Omveksling af borger JWT til OIO Saml Token: Mangler for nuværende

Eksempel: Omveksling af borger bootstrap token til IDWS token

I dette eksempel vises eksempel på request til servicen Bst2IDWS. Bemærk både claim '

*Optionel

OIO2BST og OIO3BST modtages i krypteret form. Bst2Idws servicen forsøger at dekryptere med krypteringsnøglerne i konfigurationstabellen.

Claims og valideringer for veksling til IDWS tokens

I forhold til berigelse af det udstedte IDWS token er der mulighed for at medsende følgende claims til:

dk:gov:saml:attribute:CprNumberIdentifier

...

  • Dette kan valideres af STS vha OCES service til validering af PID-CPR (PID står i bootstraptokenet).
  • For OIO2BST og OIO3BST, valideres op imod CPR i tokenet.

' i forhold til borgerens eget CPR nummer med claims i forhold til anden borgers CPR nummer.

Code Block
languagexml
title(Borgeromveksling) BST2IDWS Request til STS
collapsetrue
<?xml version="1.0" encoding="UTF-8"?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:wsa="http://www.w3.org/2005/08/addressing" xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wst="http://docs.oasis-open.org/ws-sx/ws-trust/200512" xmlns:wst14="http://docs.oasis-open.org/ws-sx/ws-trust/200802" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">
  <soapenv:Header>
    <wsa:Action wsu:Id="action">http://docs.oasis-open.org/ws-sx/ws-trust/200512/RST/Issue</wsa:Action>
    <wsa:MessageID wsu:Id="messageID">urn:uuid:3b222db7-5922-477c-b815-4ea35cba6574</wsa:MessageID>
    <wsse:Security mustUnderstand="1" wsu:Id="security">
      <wsu:Timestamp wsu:Id="ts">
        <wsu:Created>2020-12-07T09:04:30Z</wsu:Created>
      </wsu:Timestamp>
      <ds:Signature>
        <ds:SignedInfo>
          <ds:CanonicalizationMethod

...

  • Valideres vha fuldmagtsservice.

Udover claims, skal der i forespørgslen angives et audience (som beskriver hvilken service det udstedte IDWS token skal bruges til). I NSP sammenhæng opereres der med følgende audiences:

  • https://audience.nspop.dk/dds: Dokumentdelingsservicen
  • https://audience.nspop.dk/minspaerring: MinSpærring
  • https://audience.nspop.dk/minlog: MinLog2
  • https://fmk: FMK

I eksemplerne nedenfor vises der eksempler på vekslinger af bootstraptoken til Idws og JWT til Idws. I eksemplet med bootstraptoken er der ydermere vist eksempler på anvendelsen af claims til både CPR for den kaldende bruger samt fuldmagt.

Service Endpoints

Afhængig af miljø udstilles tjenesten på:

...

http://<sts-host>:<port>/sts/services/Bst2Idws

...

Eksempler på requests

I det følgende gives eksempler på følgende typer af requests:

  • Omveksling af borger bootstrap token (OIO2BST-LEGACY) til IDWS token (med angivelse af anden borgers CPR nummer for fuldmagtstildelinger)
    • OIO2BST assertion
    • OIO3BST assertion
  • Omveksling af borger JWT til IDWS token: Mangler for nuværende
  • Omveksling af borger JWT til OIO Saml Token: Mangler for nuværende

Eksempel: Omveksling af borger bootstrap token til IDWS token

I dette eksempel vises eksempel på request til servicen Bst2IDWS med en OIO2BST-LEGACY token. Bemærk både claim 'dk:gov:saml:attribute:CprNumberIdentifier' i forhold til borgerens eget CPR nummer med claims i forhold til anden borgers CPR nummer.

Code Block
languagexml
title(Borgeromveksling) BST2IDWS Request til STS
collapsetrue
<?xml version="1.0" encoding="UTF-8"?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:auth="http://docs.oasis-open.org/wsfed/authorization/200706" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:wsa="http://www.w3.org/2005/08/addressing" xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wst="http://docs.oasis-open.org/ws-sx/ws-trust/200512" xmlns:wst14="http://docs.oasis-open.org/ws-sx/ws-trust/200802" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">
  <soapenv:Header>
    <wsa:Action wsu:Id="action">http://docs.oasis-open.org/ws-sx/ws-trust/200512/RST/Issue</wsa:Action>
    <wsa:MessageID wsu:Id="messageID">urn:uuid:3b222db7-5922-477c-b815-4ea35cba6574</wsa:MessageID>
    <wsse:Security mustUnderstand="1" wsu:Id="security">
      <wsu:Timestamp wsu:Id="ts">
        <wsu:Created>2020-12-07T09:04:30Z</wsu:Created>
      </wsu:Timestamp>
      <ds:Signature>
        <ds:SignedInfo>
          <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
          <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
          <ds:Reference URI="#messageID">
            <ds:Transforms>
              <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>qy1OEXC66wBsvGKipiai5kbgtVU=</ds:DigestValue>
          </ds:Reference>
          <ds:Reference URI="#action">
            <ds:Transforms>
              <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>3cXAhlhZH22NiSh7AttxKxBap7Q=</ds:DigestValue>
          </ds:Reference>
          <ds:Reference URI="#ts">
            <ds:Transforms>
              <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>7U5J5GxULihSf9aMnTKZIBML9Rc=</ds:DigestValue>
          </ds:Reference>
          <ds:Reference URI="#body">
            <ds:Transforms>
              <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>pQiXI/9WJDEelRO2N9GJiUop5lE=</ds:DigestValue>
          </ds:Reference>
        </ds:SignedInfo>
        <ds:SignatureValue>WBwK3D7bMq8Dm6ns6eJmIPICAoa92+fRWGzoKbDcKwSNkdTlRBBnw3okSHPDlvQ7P5cuKYCLfvgYG+/705aYDUQiyL7HexTJvBKMW+TR/fkvGeqB/mQcOVypaV7wYfS7mY0eZUuTWFLf6RGxEa3OkqD7r+HT9lqsdFDZbjxpUkBBpsWwMH1OOr1u5p+cY8thwCT4h38hDOupU3NsGz36nvlODqke1DtOAaiNeteN3rLDDf3FEIl3zqfiVix/vlrZee9mK/RgFdgIC9OFVkqQhYAWlGTNmcGKTjZ0ED07qtZVi5uGsMortCtIchr0KnW6uo+yBc7zdeO4aYb0ItM78g==</ds:SignatureValue>
        <ds:KeyInfo>
          <ds:X509Data>
            <ds:X509Certificate>MIIGNDCCBRygAwIBAgIEXOg9yTANBgkqhkiG9w0BAQsFADBJMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTAeFw0yMDAyMTMxMzQ3NTdaFw0yMzAyMTMxMzQzMzBaMIGeMQswCQYDVQQGEwJESzEuMCwGA1UECgwlU3VuZGhlZHNkYXRhc3R5cmVsc2VuIC8vIENWUjozMzI1Nzg3MjFfMCAGA1UEBRMZQ1ZSOjMzMjU3ODcyLUZJRDo3OTY4MDA0NTA7BgNVBAMMNFRFU1Qgd2hpdGVsaXN0ZWQgU1AgU09TSSBhbGlhcyAoZnVua3Rpb25zY2VydGlmaWthdCkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCNWtWKpMlLgD5Er0SgRjNCKXlwU39x3DTPvqE/r09j96B+pwbzHjhnbV5HPwCNzoeUolcvnPmJrsOucIHsoKebPgfLEnhfjWnl0Z8ivPy/3iQfHyhJoB3shBcfLwH+FwZzEqw3hsabflVJHTq+9u2bLes9UM7r2Hy0mlynux28nFKB8dqkYVS1MjAid2cID4vbbavlFO+N+BSIt8M+MA8A1FVwhUEc/vyD+Ha8Alo3nYLZV9SqYlzeeGR+umiyQ7lhVOzv2CO2ULBSpX28mxGJ4N8CmCUrZgbSnPwkw3Mkq93bzMRUB4X9Bu/hWIpQZooKDM6wxE8dYn1yrAliw+ujAgMBAAGjggLMMIICyDAOBgNVHQ8BAf8EBAMCA7gwgZcGCCsGAQUFBwEBBIGKMIGHMDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9yZXNwb25kZXIwRwYIKwYBBQUHMAKGO2h0dHA6Ly9mLmFpYS5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MzQtY2EuY2VyMIIBIAYDVR0gBIIBFzCCARMwggEPBg0rBgEEAYH0UQIEBgQDMIH9MC8GCCsGAQUFBwIBFiNodHRwOi8vd3d3LnRydXN0MjQwOC5jb20vcmVwb3NpdG9yeTCByQYIKwYBBQUHAgIwgbwwDBYFRGFuSUQwAwIBARqBq0RhbklEIHRlc3QgY2VydGlmaWthdGVyIGZyYSBkZW5uZSBDQSB1ZHN0ZWRlcyB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLiBEYW5JRCB0ZXN0IGNlcnRpZmljYXRlcyBmcm9tIHRoaXMgQ0EgYXJlIGlzc3VlZCB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLjCBrAYDVR0fBIGkMIGhMDygOqA4hjZodHRwOi8vY3JsLnN5c3RlbXRlc3QzNC50cnVzdDI0MDguY29tL3N5c3RlbXRlc3QzNC5jcmwwYaBfoF2kWzBZMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTEOMAwGA1UEAwwFQ1JMMTEwHwYDVR0jBBgwFoAUzWxolzlyGaQ1q2Tq9BGjgYf4aTswHQYDVR0OBBYEFCe0e26va9zqyshyZoXec/52Pl5RMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBAGnG/H/WeWIPAbnuPMZ/p2sSulgesmt6N1fK5mupYlVmLQ/7fuBIh/ER8zK3ya6yuQBAfSwIYib8iFWm+VBPc+CeS8KE/z4LRZKs3tsFkyEPlee3KpyQ4BQEawwLZjb0ZHS6ghI846SFOy+nYV8HpLvws5/vTNlGaRbBlrDVFzL/ZGois0EJe6wd3xnglwEIKjCxv30zzAnCOrmEzGIaojm07F7rnpQkaCmGNDfsSWl6Mi8SZ8jhFZHdybG9mjr6BXc1wJl2C6hQVuo7wvaIhVgJpV5BkG61mcCBniZhGr7uCJyjQ1vheKDEDle4IIzyVajjM+x5F3BWb6JQxujEHOU=</ds:X509Certificate>
          </ds:X509Data>
        </ds:KeyInfo>
      </ds:Signature>
    </wsse:Security>
  </soapenv:Header>
  <soapenv:Body wsu:Id="body">
    <wst:RequestSecurityToken Context="urn:uuid:b501bee1-e6ef-4bda-9877-ce43d8637354">
      <wst:TokenType>http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0</wst:TokenType>
      <wst:RequestType>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Issue</wst:RequestType>
      <wst14:ActAs>
        <saml:Assertion xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" ID="_17433b24-cff4-4e22-ae47-4eefa07664a7" IssueInstant="2020-12-07T09:04:30Z" Version="2.0">
          <saml:Issuer>TEST trusted IdP</saml:Issuer>
          <ds:Signature Id="OCESSignature">
            <ds:SignedInfo>
              <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
              <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
              <ds:Reference URI="#_17433b24-cff4-4e22-ae47-4eefa07664a7">
                <ds:Transforms>
                  <ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                  <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                </ds:Transforms>
                <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
                <ds:DigestValue>4jgrBp2Qz+1jWqwv4EPDwvnoeOU=</ds:DigestValue>
              </ds:Reference>
            </ds:SignedInfo>
            <ds:SignatureValue>P0SXvO1fqVHbZIe/tcnlU7ppFHzxeb23F3YTdVjBR6U6U5xPKfn8NVaTYSJsqh6OGuxAXBrnAAYAd5wyP5E6Z8R62Q2z9Mog9qk+EM95kGfbqvJsAEQFDp6DEpAVyasKXpVdzqQv5b5/J2fG2X7ZHDUGeiIEHq9Cp/EWeFToOcEvx13eMU7MX2jhqdnc+aEGqjVHPsPrgSSy7z3zyg+5PQ476KmfuWxdKgxoKFtK1eMjbTk4bY1aEhDDQTcZNTgmg4qQVbOmMzRi3AWTl++HaMC1g8dXpuzNKWYnVc91a+vIRxghg3j6bzWDS+gET0vSyRAvlcFBl34/PdQlik8CCA==</ds:SignatureValue>
            <ds:KeyInfo>
              <ds:X509Data>
                <ds:X509Certificate>MIIGMTCCBRmgAwIBAgIEXOg9zDANBgkqhkiG9w0BAQsFADBJMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTAeFw0yMDAyMTMxMzUwNDhaFw0yMzAyMTMxMzQ5NDFaMIGbMQswCQYDVQQGEwJESzEuMCwGA1UECgwlU3VuZGhlZHNkYXRhc3R5cmVsc2VuIC8vIENWUjozMzI1Nzg3MjFcMCAGA1UEBRMZQ1ZSOjMzMjU3ODcyLUZJRDoyMjI0OTczMjA4BgNVBAMMMVRFU1QgdHJ1c3RlZCBJZFAgU09TSSBhbGlhcyAoZnVua3Rpb25zY2VydGlmaWthdCkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCxgR6YyL1auIQJtCyq6HpB3y5FtrFWigZsmbOXvhcxrmvjhqahlfvke2Vub5AfCPslTsbSgwg9sqhU7Hq2T96QZtLqa+UZP3PVzIqyfXwgXpOFvb2UGbXwQ5SPtSAhoo8z6cFPkBUdIGxL99DV7GPWw4kIk9ynV2YY/XulY049wePaHQFLuW4A5F+Nl6coXFpqn55fG0XNRxOPZUX3DUlnKT7aJKU4xA/1gIm+v4DbbIKN97SV1msXfQq+9Fdpz07dTQEINa9JzmBN1zPkT7hJEOHttqhtFwSxJhMA5V5k0ZbVj1b6WRgJZKUEtGSNOmyZUlcmwUgzz4PwGuMc85PHAgMBAAGjggLMMIICyDAOBgNVHQ8BAf8EBAMCA7gwgZcGCCsGAQUFBwEBBIGKMIGHMDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9yZXNwb25kZXIwRwYIKwYBBQUHMAKGO2h0dHA6Ly9mLmFpYS5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MzQtY2EuY2VyMIIBIAYDVR0gBIIBFzCCARMwggEPBg0rBgEEAYH0UQIEBgQDMIH9MC8GCCsGAQUFBwIBFiNodHRwOi8vd3d3LnRydXN0MjQwOC5jb20vcmVwb3NpdG9yeTCByQYIKwYBBQUHAgIwgbwwDBYFRGFuSUQwAwIBARqBq0RhbklEIHRlc3QgY2VydGlmaWthdGVyIGZyYSBkZW5uZSBDQSB1ZHN0ZWRlcyB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLiBEYW5JRCB0ZXN0IGNlcnRpZmljYXRlcyBmcm9tIHRoaXMgQ0EgYXJlIGlzc3VlZCB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLjCBrAYDVR0fBIGkMIGhMDygOqA4hjZodHRwOi8vY3JsLnN5c3RlbXRlc3QzNC50cnVzdDI0MDguY29tL3N5c3RlbXRlc3QzNC5jcmwwYaBfoF2kWzBZMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTEOMAwGA1UEAwwFQ1JMMTEwHwYDVR0jBBgwFoAUzWxolzlyGaQ1q2Tq9BGjgYf4aTswHQYDVR0OBBYEFN7fNS/56t+ZyVIxR6T6W0S7yS5JMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBAANWrGs4jCmcvQX34e5h29UhxVegt8Jg02WWBzGB9/kH5YOVnSEp7CCIc4Qut0+C0QlvcDvCre12fOsII5ZlYjKIOXwXzjO2lsNmPKRom3+2syL5aWRQLsh3viVIvVLn4E5bZiEEX8P5KkXI8Exh9OlYEro5KpVyF8Bi2r7uJDmglCYl+BSc/zozgegXJ9KP4l+08mKVWPwwfw5qwp13PWbNNOVPpdIMVzN0YQCTUvPRfNqVfx265+zmx96HF2PvHCzTL95mKfWMs+SZEVpfek4Xl9priAOI6hhmcAZR1wwAklmI7KC4I3m0gFzUOPcZycXNg3G02gXvcmlwMcrdOek=</ds:X509Certificate>
              </ds:X509Data>
            </ds:KeyInfo>
          </ds:Signature>
          <saml:Subject>
            <saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName">C=DK,O=Ingen organisatorisk tilknytning,CN=Lars Larsen,Serial=PID:9208-2002-2-514358910503</saml:NameID>
            <saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
              <saml:SubjectConfirmationData NotOnOrAfter="2020-12-07T09:09:29Z" Recipient="https://sosi"/>
            </saml:SubjectConfirmation>
          </saml:Subject>
          <saml:Conditions NotBefore="2020-12-07T09:04:24Z" NotOnOrAfter="2020-12-07T09:09:29Z">
            <saml:AudienceRestriction>
              <saml:Audience/>
            </saml:AudienceRestriction>
          </saml:Conditions>
        </saml:Assertion>
      </wst14:ActAs>
      <wsp:AppliesTo>
        <wsa:EndpointReference>
          <wsa:Address>https://fmk</wsa:Address>
        </wsa:EndpointReference>
      </wsp:AppliesTo>
      <wst:Claims Dialect="http://docs.oasis-open.org/wsfed/authorization/200706/authclaims">
        <auth:ClaimType Uri="dk:gov:saml:attribute:CprNumberIdentifier">
          <auth:Value>0501792275</auth:Value>
        </auth:ClaimType>
        <auth:ClaimType Uri="dk:healthcare:saml:attribute:OnBehalfOf">
          <auth:Value>urn:dk:healthcare:saml:actThroughProcurationBy:cprNumberIdentifier:0101603040</auth:Value>
        </auth:ClaimType>
      </wst:Claims>
    </wst:RequestSecurityToken>
  </soapenv:Body>
</soapenv:Envelope>

