The following content has been modified for better visualization. Validation will be performed on original content
| 1 |
<env:Envelope xmlns:env="http://www.w3.org/2003/05/soap-envelope">
|
| 2 |
<env:Header>
|
| 3 |
<wsa:MessageID xmlns:wsa="http://www.w3.org/2005/08/addressing">mid:14d1985e-68aa-d141-d896-0242ac120009@250f0ad8b24a</wsa:MessageID>
|
| 4 |
<wsa:Action xmlns:wsa="http://www.w3.org/2005/08/addressing" env:mustUnderstand="true">http://docs.oasis-open.org/ws-sx/ws-trust/200512/RST/Issue</wsa:Action>
|
| 5 |
<wsa:To xmlns:wsa="http://www.w3.org/2005/08/addressing">https://example.com/sts</wsa:To>
|
| 6 |
<wsse:Security xmlns:wsse="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-secext-1.0.xsd" env:mustUnderstand="true">
|
| 7 |
<wsu:Timestamp xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd">
|
| 8 |
<wsu:Created>2024-03-05T15:25:15.781Z</wsu:Created>
|
| 9 |
<wsu:Expires>2024-03-05T15:40:15.783Z</wsu:Expires>
|
| 10 |
</wsu:Timestamp>
|
| 11 |
<saml:Assertion xmlns:saml="urn:oasis:names:tc:SAML:2.0:assertion" xmlns:wsu="http://docs.oasis-open.org/wss/2004/01/oasis-200401-wss-wssecurity-utility-1.0.xsd" ID="TQuY+roX" IssueInstant="2024-03-05T15:25:15.789Z" Version="2.0" wsu:Id="TQuY+roX">
|
| 12 |
<saml:Issuer>urn:oid:1.3.6.1.4.1.59990.1.2</saml:Issuer>
|
| 13 |
<dsig:Signature xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
|
| 14 |
<dsig:SignedInfo>
|
| 15 |
<dsig:CanonicalizationMethod Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
|
| 16 |
<dsig:SignatureMethod Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256"/>
|
| 17 |
<dsig:Reference URI="#TQuY+roX">
|
| 18 |
<dsig:Transforms>
|
| 19 |
<dsig:Transform Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature"/>
|
| 20 |
<dsig:Transform Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#"/>
|
| 21 |
</dsig:Transforms>
|
| 22 |
<dsig:DigestMethod Algorithm="http://www.w3.org/2001/04/xmlenc#sha256"/>
|
| 23 |
<dsig:DigestValue>4/j/ViqSt9l/rPkcqw1sObW8FwVJpIhrYbHs5i9EMsU=</dsig:DigestValue>
|
| 24 |
</dsig:Reference>
|
| 25 |
</dsig:SignedInfo>
|
| 26 |
<dsig:SignatureValue>O3Fd5s6iYCPiqJNQ4XNDqIP1pE4c+NknF36RufBQDj2OW5Uoi0QOCZvyrCLw5VNjF9Ik7Xxg4UCWsj5YP2hDxK+9zKcNLGfmKCbIM6pvwrtX2ZyNzjn6IBLBAzE9CSrKXZX9fa2rf3gGyhTzcbq1aEDqec7XH5tQkTu07piszceLOTEWrgoTXZxBr9qDuoOzX3aMlcsRaWyjPI3B3xoQHTBrsvKmgf5mcYvMMHdNNGa2K9LV5ehJPepAZRpd+MHERYF+uH2yzxiHKA0uLkc7lURCl5g1VRpDnHQyDqyKns2x0k6N23dUjjITxCcIz6ypP7LxG0J0bsJI84T6xuOR3w==</dsig:SignatureValue>
|
| 27 |
<dsig:KeyInfo>
|
| 28 |
<dsig:X509Data>
|
| 29 |
<dsig:X509Certificate>MIIDdzCCAl+gAwIBAgIBATANBgkqhkiG9w0BAQsFADA2MTQwMgYDVQQDEythY2NlcHRhdGllLXNpZ24tem9yZ3BsYXRmb3JtLmJhc3Rpb24zNjUubmV0MCIYDzIwMjQwMzA1MTE1NTA4WhgPMjAyNzAzMDUxMTU1MDhaMDYxNDAyBgNVBAMTK2FjY2VwdGF0aWUtc2lnbi16b3JncGxhdGZvcm0uYmFzdGlvbjM2NS5uZXQwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCrPy0ncqvNjlOpHvGgUr2bZJryVX/q2vn9tMG5RQOrIKZxpJ3YREjg6U+1LPut6gIGNl6lgNpgnONhEJCDXocfNm5uV7eZtx/luUP4WpPVtvXHQ66qet4L7xD1FgGsE8/Dtcg+R4Rq4Dkwh5fdBYz9vQG61cqCJ+HFUVkYwFp56BZJ7R2UjDSIoEuGDnqyIElimU70DLauKkbw3JKXDzGPcvtEctXAYz+qwKF03rWn310NAkc1G3JZAmY5hH8x/x/HeKbidpWDM0GlrDuAvO6uIpnNdYWbdlheJKM5pZ87cMh1sM1pTH4j0NAA6LUXgEMSTAsv58pFfYvT604X2E83AgMBAAGjgYswgYgwDgYDVR0PAQH/BAQDAgWgMB0GA1UdDgQWBBQaBF664iYZVB+QbWwBulQnRTYrNTAfBgNVHSMEGDAWgBQaBF664iYZVB+QbWwBulQnRTYrNTA2BgNVHREELzAtgithY2NlcHRhdGllLXNpZ24tem9yZ3BsYXRmb3JtLmJhc3Rpb24zNjUubmV0MA0GCSqGSIb3DQEBCwUAA4IBAQAj5v1cPgdUwnvkVAlm3j75Izn6xVLH4Y2Q9FF9wH4jSoLVvwoEdmp/JAj3AwePwLfcjSdcO3tzECIVCd15sO07vaLMLjc2Maiku6iHriOW8NF+bAaa4b1Xyh3BasbMEY24nSLkPsjQ1yA1eIp9YSPz/f9DJeGSiTHrwyh0UQxyNBG5IkZHPfCvO7K0rZWMnwk6DI1AB6J/goW4R1FHMPwfxQkJqbrYdKl+e844JuC31+4Od6FK8IVwdx53FRCWv9P6pItphDUeYmd6Am20s/o/DYHSwv/R3CNJAmai7LaruP94M2QXqhMyzVxBlw84sJ+VM1ZJBmTtR5Fu2Lw8rwg3</dsig:X509Certificate>
|
| 30 |
</dsig:X509Data>
|
| 31 |
</dsig:KeyInfo>
|
| 32 |
</dsig:Signature>
|
| 33 |
<saml:Subject>
|
| 34 |
<saml:NameID>urn:oid:1.3.6.1.4.1.59990.1.2</saml:NameID>
|
| 35 |
<saml:SubjectConfirmation Method="urn:oasis:names:tc:SAML:2.0:cm:bearer"/>
|
| 36 |
</saml:Subject>
|
| 37 |
<saml:Conditions NotBefore="2024-03-05T15:25:15.789Z" NotOnOrAfter="2024-03-05T15:40:15.789Z">
|
| 38 |
<saml:AudienceRestriction>
|
| 39 |
<saml:Audience>https://example.com</saml:Audience>
|
| 40 |
</saml:AudienceRestriction>
|
| 41 |
</saml:Conditions>
|
| 42 |
<saml:AttributeStatement>
|
| 43 |
<saml:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:purposeofuse">
|
| 44 |
<saml:AttributeValue>
|
| 45 |
<PurposeOfUse xmlns="urn:hl7-org:v3" code="OPERATIONS" codeSystem="2.16.840.1.113883.3.18.7.1" codeSystemName="nhin-purpose" displayName=""/>
|
| 46 |
</saml:AttributeValue>
|
| 47 |
</saml:Attribute>
|
| 48 |
<saml:Attribute Name="urn:oasis:names:tc:xacml:2.0:subject:role">
|
| 49 |
<saml:AttributeValue>
|
| 50 |
<Role xmlns="urn:hl7-org:v3" code="182777000" codeSystem="2.16.840.1.113883.6.96" codeSystemName="SNOMED_CT" displayName=""/>
|
| 51 |
</saml:AttributeValue>
|
| 52 |
</saml:Attribute>
|
| 53 |
<saml:Attribute Name="urn:oasis:names:tc:xacml:1.0:resource:resource-id">
|
| 54 |
<saml:AttributeValue>
|
| 55 |
<InstanceIdentifier xmlns="urn:hl7-org:v3" extension="999999205" root="2.16.840.1.113883.2.4.6.3"/>
|
| 56 |
</saml:AttributeValue>
|
| 57 |
</saml:Attribute>
|
| 58 |
<saml:Attribute Name="urn:oasis:names:tc:xspa:1.0:subject:organization-id">
|
| 59 |
<saml:AttributeValue>urn:oid:1.3.6.1.4.1.59990.1.2</saml:AttributeValue>
|
| 60 |
</saml:Attribute>
|
| 61 |
</saml:AttributeStatement>
|
| 62 |
</saml:Assertion>
|
| 63 |
</wsse:Security>
|
| 64 |
</env:Header>
|
| 65 |
<env:Body>
|
| 66 |
<wst:RequestSecurityToken xmlns:wst="http://docs.oasis-open.org/ws-sx/ws-trust/200512">
|
| 67 |
<wst:RequestType>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Issue</wst:RequestType>
|
| 68 |
<wsp:AppliesTo xmlns:wsp="http://www.w3.org/ns/ws-policy">
|
| 69 |
<wsa:EndpointReference xmlns:wsa="http://www.w3.org/2005/08/addressing">
|
| 70 |
<wsa:Address>https://example.com</wsa:Address>
|
| 71 |
</wsa:EndpointReference>
|
| 72 |
</wsp:AppliesTo>
|
| 73 |
<wst:TokenType>http://docs.oasis-open.org/wss/oasis-wss-saml-token-profile-1.1#SAMLV2.0</wst:TokenType>
|
| 74 |
<wst:KeyType>http://docs.oasis-open.org/ws-sx/ws-trust/200512/Bearer</wst:KeyType>
|
| 75 |
</wst:RequestSecurityToken>
|
| 76 |
</env:Body>
|
| 77 |
</env:Envelope>
|