Svaret fra STS ser således ud:

Code Block
languagexml
title(Borgeromveksling) BST2IDWS Response fra STS
collapsetrue
<?xml version="1.0" encoding="UTF-8"?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:wsa="http://www.w3.org/2005/08/addressing" xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wst="http://docs.oasis-open.org/ws-sx/ws-trust/200512" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">
  <soapenv:Header>
    <wsa:Action wsu:Id="action">http://docs.oasis-open.org/ws-sx/ws-trust/200512/RST/Issue</wsa:Action>
    <wsa:MessageID wsu:Id="messageID">urn:uuid:bde6ee0c-06a9-4dd7-9ae0-3bf29b6280e3</wsa:MessageID>
    <wsa:RelatesTo wsu:Id="relatesTo">urn:uuid:3b222db7-5922-477c-b815-4ea35cba6574</wsa:RelatesTo>
    <wsse:Security mustUnderstand="1" wsu:Id="security">
      <wsu:Timestamp wsu:Id="ts">
        <wsu:Created>2020-12-07T09:06:39Z</wsu:Created>
      </wsu:Timestamp>
      <ds:Signature>
        <ds:SignedInfo>
          <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
          <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>0101603040
          <ds:Reference URI="#messageID">
            <ds:Transforms>
              <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>5YUEr9PKYYu2iyvY0XhKxHE6NFk=</ds:DigestValue>
          </ds:Reference>
          <ds:Reference URI="#action">
            <ds:Transforms>
              <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethodSignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1xmldsig#rsa-sha1"/>
            <ds:DigestValue>3cXAhlhZH22NiSh7AttxKxBap7Q=</ds:DigestValue>
          </ds:Reference>
          <ds:Reference URI="#relatesTo#messageID">
            <ds:Transforms>
              <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>Oo+c5AT3Gky7Q2+jevrnjtKkbhIDigestValue>qy1OEXC66wBsvGKipiai5kbgtVU=</ds:DigestValue>
          </ds:Reference>
          <ds:Reference URI="#ts#action">
            <ds:Transforms>
              <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>/DWD2fll+qjDeFmjYb4i4TTQcJE:DigestValue>3cXAhlhZH22NiSh7AttxKxBap7Q=</ds:DigestValue>
          </ds:Reference>
          <ds:Reference URI="#body#ts">
            <ds:Transforms>
              <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>TOdMnbhE5vN9Q9/01qfrGKKKJP0DigestValue>7U5J5GxULihSf9aMnTKZIBML9Rc=</ds:DigestValue>
          </ds:Reference>
        </ds:SignedInfo>
        <ds:SignatureValue>Or2nuZl8pyU4t6h90FP50MwghnBaQo0hGr/uOrDxkQo3lUXXxa5P2S4Vs5I8NzvgHGx22Piq19D2S7Z9NVMxPgRQC+kyhxIUehYFWv4ZlEX6L8Qn0N2T+44UA9pUZgJYH4BbUF0fXY79KZAiD5JGa6sc0ZKZTnO5eusR6ef6+m1jTGDOXEjH2J+qQ6i23VJPIYB0yxNU53n79d05rknhipWCQYfthE6eNKyfMy1jvkm1Wyux1bZUhwL+1WOZIbXTN7LbgN1I0x1IxFFe6yJ6ccIiSOoSzyEp00sVcTVoBLzfF2GmYVFijJo3kjjOXwnDTjxXCPCUE22ND4rjrmb2Zg==</ds:SignatureValue>Reference URI="#body">
        <ds:KeyInfo>
          <ds:X509Data>Transforms>
              <ds:Transform Algorithm="http:X509Certificate>MIIGKjCCBRKgAwIBAgIEW6uMBTANBgkqhkiG9w0BAQsFADBIMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSUwIwYDVQQDDBxUUlVTVDI0MDggU3lzdGVtdGVzdCBYWElJIENBMB4XDTE5MDQzMDA5MDcxN1oXDTIyMDQzMDA5MDYzOFowgZQxCzAJBgNVBAYTAkRLMS4wLAYDVQQKDCVTdW5kaGVkc2RhdGFzdHlyZWxzZW4gLy8gQ1ZSOjMzMjU3ODcyMVUwIAYDVQQFExlDVlI6MzMyNTc4NzItRklEOjE4OTExODYxMDEGA1UEAwwqU09TSSBUZXN0IEZlZGVyYXRpb24gKGZ1bmt0aW9uc2NlcnRpZmlrYXQpMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyo57h9E/hM5gimxaDgHB0MLcgVfXGJbQh/8OC1vTdDsCUIzIwRd5lJE+ado8urHF7UmKubFZzfCPduoRv9b3TkNVKaixiHUMtP4egbL8vcgyalk28cNQdUk8f34mg8atgvd45EnIKz2iB+yjs5guJPDBg2OFSbP0r53NU8fVTq3aLtDpDVnkxsyjNQ7HOFtzavyMnKx0vDgafEvrUR3WTSLCGju4aUIg3ThgrWXA7i3lPIAXdV8mQmlY3wn/kIBiyIotmF98UsEket/sxpJNkJ6R6AUpxnGApCDP1Fw2BgxAQWWrtD/c5IoIZwGWNfLgpJEzfhnuIZJ7Bfs9RmHFdQIDAQABo4ICzTCCAskwDgYDVR0PAQH/BAQDAgO4MIGXBggrBgEFBQcBAQSBijCBhzA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc3lzdGVtdGVzdDIyLnRydXN0MjQwOC5jb20vcmVzcG9uZGVyMEcGCCsGAQUFBzAChjtodHRwOi8vZi5haWEuc3lzdGVtdGVzdDIyLnRydXN0MjQwOC5jb20vc3lzdGVtdGVzdDIyLWNhLmNlcjCCASAGA1UdIASCARcwggETMIIBDwYNKwYBBAGB9FECBAYEAjCB/TAvBggrBgEFBQcCARYjaHR0cDovL3d3dy50cnVzdDI0MDguY29tL3JlcG9zaXRvcnkwgckGCCsGAQUFBwICMIG8MAwWBURhbklEMAMCAQEagatEYW5JRCB0ZXN0IGNlcnRpZmlrYXRlciBmcmEgZGVubmUgQ0EgdWRzdGVkZXMgdW5kZXIgT0lEIDEuMy42LjEuNC4xLjMxMzEzLjIuNC42LjQuMi4gRGFuSUQgdGVzdCBjZXJ0aWZpY2F0ZXMgZnJvbSB0aGlzIENBIGFyZSBpc3N1ZWQgdW5kZXIgT0lEIDEuMy42LjEuNC4xLjMxMzEzLjIuNC42LjQuMi4wga0GA1UdHwSBpTCBojA9oDugOYY3aHR0cDovL2NybC5zeXN0ZW10ZXN0MjIudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MjIxLmNybDBhoF+gXaRbMFkxCzAJBgNVBAYTAkRLMRIwEAYDVQQKDAlUUlVTVDI0MDgxJTAjBgNVBAMMHFRSVVNUMjQwOCBTeXN0ZW10ZXN0IFhYSUkgQ0ExDzANBgNVBAMMBkNSTDE0MjAfBgNVHSMEGDAWgBSrqAFEGbCzQ5na+nzM0gAYA+c8vzAdBgNVHQ4EFgQUGYAVKKL17LHyVGSErL26MBNadTQwCQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAQEAjHMO4sWEf8M25WHczBTJYtMitn1wLOqE6raeM6oYyw6R/4FImpOzF6bxBlfNnhhR0vJSXMWTqL/onCyy4gCs9eLglRHZ9BC8a9fmirrguNpOWlR8NAf5GRwOqCyTnkTAfUD1fp0RzVo8TvAd73WiGeUTzTiAVf7OgZFnRIYkcALXLjNs6AwELWSh+bC/gGuQcHUDd8YGSzgKS6w2qz3fIASrykxzlYjeusks58CereC6WfvN0I+GGlL9fIgjpzh7JEELME7r9QJLL9NSrmlRKfhM8gzuE6Vm4vGzmSsnNJxGMf1vTzEve4lXI8pnOtHMTtNl5zw4jCJFakRqcWm3FQ==</ds:X509Certificate>
/www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:X509Data>Transforms>
             </ds:KeyInfo>
<ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
        </ds:Signature>
    <ds:DigestValue>pQiXI/9WJDEelRO2N9GJiUop5lE=</wsseds:Security>DigestValue>
   </soapenv:Header>
  <soapenv:Body wsu:Id="body">
    <wst</ds:RequestSecurityTokenResponseCollection>Reference>
      <wst:RequestSecurityTokenResponse Context="urn:uuid:b501bee1-e6ef-4bda-9877-ce43d8637354">  </ds:SignedInfo>
        <wst:TokenType>http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0</wst:TokenType>
<ds:SignatureValue>WBwK3D7bMq8Dm6ns6eJmIPICAoa92+fRWGzoKbDcKwSNkdTlRBBnw3okSHPDlvQ7P5cuKYCLfvgYG+/705aYDUQiyL7HexTJvBKMW+TR/fkvGeqB/mQcOVypaV7wYfS7mY0eZUuTWFLf6RGxEa3OkqD7r+HT9lqsdFDZbjxpUkBBpsWwMH1OOr1u5p+cY8thwCT4h38hDOupU3NsGz36nvlODqke1DtOAaiNeteN3rLDDf3FEIl3zqfiVix/vlrZee9mK/RgFdgIC9OFVkqQhYAWlGTNmcGKTjZ0ED07qtZVi5uGsMortCtIchr0KnW6uo+yBc7zdeO4aYb0ItM78g==</ds:SignatureValue>
        <ds:KeyInfo>
         <wst <ds:RequestedSecurityToken>X509Data>
           <saml:Assertion xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" ID="_fa311122-026e-4049-8ddf-cdbd84304d7c" IssueInstant="2020-12-07T09:06:39Z" Version="2.0">
    <ds:X509Certificate>MIIGNDCCBRygAwIBAgIEXOg9yTANBgkqhkiG9w0BAQsFADBJMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTAeFw0yMDAyMTMxMzQ3NTdaFw0yMzAyMTMxMzQzMzBaMIGeMQswCQYDVQQGEwJESzEuMCwGA1UECgwlU3VuZGhlZHNkYXRhc3R5cmVsc2VuIC8vIENWUjozMzI1Nzg3MjFfMCAGA1UEBRMZQ1ZSOjMzMjU3ODcyLUZJRDo3OTY4MDA0NTA7BgNVBAMMNFRFU1Qgd2hpdGVsaXN0ZWQgU1AgU09TSSBhbGlhcyAoZnVua3Rpb25zY2VydGlmaWthdCkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCNWtWKpMlLgD5Er0SgRjNCKXlwU39x3DTPvqE/r09j96B+pwbzHjhnbV5HPwCNzoeUolcvnPmJrsOucIHsoKebPgfLEnhfjWnl0Z8ivPy/3iQfHyhJoB3shBcfLwH+FwZzEqw3hsabflVJHTq+9u2bLes9UM7r2Hy0mlynux28nFKB8dqkYVS1MjAid2cID4vbbavlFO+N+BSIt8M+MA8A1FVwhUEc/vyD+Ha8Alo3nYLZV9SqYlzeeGR+umiyQ7lhVOzv2CO2ULBSpX28mxGJ4N8CmCUrZgbSnPwkw3Mkq93bzMRUB4X9Bu/hWIpQZooKDM6wxE8dYn1yrAliw+ujAgMBAAGjggLMMIICyDAOBgNVHQ8BAf8EBAMCA7gwgZcGCCsGAQUFBwEBBIGKMIGHMDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9yZXNwb25kZXIwRwYIKwYBBQUHMAKGO2h0dHA6Ly9mLmFpYS5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MzQtY2EuY2VyMIIBIAYDVR0gBIIBFzCCARMwggEPBg0rBgEEAYH0UQIEBgQDMIH9MC8GCCsGAQUFBwIBFiNodHRwOi8vd3d3LnRydXN0MjQwOC5jb20vcmVwb3NpdG9yeTCByQYIKwYBBQUHAgIwgbwwDBYFRGFuSUQwAwIBARqBq0RhbklEIHRlc3QgY2VydGlmaWthdGVyIGZyYSBkZW5uZSBDQSB1ZHN0ZWRlcyB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLiBEYW5JRCB0ZXN0IGNlcnRpZmljYXRlcyBmcm9tIHRoaXMgQ0EgYXJlIGlzc3VlZCB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLjCBrAYDVR0fBIGkMIGhMDygOqA4hjZodHRwOi8vY3JsLnN5c3RlbXRlc3QzNC50cnVzdDI0MDguY29tL3N5c3RlbXRlc3QzNC5jcmwwYaBfoF2kWzBZMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTEOMAwGA1UEAwwFQ1JMMTEwHwYDVR0jBBgwFoAUzWxolzlyGaQ1q2Tq9BGjgYf4aTswHQYDVR0OBBYEFCe0e26va9zqyshyZoXec/52Pl5RMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBAGnG/H/WeWIPAbnuPMZ/p2sSulgesmt6N1fK5mupYlVmLQ/7fuBIh/ER8zK3ya6yuQBAfSwIYib8iFWm+VBPc+CeS8KE/z4LRZKs3tsFkyEPlee3KpyQ4BQEawwLZjb0ZHS6ghI846SFOy+nYV8HpLvws5/vTNlGaRbBlrDVFzL/ZGois0EJe6wd3xnglwEIKjCxv30zzAnCOrmEzGIaojm07F7rnpQkaCmGNDfsSWl6Mi8SZ8jhFZHdybG9mjr6BXc1wJl2C6hQVuo7wvaIhVgJpV5BkG61mcCBniZhGr7uCJyjQ1vheKDEDle4IIzyVajjM+x5F3BWb6JQxujEHOU=</ds:X509Certificate>
          </ds:X509Data>
        <saml:Issuer>TEST2-NSP-STS</saml:Issuer>
</ds:KeyInfo>
      </ds:Signature>
    </wsse:Security>
  </soapenv:Header>
  <ds<soapenv:SignatureBody wsu:Id="OCESSignaturebody">
              <ds:SignedInfo><wst:RequestSecurityToken Context="urn:uuid:b501bee1-e6ef-4bda-9877-ce43d8637354">
                <ds:CanonicalizationMethod Algorithm="http<wst:TokenType>http://wwwdocs.w3oasis-open.org/2001/10/xml-exc-c14n#"/>
         wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0</wst:TokenType>
       <ds:SignatureMethod Algorithm="http<wst:RequestType>http://wwwdocs.w3oasis-open.org/2000/09/xmldsig#rsa-sha1"/>/ws-sx/ws-trust/200512/Issue</wst:RequestType>
      <wst14:ActAs>
        <saml:Assertion  <ds:Reference URI="#_fa311122-026e-4049-8ddf-cdbd84304d7c">
                  <ds:Transforms>
                    <ds:Transform Algorithmxmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ds="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                    <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/xmldsig#" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" ID="_17433b24-cff4-4e22-ae47-4eefa07664a7" IssueInstant="2020-12-07T09:04:30Z" Version="2.0">
          <saml:Issuer>TEST        </ds:Transforms>
  trusted IdP</saml:Issuer>
                <ds:DigestMethodSignature AlgorithmId="http://www.w3.org/2000/09/xmldsig#sha1"/>
      OCESSignature">
            <ds:DigestValue>GOIAqcYUFLnazqyu7B4AL2vpV5o=</ds:DigestValue>:SignedInfo>
                </ds:Reference><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
              </ds:SignedInfo> <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
              <ds:SignatureValue>sM1Nl1ehU0k4WwrNyIJaRn/VDH9JbriFlDKaRzd/iwYtiF6rCA+NQMMHYqAjjzPewjamKuueIqx7MTt0ElEN3mUcdBaSqaohdhmTTM9U2IB76B+sWNxpGdCXQ8N1lYjVqBYkCn6uAvzG89fADpTNkBct8ekWuj/UT06h/O8KLxybhK7I0HNOWkJ45BAhOIJTOc7Vg4qyIk3PJIh+8TzpyUY9L2WuBg8YKzgAd+8uCKRFn223ePRL6GtRlJJqsXm/x/82CNj6lGHdCFXsPcZrrYvKCmZu8FSFEqQrLjyE/ULnbTQVfe+gAPhIzAh01n1SvlWoQ0omyzjiWCAA2Sketw==</ds:SignatureValue>
Reference URI="#_17433b24-cff4-4e22-ae47-4eefa07664a7">
                <ds:KeyInfo>Transforms>
                  <ds:X509Data>Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                  <ds:X509Certificate>MIIGKjCCBRKgAwIBAgIEW6uMBTANBgkqhkiG9w0BAQsFADBIMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSUwIwYDVQQDDBxUUlVTVDI0MDggU3lzdGVtdGVzdCBYWElJIENBMB4XDTE5MDQzMDA5MDcxN1oXDTIyMDQzMDA5MDYzOFowgZQxCzAJBgNVBAYTAkRLMS4wLAYDVQQKDCVTdW5kaGVkc2RhdGFzdHlyZWxzZW4gLy8gQ1ZSOjMzMjU3ODcyMVUwIAYDVQQFExlDVlI6MzMyNTc4NzItRklEOjE4OTExODYxMDEGA1UEAwwqU09TSSBUZXN0IEZlZGVyYXRpb24gKGZ1bmt0aW9uc2NlcnRpZmlrYXQpMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyo57h9E/hM5gimxaDgHB0MLcgVfXGJbQh/8OC1vTdDsCUIzIwRd5lJE+ado8urHF7UmKubFZzfCPduoRv9b3TkNVKaixiHUMtP4egbL8vcgyalk28cNQdUk8f34mg8atgvd45EnIKz2iB+yjs5guJPDBg2OFSbP0r53NU8fVTq3aLtDpDVnkxsyjNQ7HOFtzavyMnKx0vDgafEvrUR3WTSLCGju4aUIg3ThgrWXA7i3lPIAXdV8mQmlY3wn/kIBiyIotmF98UsEket/sxpJNkJ6R6AUpxnGApCDP1Fw2BgxAQWWrtD/c5IoIZwGWNfLgpJEzfhnuIZJ7Bfs9RmHFdQIDAQABo4ICzTCCAskwDgYDVR0PAQH/BAQDAgO4MIGXBggrBgEFBQcBAQSBijCBhzA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc3lzdGVtdGVzdDIyLnRydXN0MjQwOC5jb20vcmVzcG9uZGVyMEcGCCsGAQUFBzAChjtodHRwOi8vZi5haWEuc3lzdGVtdGVzdDIyLnRydXN0MjQwOC5jb20vc3lzdGVtdGVzdDIyLWNhLmNlcjCCASAGA1UdIASCARcwggETMIIBDwYNKwYBBAGB9FECBAYEAjCB/TAvBggrBgEFBQcCARYjaHR0cDovL3d3dy50cnVzdDI0MDguY29tL3JlcG9zaXRvcnkwgckGCCsGAQUFBwICMIG8MAwWBURhbklEMAMCAQEagatEYW5JRCB0ZXN0IGNlcnRpZmlrYXRlciBmcmEgZGVubmUgQ0EgdWRzdGVkZXMgdW5kZXIgT0lEIDEuMy42LjEuNC4xLjMxMzEzLjIuNC42LjQuMi4gRGFuSUQgdGVzdCBjZXJ0aWZpY2F0ZXMgZnJvbSB0aGlzIENBIGFyZSBpc3N1ZWQgdW5kZXIgT0lEIDEuMy42LjEuNC4xLjMxMzEzLjIuNC42LjQuMi4wga0GA1UdHwSBpTCBojA9oDugOYY3aHR0cDovL2NybC5zeXN0ZW10ZXN0MjIudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MjIxLmNybDBhoF+gXaRbMFkxCzAJBgNVBAYTAkRLMRIwEAYDVQQKDAlUUlVTVDI0MDgxJTAjBgNVBAMMHFRSVVNUMjQwOCBTeXN0ZW10ZXN0IFhYSUkgQ0ExDzANBgNVBAMMBkNSTDE0MjAfBgNVHSMEGDAWgBSrqAFEGbCzQ5na+nzM0gAYA+c8vzAdBgNVHQ4EFgQUGYAVKKL17LHyVGSErL26MBNadTQwCQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAQEAjHMO4sWEf8M25WHczBTJYtMitn1wLOqE6raeM6oYyw6R/4FImpOzF6bxBlfNnhhR0vJSXMWTqL/onCyy4gCs9eLglRHZ9BC8a9fmirrguNpOWlR8NAf5GRwOqCyTnkTAfUD1fp0RzVo8TvAd73WiGeUTzTiAVf7OgZFnRIYkcALXLjNs6AwELWSh+bC/gGuQcHUDd8YGSzgKS6w2qz3fIASrykxzlYjeusks58CereC6WfvN0I+GGlL9fIgjpzh7JEELME7r9QJLL9NSrmlRKfhM8gzuE6Vm4vGzmSsnNJxGMf1vTzEve4lXI8pnOtHMTtNl5zw4jCJFakRqcWm3FQ==</ds:X509Certificate>Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                </ds:X509Data>Transforms>
               </ds:KeyInfo>
 <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
                <ds:DigestValue>4jgrBp2Qz+1jWqwv4EPDwvnoeOU=</ds:Signature>DigestValue>
            <saml:Subject>  </ds:Reference>
              <saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName">C=DK,O=Ingen organisatorisk tilknytning,CN=Lars Larsen,Serial=PID:9208-2002-2-514358910503</saml:NameID>
       </ds:SignedInfo>
            <ds:SignatureValue>P0SXvO1fqVHbZIe/tcnlU7ppFHzxeb23F3YTdVjBR6U6U5xPKfn8NVaTYSJsqh6OGuxAXBrnAAYAd5wyP5E6Z8R62Q2z9Mog9qk+EM95kGfbqvJsAEQFDp6DEpAVyasKXpVdzqQv5b5/J2fG2X7ZHDUGeiIEHq9Cp/EWeFToOcEvx13eMU7MX2jhqdnc+aEGqjVHPsPrgSSy7z3zyg+5PQ476KmfuWxdKgxoKFtK1eMjbTk4bY1aEhDDQTcZNTgmg4qQVbOmMzRi3AWTl++HaMC1g8dXpuzNKWYnVc91a+vIRxghg3j6bzWDS+gET0vSyRAvlcFBl34/PdQlik8CCA==</ds:SignatureValue>
           <saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:holder-of-key"> <ds:KeyInfo>
                <saml:SubjectConfirmationData NotOnOrAfter="2020-12-07T09:09:29Z" Recipient="https://fmk"><ds:X509Data>
                <ds:X509Certificate>MIIGMTCCBRmgAwIBAgIEXOg9zDANBgkqhkiG9w0BAQsFADBJMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTAeFw0yMDAyMTMxMzUwNDhaFw0yMzAyMTMxMzQ5NDFaMIGbMQswCQYDVQQGEwJESzEuMCwGA1UECgwlU3VuZGhlZHNkYXRhc3R5cmVsc2VuIC8vIENWUjozMzI1Nzg3MjFcMCAGA1UEBRMZQ1ZSOjMzMjU3ODcyLUZJRDoyMjI0OTczMjA4BgNVBAMMMVRFU1QgdHJ1c3RlZCBJZFAgU09TSSBhbGlhcyAoZnVua3Rpb25zY2VydGlmaWthdCkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCxgR6YyL1auIQJtCyq6HpB3y5FtrFWigZsmbOXvhcxrmvjhqahlfvke2Vub5AfCPslTsbSgwg9sqhU7Hq2T96QZtLqa+UZP3PVzIqyfXwgXpOFvb2UGbXwQ5SPtSAhoo8z6cFPkBUdIGxL99DV7GPWw4kIk9ynV2YY/XulY049wePaHQFLuW4A5F+Nl6coXFpqn55fG0XNRxOPZUX3DUlnKT7aJKU4xA/1gIm+v4DbbIKN97SV1msXfQq+9Fdpz07dTQEINa9JzmBN1zPkT7hJEOHttqhtFwSxJhMA5V5k0ZbVj1b6WRgJZKUEtGSNOmyZUlcmwUgzz4PwGuMc85PHAgMBAAGjggLMMIICyDAOBgNVHQ8BAf8EBAMCA7gwgZcGCCsGAQUFBwEBBIGKMIGHMDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9yZXNwb25kZXIwRwYIKwYBBQUHMAKGO2h0dHA6Ly9mLmFpYS5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MzQtY2EuY2VyMIIBIAYDVR0gBIIBFzCCARMwggEPBg0rBgEEAYH0UQIEBgQDMIH9MC8GCCsGAQUFBwIBFiNodHRwOi8vd3d3LnRydXN0MjQwOC5jb20vcmVwb3NpdG9yeTCByQYIKwYBBQUHAgIwgbwwDBYFRGFuSUQwAwIBARqBq0RhbklEIHRlc3QgY2VydGlmaWthdGVyIGZyYSBkZW5uZSBDQSB1ZHN0ZWRlcyB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLiBEYW5JRCB0ZXN0IGNlcnRpZmljYXRlcyBmcm9tIHRoaXMgQ0EgYXJlIGlzc3VlZCB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLjCBrAYDVR0fBIGkMIGhMDygOqA4hjZodHRwOi8vY3JsLnN5c3RlbXRlc3QzNC50cnVzdDI0MDguY29tL3N5c3RlbXRlc3QzNC5jcmwwYaBfoF2kWzBZMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTEOMAwGA1UEAwwFQ1JMMTEwHwYDVR0jBBgwFoAUzWxolzlyGaQ1q2Tq9BGjgYf4aTswHQYDVR0OBBYEFN7fNS/56t+ZyVIxR6T6W0S7yS5JMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBAANWrGs4jCmcvQX34e5h29UhxVegt8Jg02WWBzGB9/kH5YOVnSEp7CCIc4Qut0+C0QlvcDvCre12fOsII5ZlYjKIOXwXzjO2lsNmPKRom3+2syL5aWRQLsh3viVIvVLn4E5bZiEEX8P5KkXI8Exh9OlYEro5KpVyF8Bi2r7uJDmglCYl+BSc/zozgegXJ9KP4l+08mKVWPwwfw5qwp13PWbNNOVPpdIMVzN0YQCTUvPRfNqVfx265+zmx96HF2PvHCzTL95mKfWMs+SZEVpfek4Xl9priAOI6hhmcAZR1wwAklmI7KC4I3m0gFzUOPcZycXNg3G02gXvcmlwMcrdOek=</ds:X509Certificate>
               </ds:X509Data>
   <ds:KeyInfo>
          </ds:KeyInfo>
          <ds</ds:X509Data>Signature>
          <saml:Subject>
            <ds:X509Certificate>MIIGNDCCBRygAwIBAgIEXOg9yTANBgkqhkiG9w0BAQsFADBJMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTAeFw0yMDAyMTMxMzQ3NTdaFw0yMzAyMTMxMzQzMzBaMIGeMQswCQYDVQQGEwJESzEuMCwGA1UECgwlU3VuZGhlZHNkYXRhc3R5cmVsc2VuIC8vIENWUjozMzI1Nzg3MjFfMCAGA1UEBRMZQ1ZSOjMzMjU3ODcyLUZJRDo3OTY4MDA0NTA7BgNVBAMMNFRFU1Qgd2hpdGVsaXN0ZWQgU1AgU09TSSBhbGlhcyAoZnVua3Rpb25zY2VydGlmaWthdCkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCNWtWKpMlLgD5Er0SgRjNCKXlwU39x3DTPvqE/r09j96B+pwbzHjhnbV5HPwCNzoeUolcvnPmJrsOucIHsoKebPgfLEnhfjWnl0Z8ivPy/3iQfHyhJoB3shBcfLwH+FwZzEqw3hsabflVJHTq+9u2bLes9UM7r2Hy0mlynux28nFKB8dqkYVS1MjAid2cID4vbbavlFO+N+BSIt8M+MA8A1FVwhUEc/vyD+Ha8Alo3nYLZV9SqYlzeeGR+umiyQ7lhVOzv2CO2ULBSpX28mxGJ4N8CmCUrZgbSnPwkw3Mkq93bzMRUB4X9Bu/hWIpQZooKDM6wxE8dYn1yrAliw+ujAgMBAAGjggLMMIICyDAOBgNVHQ8BAf8EBAMCA7gwgZcGCCsGAQUFBwEBBIGKMIGHMDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9yZXNwb25kZXIwRwYIKwYBBQUHMAKGO2h0dHA6Ly9mLmFpYS5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MzQtY2EuY2VyMIIBIAYDVR0gBIIBFzCCARMwggEPBg0rBgEEAYH0UQIEBgQDMIH9MC8GCCsGAQUFBwIBFiNodHRwOi8vd3d3LnRydXN0MjQwOC5jb20vcmVwb3NpdG9yeTCByQYIKwYBBQUHAgIwgbwwDBYFRGFuSUQwAwIBARqBq0RhbklEIHRlc3QgY2VydGlmaWthdGVyIGZyYSBkZW5uZSBDQSB1ZHN0ZWRlcyB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLiBEYW5JRCB0ZXN0IGNlcnRpZmljYXRlcyBmcm9tIHRoaXMgQ0EgYXJlIGlzc3VlZCB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLjCBrAYDVR0fBIGkMIGhMDygOqA4hjZodHRwOi8vY3JsLnN5c3RlbXRlc3QzNC50cnVzdDI0MDguY29tL3N5c3RlbXRlc3QzNC5jcmwwYaBfoF2kWzBZMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTEOMAwGA1UEAwwFQ1JMMTEwHwYDVR0jBBgwFoAUzWxolzlyGaQ1q2Tq9BGjgYf4aTswHQYDVR0OBBYEFCe0e26va9zqyshyZoXec/52Pl5RMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBAGnG/H/WeWIPAbnuPMZ/p2sSulgesmt6N1fK5mupYlVmLQ/7fuBIh/ER8zK3ya6yuQBAfSwIYib8iFWm+VBPc+CeS8KE/z4LRZKs3tsFkyEPlee3KpyQ4BQEawwLZjb0ZHS6ghI846SFOy+nYV8HpLvws5/vTNlGaRbBlrDVFzL/ZGois0EJe6wd3xnglwEIKjCxv30zzAnCOrmEzGIaojm07F7rnpQkaCmGNDfsSWl6Mi8SZ8jhFZHdybG9mjr6BXc1wJl2C6hQVuo7wvaIhVgJpV5BkG61mcCBniZhGr7uCJyjQ1vheKDEDle4IIzyVajjM+x5F3BWb6JQxujEHOU=</ds:X509Certificate><saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName">C=DK,O=Ingen organisatorisk tilknytning,CN=Lars Larsen,Serial=PID:9208-2002-2-514358910503</saml:NameID>
                    </ds:X509Data><saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer">
              <saml:SubjectConfirmationData    </ds:KeyInfo>
                </saml:SubjectConfirmationData>NotOnOrAfter="2020-12-07T09:09:29Z" Recipient="https://sosi"/>
              </saml:SubjectConfirmation>
            </saml:Subject>
            <saml:Conditions NotBefore="2020-12-07T09:0104:39Z24Z" NotOnOrAfter="2020-12-07T09:09:29Z">
              <saml:AudienceRestriction>
                <saml:Audience>https://fmk<Audience/>
            </saml:Audience>AudienceRestriction>
          </saml:Conditions>
        </saml:AudienceRestriction>Assertion>
      </wst14:ActAs>
      </saml<wsp:Conditions>AppliesTo>
        <wsa:EndpointReference>
          <saml:AttributeStatement>
<wsa:Address>https://fmk</wsa:Address>
        </wsa:EndpointReference>
      </wsp:AppliesTo>
    <saml:Attribute Name="dk:gov:saml:attribute:SpecVer" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic  <wst:Claims Dialect="http://docs.oasis-open.org/wsfed/authorization/200706/authclaims">
                <saml:AttributeValue xsi:type="xs:string">DK-SAML-2.0</saml:AttributeValue><auth:ClaimType Uri="dk:gov:saml:attribute:CprNumberIdentifier">
              </saml:Attribute>
<auth:Value>0501792275</auth:Value>
        </auth:ClaimType>
        <saml<auth:AttributeClaimType NameUri="dk:govhealthcare:saml:attribute:AssuranceLevel" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basicOnBehalfOf">
                <saml:AttributeValue xsi:type="xs:string">3</saml:AttributeValue>
      <auth:Value>urn:dk:healthcare:saml:actThroughProcurationBy:cprNumberIdentifier:0101603040</auth:Value>
        </samlauth:Attribute>ClaimType>
      </wst:Claims>
    </wst:RequestSecurityToken>
  </soapenv:Body>
</soapenv:Envelope>

Svaret fra STS ser således ud:

Code Block
languagexml
title(Borgeromveksling) BST2IDWS Response fra STS
collapsetrue
<?xml version="1.0" encoding="UTF-8"?>
<soapenv:Envelope xmlns:soapenv="http://schemas.xmlsoap.org/soap/envelope/" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:saml    <saml:Attribute Name="dk:gov:saml:attribute:CprNumberIdentifier" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
                <saml:AttributeValue xsi:type="xs:string">0501792275</saml:AttributeValue>
              </saml:Attribute>
              <saml:Attribute Name="dk:gov:saml:attribute:Privileges_intermediate" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
                <saml:AttributeValue xsi:type="xs:string">PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiID8+PGJwcDpQcml2aWxlZ2VMaXN0IHhtbG5zOmJwcD0iaHR0cDovL2l0c3QuZGsvb2lvc2FtbC9iYXNpY19wcml2aWxlZ2VfcHJvZmlsZSI+PGJwcDpQcml2aWxlZ2VHcm91cCBTY29wZT0idXJuOmRrOmhlYWx0aGNhcmU6c2FtbDphY3RUaHJvdWdoUHJvY3VyYXRpb25CeTpjcHJOdW1iZXJJZGVudGlmaWVyOjAxMDE2MDMwNDAiPjxicHA6UHJpdmlsZWdlPnVybjpkazpuc3BvcDpzdHM6ZGR2OnJlYWQ8L2JwcDpQcml2aWxlZ2U+PGJwcDpQcml2aWxlZ2U+dXJuOmRrOm5zcG9wOnN0czpkZHY6d3JpdGU8L2JwcDpQcml2aWxlZ2U+PGJwcDpQcml2aWxlZ2U+dXJuOmRrOm5zcG9wOnN0czpmbWs6cmVhZDwvYnBwOlByaXZpbGVnZT48YnBwOlByaXZpbGVnZT51cm46ZGs6bnNwb3A6c3RzOmZtazp3cml0ZTwvYnBwOlByaXZpbGVnZT48L2JwcDpQcml2aWxlZ2VHcm91cD48L2JwcDpQcml2aWxlZ2VMaXN0Pg==</saml:AttributeValue>
              </saml:Attribute>
            </saml:AttributeStatement>
          </saml:Assertion>
        </wst:RequestedSecurityToken>
        <wsp:AppliesTo>
          <wsa:EndpointReference>
            <wsa:Address>https://fmk</wsa:Address>
          </wsa:EndpointReference>
        </wsp:AppliesTo>assertion" xmlns:wsa="http://www.w3.org/2005/08/addressing" xmlns:wsp="http://schemas.xmlsoap.org/ws/2004/09/policy" xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" xmlns:wst="http://docs.oasis-open.org/ws-sx/ws-trust/200512" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">
  <soapenv:Header>
    <wsa:Action wsu:Id="action">http://docs.oasis-open.org/ws-sx/ws-trust/200512/RST/Issue</wsa:Action>
    <wsa:MessageID wsu:Id="messageID">urn:uuid:bde6ee0c-06a9-4dd7-9ae0-3bf29b6280e3</wsa:MessageID>
    <wsa:RelatesTo wsu:Id="relatesTo">urn:uuid:3b222db7-5922-477c-b815-4ea35cba6574</wsa:RelatesTo>
    <wsse:Security mustUnderstand="1" wsu:Id="security">
      <wsu:Timestamp  <wst:Lifetime>
  wsu:Id="ts">
        <wsu:Created>2020-12-07T09:0106:39Z</wsu:Created>
      </wsu:Timestamp>
      <wsu:Expires>2020-12-07T09:09:29Z</wsu:Expires><ds:Signature>
        </wst<ds:Lifetime>SignedInfo>
           </wst:RequestSecurityTokenResponse><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
    </wst:RequestSecurityTokenResponseCollection>
  </soapenv:Body>
</soapenv:Envelope>

Bemærk returværdien fra STS, der indeholder attributten 'dk:gov:saml:attribute:Privileges_intermediate'. Værdien er base64 encoded. Efter en decode ser det således ud (bemærk, at strukturen både indeholder det CPR nummer, som borgeren ønsker at arbejde på vegne af samt listen af de privilegier, der rent faktisk er tildelt fra denne borger til den kaldende borger):

Code Block
languagexml
titleDecoded dk:gov:saml:attribute:Privileges_intermediate
collapsetrue
<?xml version="1.0" encoding="UTF-8"?>
<bpp:PrivilegeList xmlns:bpp      <ds:SignatureMethod Algorithm="http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>0101603040
          <ds:Reference URI="#messageID">
            <ds:Transforms>
              <ds:Transform Algorithm="http://itst.dk/oiosaml/basic_privilege_profile">
  <bpp:PrivilegeGroup Scope="urn:dk:healthcare:saml:actThroughProcurationBy:cprNumberIdentifier:0101603040">
    <bpp:Privilege>urn:dk:nspop:sts:ddv:read</bpp:Privilege>
    <bpp:Privilege>urn:dk:nspop:sts:ddv:write</bpp:Privilege>
    <bpp:Privilege>urn:dk:nspop:sts:fmk:read</bpp:Privilege>
    <bpp:Privilege>urn:dk:nspop:sts:fmk:write</bpp:Privilege>
  </bpp:PrivilegeGroup>
</bpp:PrivilegeList>

 OIO2BST assertion

Code Block
languagexml
titleoio2bst citizen assertion
collapsetrue
<Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion" ID="_f3070cce-b0ce-4025-b374-ada158cb137c" IssueInstant="2020-11-13T10:22:50.027Z" Version="2.0">
    <!--  Udstederen af bootstraptokenet (her SEB IdP)  -->
    <Issuer>https://seblogin.nsi.dk/runtime/</Issuer>
    <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>5YUEr9PKYYu2iyvY0XhKxHE6NFk=</ds:DigestValue>
          </ds:Reference>
          <ds:Reference URI="#action">
            <ds:Transforms>
              <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            </ds:Transforms>
            <ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>3cXAhlhZH22NiSh7AttxKxBap7Q=</ds:DigestValue>
          </ds:Reference>
          <ds:Reference URI="#relatesTo">
            <ds:SignedInfo>Transforms>
              <ds:CanonicalizationMethodTransform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/></ds:Transforms>
            <ds:ReferenceDigestMethod URI="#_f3070cce-b0ce-4025-b374-ada158cb137c">
   Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
             <ds:Transforms><ds:DigestValue>Oo+c5AT3Gky7Q2+jevrnjtKkbhI=</ds:DigestValue>
          </ds:Reference>
          <ds:TransformReference AlgorithmURI="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
#ts">
            <ds:Transforms>
              <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                </ds:Transforms>
                <ds:DigestMethod Algorithm="http://www.w3.org/20012000/0409/xmlenc#sha256xmldsig#sha1"/>
                <ds:DigestValue>mLOzno5qLFEcRB7wZ803TDigestValue>/DWD2fll+63ZuUdWFETQm1DH0uLgxEqjDeFmjYb4i4TTQcJE=</ds:DigestValue>
            </ds:Reference>
        </ds:SignedInfo>
        <ds:SignatureValue>cam+piuM1GFsBWP2cyTnKCkSYFMYjwKawizCLXw2F8fpD2UioxDtbFOJLG8ca03lh5881RRxrqkwK0Q/QAgKACB8t7NXuYOnMZK0hm2Ys9wibGVqS2De7UImO7BA/RvL9QjRuOHqM3/BWeNG1hteIFzDsVmYGu6CRH6giuLx7uoI6mF69Jb3v3DrztjaCRqWXU8lJo6bNY/ET/hu5/10Xfegb/7qNWb34cW7WQE2qAWRJaLyj1/apQX5BpsdjS0V2uvTsQYx+Dob8cTKqY9nPbuUR5pgcsEg6jle82GhpsiT5hHyC7R2BlP2ZFknkAMg8orogOIhe0tYTIzMD6d2DQ==</ds:SignatureValue>
        <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#">
            <X509Data><ds:Reference URI="#body">
            <ds:Transforms>
    <!--  Certifikat som har signeret bootstraptokenet (her SEB IdP) <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
                <X509Certificate>MIIGRTCCBS2gAwIBAgIEUw8DszANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSQwIgYDVQQDDBtUUlVTVDI0MDggU3lzdGVtdGVzdCBYSVggQ0EwHhcNMTQwNTA1MTMzNTU4WhcNMTcwNTA1MTMzNTEyWjCBljELMAkGA1UEBhMCREsxMTAvBgNVBAoMKERpZ2l0YWxpc2VyaW5nc3N0eXJlbHNlbiAvLyBDVlI6MzQwNTExNzgxVDAgBgNVBAUTGUNWUjozNDA1MTE3OC1VSUQ6ODMzODQ5NzAwMAYDVQQDDClEaWdpdGFsaXNlcmluZ3NzdHlyZWxzZW4gLSBOZW1Mb2ctaW4gVGVzdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALnCmDRMztjDckSupQBLcEzrRRJnAFxzEFdB7Cj6ApMQ/YxqKzfL/TSIr3v2mdgQNnsJGz91YbAteDPRHR/K1W3kqoIX/qH2uXDzHK+qi4YD9D8s4MnHAt02x6t0TgKQGjn1XO6lgLQ563DjtgD2fdPm9USV2Lkxe5ofNRG7yvWowBWjXKia8D64k6zSzoHKdPz6GCy9S0NmwIyJE0sJavcfwxT3/ia0g63/xD77SteT4H/OR/DLis7FLnfkLp8yrd5xAk4nEGizmjrg2OVJmIMMPK6PQdw+/lqSdgaPDxMD6yoIwWshux5Rup1+piMLg852odHR6EhUzjEsi9DnWWcCAwEAAaOCAucwggLjMA4GA1UdDwEB/wQEAwIEsDCBlwYIKwYBBQUHAQEEgYowgYcwPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnN5c3RlbXRlc3QxOS50cnVzdDI0MDguY29tL3Jlc3BvbmRlcjBHBggrBgEFBQcwAoY7aHR0cDovL3YuYWlhLnN5c3RlbXRlc3QxOS50cnVzdDI0MDguY29tL3N5c3RlbXRlc3QxOS1jYS5jZXIwggEgBgNVHSAEggEXMIIBEzCCAQ8GDSsGAQQBgfRRAgQGAwQwgf0wLwYIKwYBBQUHAgEWI2h0dHA6Ly93d3cudHJ1c3QyNDA4LmNvbS9yZXBvc2l0b3J5MIHJBggrBgEFBQcCAjCBvDAMFgVEYW5JRDADAgEBGoGrRGFuSUQgdGVzdCBjZXJ0aWZpa2F0ZXIgZnJhIGRlbm5lIENBIHVkc3RlZGVzIHVuZGVyIE9JRCAxLjMuNi4xLjQuMS4zMTMxMy4yLjQuNi4zLjQuIERhbklEIHRlc3QgY2VydGlmaWNhdGVzIGZyb20gdGhpcyBDQSBhcmUgaXNzdWVkIHVuZGVyIE9JRCAxLjMuNi4xLjQuMS4zMTMxMy4yLjQuNi4zLjQuMBwGA1UdEQQVMBOBEW5lbWxvZ2luQGRpZ3N0LmRrMIGpBgNVHR8EgaEwgZ4wPKA6oDiGNmh0dHA6Ly9jcmwuc3lzdGVtdGVzdDE5LnRydXN0MjQwOC5jb20vc3lzdGVtdGVzdDE5LmNybDBeoFygWqRYMFYxCzAJBgNVBAYTAkRLMRIwEAYDVQQKDAlUUlVTVDI0MDgxJDAiBgNVBAMMG1RSVVNUMjQwOCBTeXN0ZW10ZXN0IFhJWCBDQTENMAsGA1UEAwwEQ1JMMjAfBgNVHSMEGDAWgBTMAlUM5IF0ryBU1REUV5yRUjh/oDAdBgNVHQ4EFgQUwm9c3oUHE/zZ/43g4RUhswnMVAowCQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAQEACLh3Ovvljv4b/Ywf/8WxoB2y50Oqt8rpwXZp+no4d5tLqIMTSAlQxL0lAf4Qm4e6tF5m/55+dLwxw5/Dqwa0bQXHt98vJjSBYLQH6rwfDzNmVGimO1n84k4MMYY449ykjqRNDfCS3+5+zV/An4CH9eUhvB0AHHWbD6eALw39sPGxc5kHADTOdJ5SboSm9DHYdLLt9k8HyxrHIkcJApLWPgyFmkE0+8jtuQQluN62F5+j5d53oTKinHEd7adM0ea537vNf5uBGu6h9OTXlhZwM9tlnrsTYQTTAIzdxGPlpD9Zvo5nmJHwILdRonm8rZf3vAm59/U6+Cht4+X2l5zxyg==</X509Certificate>
</ds:Transforms>
             </X509Data>
<ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
            <ds:DigestValue>TOdMnbhE5vN9Q9/01qfrGKKKJP0=</KeyInfo>ds:DigestValue>
          </ds:Signature>Reference>
       <Subject> </ds:SignedInfo>
        <!--  NameID indeholder en unik ID for borgeren  --><ds:SignatureValue>Or2nuZl8pyU4t6h90FP50MwghnBaQo0hGr/uOrDxkQo3lUXXxa5P2S4Vs5I8NzvgHGx22Piq19D2S7Z9NVMxPgRQC+kyhxIUehYFWv4ZlEX6L8Qn0N2T+44UA9pUZgJYH4BbUF0fXY79KZAiD5JGa6sc0ZKZTnO5eusR6ef6+m1jTGDOXEjH2J+qQ6i23VJPIYB0yxNU53n79d05rknhipWCQYfthE6eNKyfMy1jvkm1Wyux1bZUhwL+1WOZIbXTN7LbgN1I0x1IxFFe6yJ6ccIiSOoSzyEp00sVcTVoBLzfF2GmYVFijJo3kjjOXwnDTjxXCPCUE22ND4rjrmb2Zg==</ds:SignatureValue>
        <ds:KeyInfo>
        <!--  TODO<ds:X509Data>
 Hvad skal SEB sætte her?  -->
        <NameID Format="’urn:oasis:names:tc:SAML:2.0:nameid-format:persistent">dk:gov:saml:attribute:CprNumberIdentifier:1802602810</NameID>
<ds:X509Certificate>MIIGKjCCBRKgAwIBAgIEW6uMBTANBgkqhkiG9w0BAQsFADBIMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSUwIwYDVQQDDBxUUlVTVDI0MDggU3lzdGVtdGVzdCBYWElJIENBMB4XDTE5MDQzMDA5MDcxN1oXDTIyMDQzMDA5MDYzOFowgZQxCzAJBgNVBAYTAkRLMS4wLAYDVQQKDCVTdW5kaGVkc2RhdGFzdHlyZWxzZW4gLy8gQ1ZSOjMzMjU3ODcyMVUwIAYDVQQFExlDVlI6MzMyNTc4NzItRklEOjE4OTExODYxMDEGA1UEAwwqU09TSSBUZXN0IEZlZGVyYXRpb24gKGZ1bmt0aW9uc2NlcnRpZmlrYXQpMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyo57h9E/hM5gimxaDgHB0MLcgVfXGJbQh/8OC1vTdDsCUIzIwRd5lJE+ado8urHF7UmKubFZzfCPduoRv9b3TkNVKaixiHUMtP4egbL8vcgyalk28cNQdUk8f34mg8atgvd45EnIKz2iB+yjs5guJPDBg2OFSbP0r53NU8fVTq3aLtDpDVnkxsyjNQ7HOFtzavyMnKx0vDgafEvrUR3WTSLCGju4aUIg3ThgrWXA7i3lPIAXdV8mQmlY3wn/kIBiyIotmF98UsEket/sxpJNkJ6R6AUpxnGApCDP1Fw2BgxAQWWrtD/c5IoIZwGWNfLgpJEzfhnuIZJ7Bfs9RmHFdQIDAQABo4ICzTCCAskwDgYDVR0PAQH/BAQDAgO4MIGXBggrBgEFBQcBAQSBijCBhzA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc3lzdGVtdGVzdDIyLnRydXN0MjQwOC5jb20vcmVzcG9uZGVyMEcGCCsGAQUFBzAChjtodHRwOi8vZi5haWEuc3lzdGVtdGVzdDIyLnRydXN0MjQwOC5jb20vc3lzdGVtdGVzdDIyLWNhLmNlcjCCASAGA1UdIASCARcwggETMIIBDwYNKwYBBAGB9FECBAYEAjCB/TAvBggrBgEFBQcCARYjaHR0cDovL3d3dy50cnVzdDI0MDguY29tL3JlcG9zaXRvcnkwgckGCCsGAQUFBwICMIG8MAwWBURhbklEMAMCAQEagatEYW5JRCB0ZXN0IGNlcnRpZmlrYXRlciBmcmEgZGVubmUgQ0EgdWRzdGVkZXMgdW5kZXIgT0lEIDEuMy42LjEuNC4xLjMxMzEzLjIuNC42LjQuMi4gRGFuSUQgdGVzdCBjZXJ0aWZpY2F0ZXMgZnJvbSB0aGlzIENBIGFyZSBpc3N1ZWQgdW5kZXIgT0lEIDEuMy42LjEuNC4xLjMxMzEzLjIuNC42LjQuMi4wga0GA1UdHwSBpTCBojA9oDugOYY3aHR0cDovL2NybC5zeXN0ZW10ZXN0MjIudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MjIxLmNybDBhoF+gXaRbMFkxCzAJBgNVBAYTAkRLMRIwEAYDVQQKDAlUUlVTVDI0MDgxJTAjBgNVBAMMHFRSVVNUMjQwOCBTeXN0ZW10ZXN0IFhYSUkgQ0ExDzANBgNVBAMMBkNSTDE0MjAfBgNVHSMEGDAWgBSrqAFEGbCzQ5na+nzM0gAYA+c8vzAdBgNVHQ4EFgQUGYAVKKL17LHyVGSErL26MBNadTQwCQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAQEAjHMO4sWEf8M25WHczBTJYtMitn1wLOqE6raeM6oYyw6R/4FImpOzF6bxBlfNnhhR0vJSXMWTqL/onCyy4gCs9eLglRHZ9BC8a9fmirrguNpOWlR8NAf5GRwOqCyTnkTAfUD1fp0RzVo8TvAd73WiGeUTzTiAVf7OgZFnRIYkcALXLjNs6AwELWSh+bC/gGuQcHUDd8YGSzgKS6w2qz3fIASrykxzlYjeusks58CereC6WfvN0I+GGlL9fIgjpzh7JEELME7r9QJLL9NSrmlRKfhM8gzuE6Vm4vGzmSsnNJxGMf1vTzEve4lXI8pnOtHMTtNl5zw4jCJFakRqcWm3FQ==</ds:X509Certificate>
         <SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:holder-of-key"> </ds:X509Data>
        </ds:KeyInfo>
     <SubjectConfirmationData xmlns:a="http://www.w3.org/2001/XMLSchema-instance" a:type="KeyInfoConfirmationDataType</ds:Signature>
    </wsse:Security>
  </soapenv:Header>
  <soapenv:Body wsu:Id="body">
    <wst:RequestSecurityTokenResponseCollection>
      <wst:RequestSecurityTokenResponse Context="urn:uuid:b501bee1-e6ef-4bda-9877-ce43d8637354">
       <KeyInfo xmlns="http <wst:TokenType>http://wwwdocs.w3oasis-open.org/2000/09/xmldsig#">
                    <X509Data>
   wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0</wst:TokenType>
        <wst:RequestedSecurityToken>
          <saml:Assertion   <!--  Holder-of-key certifikatet - dvs. certifikat for det system/SOSI-STS-klient som kan veksle bootstraptokenet til et IDWS-identitytoken -->
                        <X509Certificate>MIIGIzCCBQugAwIBAgIEUw/NqTANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSQwIgYDVQQDDBtUUlVTVDI0MDggU3lzdGVtdGVzdCBYSVggQ0EwHhcNMTUwNDIwMDcyNTQyWhcNMTgwNDIwMDcyMzM3WjCBkTELMAkGA1UEBhMCREsxMTAvBgNVBAoMKERpZ2l0YWxpc2VyaW5nc3N0eXJlbHNlbiAvLyBDVlI6MzQwNTExNzgxTzAgBgNVBAUTGUNWUjozNDA1MTE3OC1GSUQ6NjkyMjEwNTAwKwYDVQQDDCRKYXZhIHJlZi4gVEVTVCAoZnVua3Rpb25zY2VydGlmaWthdCkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCsZhc0L2r7+KF2FtqJxtBI/KKneBo6ojLQf8ZgaXa6eFK15lyI4nGM3xZ/OgC8/vjsw2XWQE08vL09W8SKiujEt6xs967Z/Y4rNl1S8hZa5TVmBTlOEwEbmIzGB8tckVj14KnZ6kcZGvygb8FT5gvMGpueMj3OzvhvkShfGvuG/9yrr8hj7590vu3X0EkeI5dQAFPG41sUqzjDMZhZol5zhHCqkxXf0C+H+1gYYvNvEYGc1WXfaK0j3i66RcKAWJvozgf6jDQfwHsV7qswndxbvIhoZ6W7cBxzs4ajDQ5QeHS5JtWKopgmz0hXgcgXChJ4ZVvyhpatXLuldJeINrlHAgMBAAGjggLKMIICxjAOBgNVHQ8BAf8EBAMCA7gwgZcGCCsGAQUFBwEBBIGKMIGHMDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zeXN0ZW10ZXN0MTkudHJ1c3QyNDA4LmNvbS9yZXNwb25kZXIwRwYIKwYBBQUHMAKGO2h0dHA6Ly9mLmFpYS5zeXN0ZW10ZXN0MTkudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MTktY2EuY2VyMIIBIAYDVR0gBIIBFzCCARMwggEPBg0rBgEEAYH0UQIEBgQCMIH9MC8GCCsGAQUFBwIBFiNodHRwOi8vd3d3LnRydXN0MjQwOC5jb20vcmVwb3NpdG9yeTCByQYIKwYBBQUHAgIwgbwwDBYFRGFuSUQwAwIBARqBq0RhbklEIHRlc3QgY2VydGlmaWthdGVyIGZyYSBkZW5uZSBDQSB1ZHN0ZWRlcyB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4yLiBEYW5JRCB0ZXN0IGNlcnRpZmljYXRlcyBmcm9tIHRoaXMgQ0EgYXJlIGlzc3VlZCB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4yLjCBqgYDVR0fBIGiMIGfMDygOqA4hjZodHRwOi8vY3JsLnN5c3RlbXRlc3QxOS50cnVzdDI0MDguY29tL3N5c3RlbXRlc3QxOS5jcmwwX6BdoFukWTBXMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSQwIgYDVQQDDBtUUlVTVDI0MDggU3lzdGVtdGVzdCBYSVggQ0ExDjAMBgNVBAMMBUNSTDI4MB8GA1UdIwQYMBaAFMwCVQzkgXSvIFTVERRXnJFSOH+gMB0GA1UdDgQWBBRUEhCFm3sj4tGyEI3OkBYnKKSOFDAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBCwUAA4IBAQB9r7wKMTPCxGmQYFu7M+CyGrxSWaFqe8FH6YGyh9SaCjZUSbayamCqjhxM+7cLZtSBXySMYkcUImj5tWzED3BUIX6vbhzXvAsvyBuyXH9iRrBq3hLUOL18dBOMOY98TghF9jqJQBoq3Ikctob3/ikfpws86/jLnoKvA5q3IGYJIiwZssj85kcXmbhOpi1x9SjCRqgXldDVqiSEBVcuU8WKqvDVhIoFJzpsDbWvjeGnlgXtU0mK55tJYvm9i0leaoaAEKesRd2MdG9yZ4yhDFcvzUaTlQULvBxoNgXGPOGPxIEr2euiDhBcdrx/zbC8tjok6eBwu4FvGqyrpm11xjQs</X509Certificate>xmlns:xs="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" ID="_fa311122-026e-4049-8ddf-cdbd84304d7c" IssueInstant="2020-12-07T09:06:39Z" Version="2.0">
            <saml:Issuer>TEST2-NSP-STS</saml:Issuer>
            </X509Data> <ds:Signature Id="OCESSignature">
              <ds:SignedInfo>
  </KeyInfo>
              </SubjectConfirmationData><ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
        </SubjectConfirmation>
    </Subject>
    <Conditions<ds:SignatureMethod NotOnOrAfterAlgorithm="2020-11-13T12:22:50.027Z"http://www.w3.org/2000/09/xmldsig#rsa-sha1"/>
        <!--  Aftageren som  omveksle dette bootstraptoken (her SOSI-STS'en)   -->
 <ds:Reference URI="#_fa311122-026e-4049-8ddf-cdbd84304d7c">
       <AudienceRestriction>
            <Audience>https://sts.sosi.dk/</Audience>
  <ds:Transforms>
      </AudienceRestriction>
    </Conditions>
    <AttributeStatement>
        <!--  Angivelse af profil og version (konstanten 'DK-SAML-2.0')  -->
<ds:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
                   <Attribute Name="dk:gov:saml:attribute:SpecVer" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic"<ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
            <AttributeValue>DK-SAML-2.0</AttributeValue>
        </Attribute>ds:Transforms>
        <!--  Sikringsniveau udtrykt efter NIST/ITT  -->
        <Attribute Name="dk:gov:saml:attribute:AssuranceLevel" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
<ds:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha1"/>
                  <AttributeValue>3</AttributeValue><ds:DigestValue>GOIAqcYUFLnazqyu7B4AL2vpV5o=</ds:DigestValue>
        </Attribute>
        <!--/ds:Reference>
  borgerens CPR-nummer  -->
        <Attribute Name="dk:gov:saml:attribute:CprNumberIdentifier" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
 </ds:SignedInfo>
               <AttributeValue>1802602810</AttributeValue><ds:SignatureValue>sM1Nl1ehU0k4WwrNyIJaRn/VDH9JbriFlDKaRzd/iwYtiF6rCA+NQMMHYqAjjzPewjamKuueIqx7MTt0ElEN3mUcdBaSqaohdhmTTM9U2IB76B+sWNxpGdCXQ8N1lYjVqBYkCn6uAvzG89fADpTNkBct8ekWuj/UT06h/O8KLxybhK7I0HNOWkJ45BAhOIJTOc7Vg4qyIk3PJIh+8TzpyUY9L2WuBg8YKzgAd+8uCKRFn223ePRL6GtRlJJqsXm/x/82CNj6lGHdCFXsPcZrrYvKCmZu8FSFEqQrLjyE/ULnbTQVfe+gAPhIzAh01n1SvlWoQ0omyzjiWCAA2Sketw==</ds:SignatureValue>
        </Attribute>
     </AttributeStatement>
</Assertion>

 OIO3BST assertion

Code Block
languagexml
titleoio3bst citizen assertion
collapsetrue
<Assertion xmlns="urn:oasis:names:tc:SAML:2.0:assertion" ID="_f3070cce-b0ce-4025-b374-ada158cb137c" IssueInstant="2020-11-13T10:22:50.027Z" Version="2.0">
 <ds:KeyInfo>
       <!--  Udstederen af bootstraptokenet (her NemLog-in3 STS)  -->
<ds:X509Data>
     <Issuer>https://sts.nemlog-in.dk</Issuer>
             <ds:Signature xmlns:ds="http://www.w3.org/2000/09/xmldsig#">X509Certificate>MIIGKjCCBRKgAwIBAgIEW6uMBTANBgkqhkiG9w0BAQsFADBIMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSUwIwYDVQQDDBxUUlVTVDI0MDggU3lzdGVtdGVzdCBYWElJIENBMB4XDTE5MDQzMDA5MDcxN1oXDTIyMDQzMDA5MDYzOFowgZQxCzAJBgNVBAYTAkRLMS4wLAYDVQQKDCVTdW5kaGVkc2RhdGFzdHlyZWxzZW4gLy8gQ1ZSOjMzMjU3ODcyMVUwIAYDVQQFExlDVlI6MzMyNTc4NzItRklEOjE4OTExODYxMDEGA1UEAwwqU09TSSBUZXN0IEZlZGVyYXRpb24gKGZ1bmt0aW9uc2NlcnRpZmlrYXQpMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAyo57h9E/hM5gimxaDgHB0MLcgVfXGJbQh/8OC1vTdDsCUIzIwRd5lJE+ado8urHF7UmKubFZzfCPduoRv9b3TkNVKaixiHUMtP4egbL8vcgyalk28cNQdUk8f34mg8atgvd45EnIKz2iB+yjs5guJPDBg2OFSbP0r53NU8fVTq3aLtDpDVnkxsyjNQ7HOFtzavyMnKx0vDgafEvrUR3WTSLCGju4aUIg3ThgrWXA7i3lPIAXdV8mQmlY3wn/kIBiyIotmF98UsEket/sxpJNkJ6R6AUpxnGApCDP1Fw2BgxAQWWrtD/c5IoIZwGWNfLgpJEzfhnuIZJ7Bfs9RmHFdQIDAQABo4ICzTCCAskwDgYDVR0PAQH/BAQDAgO4MIGXBggrBgEFBQcBAQSBijCBhzA8BggrBgEFBQcwAYYwaHR0cDovL29jc3Auc3lzdGVtdGVzdDIyLnRydXN0MjQwOC5jb20vcmVzcG9uZGVyMEcGCCsGAQUFBzAChjtodHRwOi8vZi5haWEuc3lzdGVtdGVzdDIyLnRydXN0MjQwOC5jb20vc3lzdGVtdGVzdDIyLWNhLmNlcjCCASAGA1UdIASCARcwggETMIIBDwYNKwYBBAGB9FECBAYEAjCB/TAvBggrBgEFBQcCARYjaHR0cDovL3d3dy50cnVzdDI0MDguY29tL3JlcG9zaXRvcnkwgckGCCsGAQUFBwICMIG8MAwWBURhbklEMAMCAQEagatEYW5JRCB0ZXN0IGNlcnRpZmlrYXRlciBmcmEgZGVubmUgQ0EgdWRzdGVkZXMgdW5kZXIgT0lEIDEuMy42LjEuNC4xLjMxMzEzLjIuNC42LjQuMi4gRGFuSUQgdGVzdCBjZXJ0aWZpY2F0ZXMgZnJvbSB0aGlzIENBIGFyZSBpc3N1ZWQgdW5kZXIgT0lEIDEuMy42LjEuNC4xLjMxMzEzLjIuNC42LjQuMi4wga0GA1UdHwSBpTCBojA9oDugOYY3aHR0cDovL2NybC5zeXN0ZW10ZXN0MjIudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MjIxLmNybDBhoF+gXaRbMFkxCzAJBgNVBAYTAkRLMRIwEAYDVQQKDAlUUlVTVDI0MDgxJTAjBgNVBAMMHFRSVVNUMjQwOCBTeXN0ZW10ZXN0IFhYSUkgQ0ExDzANBgNVBAMMBkNSTDE0MjAfBgNVHSMEGDAWgBSrqAFEGbCzQ5na+nzM0gAYA+c8vzAdBgNVHQ4EFgQUGYAVKKL17LHyVGSErL26MBNadTQwCQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAQEAjHMO4sWEf8M25WHczBTJYtMitn1wLOqE6raeM6oYyw6R/4FImpOzF6bxBlfNnhhR0vJSXMWTqL/onCyy4gCs9eLglRHZ9BC8a9fmirrguNpOWlR8NAf5GRwOqCyTnkTAfUD1fp0RzVo8TvAd73WiGeUTzTiAVf7OgZFnRIYkcALXLjNs6AwELWSh+bC/gGuQcHUDd8YGSzgKS6w2qz3fIASrykxzlYjeusks58CereC6WfvN0I+GGlL9fIgjpzh7JEELME7r9QJLL9NSrmlRKfhM8gzuE6Vm4vGzmSsnNJxGMf1vTzEve4lXI8pnOtHMTtNl5zw4jCJFakRqcWm3FQ==</ds:X509Certificate>
        <ds:SignedInfo>
            <ds:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
</ds:X509Data>
             <ds:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/> </ds:KeyInfo>
            <ds:Reference URI="#_f3070cce-b0ce-4025-b374-ada158cb137c"></ds:Signature>
            <saml:Subject>
    <ds:Transforms>
          <saml:NameID Format="urn:oasis:names:tc:SAML:1.1:nameid-format:X509SubjectName">C=DK,O=Ingen organisatorisk tilknytning,CN=Lars Larsen,Serial=PID:9208-2002-2-514358910503</saml:NameID>
              <ds<saml:TransformSubjectConfirmation AlgorithmMethod="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/urn:oasis:names:tc:SAML:2.0:cm:holder-of-key">
                    <ds:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/<saml:SubjectConfirmationData NotOnOrAfter="2020-12-07T09:09:29Z" Recipient="https://fmk">
                </ds:Transforms>
  <ds:KeyInfo>
                    <ds:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
X509Data>
                      <ds:DigestValue>mLOzno5qLFEcRB7wZ803T+63ZuUdWFETQm1DH0uLgxEX509Certificate>MIIGNDCCBRygAwIBAgIEXOg9yTANBgkqhkiG9w0BAQsFADBJMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTAeFw0yMDAyMTMxMzQ3NTdaFw0yMzAyMTMxMzQzMzBaMIGeMQswCQYDVQQGEwJESzEuMCwGA1UECgwlU3VuZGhlZHNkYXRhc3R5cmVsc2VuIC8vIENWUjozMzI1Nzg3MjFfMCAGA1UEBRMZQ1ZSOjMzMjU3ODcyLUZJRDo3OTY4MDA0NTA7BgNVBAMMNFRFU1Qgd2hpdGVsaXN0ZWQgU1AgU09TSSBhbGlhcyAoZnVua3Rpb25zY2VydGlmaWthdCkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCNWtWKpMlLgD5Er0SgRjNCKXlwU39x3DTPvqE/r09j96B+pwbzHjhnbV5HPwCNzoeUolcvnPmJrsOucIHsoKebPgfLEnhfjWnl0Z8ivPy/3iQfHyhJoB3shBcfLwH+FwZzEqw3hsabflVJHTq+9u2bLes9UM7r2Hy0mlynux28nFKB8dqkYVS1MjAid2cID4vbbavlFO+N+BSIt8M+MA8A1FVwhUEc/vyD+Ha8Alo3nYLZV9SqYlzeeGR+umiyQ7lhVOzv2CO2ULBSpX28mxGJ4N8CmCUrZgbSnPwkw3Mkq93bzMRUB4X9Bu/hWIpQZooKDM6wxE8dYn1yrAliw+ujAgMBAAGjggLMMIICyDAOBgNVHQ8BAf8EBAMCA7gwgZcGCCsGAQUFBwEBBIGKMIGHMDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9yZXNwb25kZXIwRwYIKwYBBQUHMAKGO2h0dHA6Ly9mLmFpYS5zeXN0ZW10ZXN0MzQudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MzQtY2EuY2VyMIIBIAYDVR0gBIIBFzCCARMwggEPBg0rBgEEAYH0UQIEBgQDMIH9MC8GCCsGAQUFBwIBFiNodHRwOi8vd3d3LnRydXN0MjQwOC5jb20vcmVwb3NpdG9yeTCByQYIKwYBBQUHAgIwgbwwDBYFRGFuSUQwAwIBARqBq0RhbklEIHRlc3QgY2VydGlmaWthdGVyIGZyYSBkZW5uZSBDQSB1ZHN0ZWRlcyB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLiBEYW5JRCB0ZXN0IGNlcnRpZmljYXRlcyBmcm9tIHRoaXMgQ0EgYXJlIGlzc3VlZCB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4zLjCBrAYDVR0fBIGkMIGhMDygOqA4hjZodHRwOi8vY3JsLnN5c3RlbXRlc3QzNC50cnVzdDI0MDguY29tL3N5c3RlbXRlc3QzNC5jcmwwYaBfoF2kWzBZMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSYwJAYDVQQDDB1UUlVTVDI0MDggU3lzdGVtdGVzdCBYWFhJViBDQTEOMAwGA1UEAwwFQ1JMMTEwHwYDVR0jBBgwFoAUzWxolzlyGaQ1q2Tq9BGjgYf4aTswHQYDVR0OBBYEFCe0e26va9zqyshyZoXec/52Pl5RMAkGA1UdEwQCMAAwDQYJKoZIhvcNAQELBQADggEBAGnG/H/WeWIPAbnuPMZ/p2sSulgesmt6N1fK5mupYlVmLQ/7fuBIh/ER8zK3ya6yuQBAfSwIYib8iFWm+VBPc+CeS8KE/z4LRZKs3tsFkyEPlee3KpyQ4BQEawwLZjb0ZHS6ghI846SFOy+nYV8HpLvws5/vTNlGaRbBlrDVFzL/ZGois0EJe6wd3xnglwEIKjCxv30zzAnCOrmEzGIaojm07F7rnpQkaCmGNDfsSWl6Mi8SZ8jhFZHdybG9mjr6BXc1wJl2C6hQVuo7wvaIhVgJpV5BkG61mcCBniZhGr7uCJyjQ1vheKDEDle4IIzyVajjM+x5F3BWb6JQxujEHOU=</ds:DigestValue>X509Certificate>
                    </ds:Reference>
X509Data>
                  </ds:SignedInfo>KeyInfo>
          <ds:SignatureValue>cam+piuM1GFsBWP2cyTnKCkSYFMYjwKawizCLXw2F8fpD2UioxDtbFOJLG8ca03lh5881RRxrqkwK0Q/QAgKACB8t7NXuYOnMZK0hm2Ys9wibGVqS2De7UImO7BA/RvL9QjRuOHqM3/BWeNG1hteIFzDsVmYGu6CRH6giuLx7uoI6mF69Jb3v3DrztjaCRqWXU8lJo6bNY/ET/hu5/10Xfegb/7qNWb34cW7WQE2qAWRJaLyj1/apQX5BpsdjS0V2uvTsQYx+Dob8cTKqY9nPbuUR5pgcsEg6jle82GhpsiT5hHyC7R2BlP2ZFknkAMg8orogOIhe0tYTIzMD6d2DQ==</ds:SignatureValue>
      </saml:SubjectConfirmationData>
             <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#"> </saml:SubjectConfirmation>
            <X509Data></saml:Subject>
            <saml:Conditions NotBefore="2020-12-07T09:01:39Z" NotOnOrAfter="2020-12-07T09:09:29Z">
   <!--  Certifikat som har signeret bootstraptokenet (her NemLog-in3 STS)  --><saml:AudienceRestriction>
                <X509Certificate>MIIGRTCCBS2gAwIBAgIEUw8DszANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSQwIgYDVQQDDBtUUlVTVDI0MDggU3lzdGVtdGVzdCBYSVggQ0EwHhcNMTQwNTA1MTMzNTU4WhcNMTcwNTA1MTMzNTEyWjCBljELMAkGA1UEBhMCREsxMTAvBgNVBAoMKERpZ2l0YWxpc2VyaW5nc3N0eXJlbHNlbiAvLyBDVlI6MzQwNTExNzgxVDAgBgNVBAUTGUNWUjozNDA1MTE3OC1VSUQ6ODMzODQ5NzAwMAYDVQQDDClEaWdpdGFsaXNlcmluZ3NzdHlyZWxzZW4gLSBOZW1Mb2ctaW4gVGVzdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALnCmDRMztjDckSupQBLcEzrRRJnAFxzEFdB7Cj6ApMQ<saml:Audience>https:/YxqKzfL/TSIr3v2mdgQNnsJGz91YbAteDPRHR/K1W3kqoIX/qH2uXDzHK+qi4YD9D8s4MnHAt02x6t0TgKQGjn1XO6lgLQ563DjtgD2fdPm9USV2Lkxe5ofNRG7yvWowBWjXKia8D64k6zSzoHKdPz6GCy9S0NmwIyJE0sJavcfwxT3/ia0g63/xD77SteT4H/OR/DLis7FLnfkLp8yrd5xAk4nEGizmjrg2OVJmIMMPK6PQdw+/lqSdgaPDxMD6yoIwWshux5Rup1+piMLg852odHR6EhUzjEsi9DnWWcCAwEAAaOCAucwggLjMA4GA1UdDwEB/wQEAwIEsDCBlwYIKwYBBQUHAQEEgYowgYcwPAYIKwYBBQUHMAGGMGh0dHA6Ly9vY3NwLnN5c3RlbXRlc3QxOS50cnVzdDI0MDguY29tL3Jlc3BvbmRlcjBHBggrBgEFBQcwAoY7aHR0cDovL3YuYWlhLnN5c3RlbXRlc3QxOS50cnVzdDI0MDguY29tL3N5c3RlbXRlc3QxOS1jYS5jZXIwggEgBgNVHSAEggEXMIIBEzCCAQ8GDSsGAQQBgfRRAgQGAwQwgf0wLwYIKwYBBQUHAgEWI2h0dHA6Ly93d3cudHJ1c3QyNDA4LmNvbS9yZXBvc2l0b3J5MIHJBggrBgEFBQcCAjCBvDAMFgVEYW5JRDADAgEBGoGrRGFuSUQgdGVzdCBjZXJ0aWZpa2F0ZXIgZnJhIGRlbm5lIENBIHVkc3RlZGVzIHVuZGVyIE9JRCAxLjMuNi4xLjQuMS4zMTMxMy4yLjQuNi4zLjQuIERhbklEIHRlc3QgY2VydGlmaWNhdGVzIGZyb20gdGhpcyBDQSBhcmUgaXNzdWVkIHVuZGVyIE9JRCAxLjMuNi4xLjQuMS4zMTMxMy4yLjQuNi4zLjQuMBwGA1UdEQQVMBOBEW5lbWxvZ2luQGRpZ3N0LmRrMIGpBgNVHR8EgaEwgZ4wPKA6oDiGNmh0dHA6Ly9jcmwuc3lzdGVtdGVzdDE5LnRydXN0MjQwOC5jb20vc3lzdGVtdGVzdDE5LmNybDBeoFygWqRYMFYxCzAJBgNVBAYTAkRLMRIwEAYDVQQKDAlUUlVTVDI0MDgxJDAiBgNVBAMMG1RSVVNUMjQwOCBTeXN0ZW10ZXN0IFhJWCBDQTENMAsGA1UEAwwEQ1JMMjAfBgNVHSMEGDAWgBTMAlUM5IF0ryBU1REUV5yRUjh/oDAdBgNVHQ4EFgQUwm9c3oUHE/zZ/43g4RUhswnMVAowCQYDVR0TBAIwADANBgkqhkiG9w0BAQsFAAOCAQEACLh3Ovvljv4b/Ywf/8WxoB2y50Oqt8rpwXZp+no4d5tLqIMTSAlQxL0lAf4Qm4e6tF5m/55+dLwxw5/Dqwa0bQXHt98vJjSBYLQH6rwfDzNmVGimO1n84k4MMYY449ykjqRNDfCS3+5+zV/An4CH9eUhvB0AHHWbD6eALw39sPGxc5kHADTOdJ5SboSm9DHYdLLt9k8HyxrHIkcJApLWPgyFmkE0+8jtuQQluN62F5+j5d53oTKinHEd7adM0ea537vNf5uBGu6h9OTXlhZwM9tlnrsTYQTTAIzdxGPlpD9Zvo5nmJHwILdRonm8rZf3vAm59/U6+Cht4+X2l5zxyg==</X509Certificate>
fmk</saml:Audience>
              </X509Data>
   saml:AudienceRestriction>
     </KeyInfo>
    </ds:Signature>
    <Subject></saml:Conditions>
        <!--   NameID indeholder<saml:AttributeStatement>
 en persistent UUID for borgeren  -->
        <NameID Format<saml:Attribute Name="dk:gov:saml:attribute:SpecVer" NameFormat="urn:oasis:names:tc:SAML:2.0:nameidattrname-format:persistent">https://data.gov.dk/model/core/eid/person/uuid/123e4567-e89b-12d3-a456-426655440000</NameID>
basic">
              <SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:holder-of-key">
  <saml:AttributeValue xsi:type="xs:string">DK-SAML-2.0</saml:AttributeValue>
             <SubjectConfirmationData xmlns:a="http://www.w3.org/2001/XMLSchema-instance" a:type="KeyInfoConfirmationDataType"> </saml:Attribute>
              <saml:Attribute  <KeyInfo xmlns="http://www.w3.org/2000/09/xmldsig#Name="dk:gov:saml:attribute:AssuranceLevel" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
                <saml:AttributeValue xsi:type="xs:string">3</saml:AttributeValue>
     <X509Data>
         </saml:Attribute>
              <saml:Attribute  <!--  Holder-of-key certifikatet - dvs. certifikat for det system/SOSI-STS-klient som kan veksle bootstraptokenet til et IDWS token  -->
Name="dk:gov:saml:attribute:CprNumberIdentifier" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
                <saml:AttributeValue xsi:type="xs:string">0501792275</saml:AttributeValue>
              </saml:Attribute>
              <saml:Attribute  <X509Certificate>MIIGIzCCBQugAwIBAgIEUw/NqTANBgkqhkiG9w0BAQsFADBHMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSQwIgYDVQQDDBtUUlVTVDI0MDggU3lzdGVtdGVzdCBYSVggQ0EwHhcNMTUwNDIwMDcyNTQyWhcNMTgwNDIwMDcyMzM3WjCBkTELMAkGA1UEBhMCREsxMTAvBgNVBAoMKERpZ2l0YWxpc2VyaW5nc3N0eXJlbHNlbiAvLyBDVlI6MzQwNTExNzgxTzAgBgNVBAUTGUNWUjozNDA1MTE3OC1GSUQ6NjkyMjEwNTAwKwYDVQQDDCRKYXZhIHJlZi4gVEVTVCAoZnVua3Rpb25zY2VydGlmaWthdCkwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCsZhc0L2r7+KF2FtqJxtBI/KKneBo6ojLQf8ZgaXa6eFK15lyI4nGM3xZ/OgC8/vjsw2XWQE08vL09W8SKiujEt6xs967Z/Y4rNl1S8hZa5TVmBTlOEwEbmIzGB8tckVj14KnZ6kcZGvygb8FT5gvMGpueMj3OzvhvkShfGvuG/9yrr8hj7590vu3X0EkeI5dQAFPG41sUqzjDMZhZol5zhHCqkxXf0C+H+1gYYvNvEYGc1WXfaK0j3i66RcKAWJvozgf6jDQfwHsV7qswndxbvIhoZ6W7cBxzs4ajDQ5QeHS5JtWKopgmz0hXgcgXChJ4ZVvyhpatXLuldJeINrlHAgMBAAGjggLKMIICxjAOBgNVHQ8BAf8EBAMCA7gwgZcGCCsGAQUFBwEBBIGKMIGHMDwGCCsGAQUFBzABhjBodHRwOi8vb2NzcC5zeXN0ZW10ZXN0MTkudHJ1c3QyNDA4LmNvbS9yZXNwb25kZXIwRwYIKwYBBQUHMAKGO2h0dHA6Ly9mLmFpYS5zeXN0ZW10ZXN0MTkudHJ1c3QyNDA4LmNvbS9zeXN0ZW10ZXN0MTktY2EuY2VyMIIBIAYDVR0gBIIBFzCCARMwggEPBg0rBgEEAYH0UQIEBgQCMIH9MC8GCCsGAQUFBwIBFiNodHRwOi8vd3d3LnRydXN0MjQwOC5jb20vcmVwb3NpdG9yeTCByQYIKwYBBQUHAgIwgbwwDBYFRGFuSUQwAwIBARqBq0RhbklEIHRlc3QgY2VydGlmaWthdGVyIGZyYSBkZW5uZSBDQSB1ZHN0ZWRlcyB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4yLiBEYW5JRCB0ZXN0IGNlcnRpZmljYXRlcyBmcm9tIHRoaXMgQ0EgYXJlIGlzc3VlZCB1bmRlciBPSUQgMS4zLjYuMS40LjEuMzEzMTMuMi40LjYuNC4yLjCBqgYDVR0fBIGiMIGfMDygOqA4hjZodHRwOi8vY3JsLnN5c3RlbXRlc3QxOS50cnVzdDI0MDguY29tL3N5c3RlbXRlc3QxOS5jcmwwX6BdoFukWTBXMQswCQYDVQQGEwJESzESMBAGA1UECgwJVFJVU1QyNDA4MSQwIgYDVQQDDBtUUlVTVDI0MDggU3lzdGVtdGVzdCBYSVggQ0ExDjAMBgNVBAMMBUNSTDI4MB8GA1UdIwQYMBaAFMwCVQzkgXSvIFTVERRXnJFSOH+gMB0GA1UdDgQWBBRUEhCFm3sj4tGyEI3OkBYnKKSOFDAJBgNVHRMEAjAAMA0GCSqGSIb3DQEBCwUAA4IBAQB9r7wKMTPCxGmQYFu7M+CyGrxSWaFqe8FH6YGyh9SaCjZUSbayamCqjhxM+7cLZtSBXySMYkcUImj5tWzED3BUIX6vbhzXvAsvyBuyXH9iRrBq3hLUOL18dBOMOY98TghF9jqJQBoq3Ikctob3/ikfpws86/jLnoKvA5q3IGYJIiwZssj85kcXmbhOpi1x9SjCRqgXldDVqiSEBVcuU8WKqvDVhIoFJzpsDbWvjeGnlgXtU0mK55tJYvm9i0leaoaAEKesRd2MdG9yZ4yhDFcvzUaTlQULvBxoNgXGPOGPxIEr2euiDhBcdrx/zbC8tjok6eBwu4FvGqyrpm11xjQs</X509Certificate>Name="dk:gov:saml:attribute:Privileges_intermediate" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:basic">
                    </X509Data><saml:AttributeValue xsi:type="xs:string">PD94bWwgdmVyc2lvbj0iMS4wIiBlbmNvZGluZz0iVVRGLTgiID8+PGJwcDpQcml2aWxlZ2VMaXN0IHhtbG5zOmJwcD0iaHR0cDovL2l0c3QuZGsvb2lvc2FtbC9iYXNpY19wcml2aWxlZ2VfcHJvZmlsZSI+PGJwcDpQcml2aWxlZ2VHcm91cCBTY29wZT0idXJuOmRrOmhlYWx0aGNhcmU6c2FtbDphY3RUaHJvdWdoUHJvY3VyYXRpb25CeTpjcHJOdW1iZXJJZGVudGlmaWVyOjAxMDE2MDMwNDAiPjxicHA6UHJpdmlsZWdlPnVybjpkazpuc3BvcDpzdHM6ZGR2OnJlYWQ8L2JwcDpQcml2aWxlZ2U+PGJwcDpQcml2aWxlZ2U+dXJuOmRrOm5zcG9wOnN0czpkZHY6d3JpdGU8L2JwcDpQcml2aWxlZ2U+PGJwcDpQcml2aWxlZ2U+dXJuOmRrOm5zcG9wOnN0czpmbWs6cmVhZDwvYnBwOlByaXZpbGVnZT48YnBwOlByaXZpbGVnZT51cm46ZGs6bnNwb3A6c3RzOmZtazp3cml0ZTwvYnBwOlByaXZpbGVnZT48L2JwcDpQcml2aWxlZ2VHcm91cD48L2JwcDpQcml2aWxlZ2VMaXN0Pg==</saml:AttributeValue>
                </KeyInfo>saml:Attribute>
            </SubjectConfirmationData>
        </SubjectConfirmation>
    </Subject>
    <Conditions NotOnOrAfter="2020-11-13T12:22:50.027Z">
saml:AttributeStatement>
          <!--/saml:Assertion>
      Aftageren som må omveksle dette bootstraptoken (her SOSI-STS'en)   -->
 </wst:RequestedSecurityToken>
        <wsp:AppliesTo>
          <AudienceRestriction><wsa:EndpointReference>
            <Audience>https<wsa:Address>https://sts.sosi.dk/</Audience>fmk</wsa:Address>
        </AudienceRestriction>
    </Conditions>
    <AttributeStatement>wsa:EndpointReference>
        <!--  Angivelse af profil og version (konstanten 'OIO-SAML-3.0')  -->/wsp:AppliesTo>
        <wst:Lifetime>
        <Attribute Name="https://data.gov.dk/model/core/specVersion" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri"> <wsu:Created>2020-12-07T09:01:39Z</wsu:Created>
            <AttributeValue>OIO-SAML-3.0</AttributeValue><wsu:Expires>2020-12-07T09:09:29Z</wsu:Expires>
        </Attribute>wst:Lifetime>
        <!--/wst:RequestSecurityTokenResponse>
  Sikringsniveau udtrykt efter NSIS  -->
        <Attribute Name="https://data.gov.dk/concept/core/nsis/loa" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <AttributeValue>Substantial</AttributeValue>
        </Attribute>
        <!--  borgerens CPR-nummer  -->
        <Attribute Name="https://data.gov.dk/model/core/eid/cprNumber" NameFormat="urn:oasis:names:tc:SAML:2.0:attrname-format:uri">
            <AttributeValue>1802602810</AttributeValue>
        </Attribute>
    </AttributeStatement>
</Assertion>

...

 </wst:RequestSecurityTokenResponseCollection>
  </soapenv:Body>
</soapenv:Envelope>

Bemærk returværdien fra STS, der indeholder attributten 'dk:gov:saml:attribute:Privileges_intermediate'. Værdien er base64 encoded. Efter en decode ser det således ud (bemærk, at strukturen både indeholder det CPR nummer, som borgeren ønsker at arbejde på vegne af samt listen af de privilegier, der rent faktisk er tildelt fra denne borger til den kaldende borger):

Code Block
languagexml
titleDecoded dk:gov:saml:attribute:Privileges_intermediate
collapsetrue
<?xml version="1.0" encoding="UTF-8"?>
<bpp:PrivilegeList xmlns:bpp="http://itst.dk/oiosaml/basic_privilege_profile">
  <bpp:PrivilegeGroup Scope="urn:dk:healthcare:saml:actThroughProcurationBy:cprNumberIdentifier:0101603040">
    <bpp:Privilege>urn:dk:nspop:sts:ddv:read</bpp:Privilege>
    <bpp:Privilege>urn:dk:nspop:sts:ddv:write</bpp:Privilege>
    <bpp:Privilege>urn:dk:nspop:sts:fmk:read</bpp:Privilege>
    <bpp:Privilege>urn:dk:nspop:sts:fmk:write</bpp:Privilege>
  </bpp:PrivilegeGroup>
</bpp:PrivilegeList>

 Eksempel: Omveksling af borger JWT token til IDWS token