SAML 2.0 IdP metadata
Her er metadata som SimpleSAMLphp har generert for deg. Du må utveksle metadata med de partene du stoler på for å sette opp en føderasjon.
Du kan nå metadata i XML-format på en dedikert URL:
https://personale.idp.indire.it/saml2/idp/metadata.php
Metadata
I SAML 2.0 Metadata XML Format:
<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://personale.idp.indire.it/saml2/idp/metadata.php">
<md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIID3zCCAsegAwIBAgIJANd8FzRLfm5bMA0GCSqGSIb3DQEBCwUAMIGFMQswCQYDVQQGEwJJVDELMAkGA1UECAwCRkkxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEMMAoGA1UECwwDQ0VEMRYwFAYDVQQDDA1pZHAuaW5kaXJlLml0MSAwHgYJKoZIhvcNAQkBFhFhLnJvbmNhQGluZGlyZS5pdDAeFw0xNTA0MDExMTA0MzJaFw0yNTAzMzExMTA0MzJaMIGFMQswCQYDVQQGEwJJVDELMAkGA1UECAwCRkkxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEMMAoGA1UECwwDQ0VEMRYwFAYDVQQDDA1pZHAuaW5kaXJlLml0MSAwHgYJKoZIhvcNAQkBFhFhLnJvbmNhQGluZGlyZS5pdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJ0t/1yvnWbcCNCn8d4CaZ1HegH2lbaXf2c1JmAuMnPiXoXZaElX+qX7pJq5KQ8JsswlRGqij5vgFMcgP6/ckBL7hMn57lUlmpXOq9pRTlf0qcOr7XQU7iS1miOi48PXrONu4CFltoxn6TsKJDkOzgGkjc1s2HVchaJ5KqDAprsCd+D9CmH3SC8l7F+3yc3m3yb943CnhrmWzmkL3ItFYareMxQa/Gf4ZdnlFuD7JyzUUHqGLq3xxS1F6raq+Gz678WFEqgnFuTGZVFY8UnM7JMUe4xlsm9a0aoiivZ/fU+mstJV3RFN1ERGy0KIrOBtEsnV1KJcWWsJdDzK4iz1OnMCAwEAAaNQME4wHQYDVR0OBBYEFGrLiW7wOoCFfd1dyETheDKVhfOLMB8GA1UdIwQYMBaAFGrLiW7wOoCFfd1dyETheDKVhfOLMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBADIO1kI9DCEC5pr7vG1gCAiwY1QuLUIvrKowTNd6dlGtFmVrQgxTnw9E50PdG1y4TzL6BMYlX3M/EtFfD9RtzzzJuJLJVzTI4+/4We9ZhNrvL+eOSb2BhkVEtaD0hPY0tWdFy8Z/iaOF4Bk5RiATKaJw0P9MCXY7srnocDyPk8EwRJTWNXUTFjjsFJYTPZIT4hszC5V1wN99xXTFs6cpHUfPHd1B5B53pKNgPQ6lw+ZDcfiSy4VsyFBSliwHeckhxJQEKRwSLK5JqdhaPGaUSNBS3vsZO7WAVVG/nth/crLUp8fDXcmNr9/DJBrJOfEG6+1/AQZqWR5SDJq+Tenw01w=</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIID3zCCAsegAwIBAgIJANd8FzRLfm5bMA0GCSqGSIb3DQEBCwUAMIGFMQswCQYDVQQGEwJJVDELMAkGA1UECAwCRkkxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEMMAoGA1UECwwDQ0VEMRYwFAYDVQQDDA1pZHAuaW5kaXJlLml0MSAwHgYJKoZIhvcNAQkBFhFhLnJvbmNhQGluZGlyZS5pdDAeFw0xNTA0MDExMTA0MzJaFw0yNTAzMzExMTA0MzJaMIGFMQswCQYDVQQGEwJJVDELMAkGA1UECAwCRkkxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEMMAoGA1UECwwDQ0VEMRYwFAYDVQQDDA1pZHAuaW5kaXJlLml0MSAwHgYJKoZIhvcNAQkBFhFhLnJvbmNhQGluZGlyZS5pdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJ0t/1yvnWbcCNCn8d4CaZ1HegH2lbaXf2c1JmAuMnPiXoXZaElX+qX7pJq5KQ8JsswlRGqij5vgFMcgP6/ckBL7hMn57lUlmpXOq9pRTlf0qcOr7XQU7iS1miOi48PXrONu4CFltoxn6TsKJDkOzgGkjc1s2HVchaJ5KqDAprsCd+D9CmH3SC8l7F+3yc3m3yb943CnhrmWzmkL3ItFYareMxQa/Gf4ZdnlFuD7JyzUUHqGLq3xxS1F6raq+Gz678WFEqgnFuTGZVFY8UnM7JMUe4xlsm9a0aoiivZ/fU+mstJV3RFN1ERGy0KIrOBtEsnV1KJcWWsJdDzK4iz1OnMCAwEAAaNQME4wHQYDVR0OBBYEFGrLiW7wOoCFfd1dyETheDKVhfOLMB8GA1UdIwQYMBaAFGrLiW7wOoCFfd1dyETheDKVhfOLMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBADIO1kI9DCEC5pr7vG1gCAiwY1QuLUIvrKowTNd6dlGtFmVrQgxTnw9E50PdG1y4TzL6BMYlX3M/EtFfD9RtzzzJuJLJVzTI4+/4We9ZhNrvL+eOSb2BhkVEtaD0hPY0tWdFy8Z/iaOF4Bk5RiATKaJw0P9MCXY7srnocDyPk8EwRJTWNXUTFjjsFJYTPZIT4hszC5V1wN99xXTFs6cpHUfPHd1B5B53pKNgPQ6lw+ZDcfiSy4VsyFBSliwHeckhxJQEKRwSLK5JqdhaPGaUSNBS3vsZO7WAVVG/nth/crLUp8fDXcmNr9/DJBrJOfEG6+1/AQZqWR5SDJq+Tenw01w=</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://personale.idp.indire.it/saml2/idp/SingleLogoutService.php"/>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://personale.idp.indire.it/saml2/idp/SSOService.php"/>
</md:IDPSSODescriptor>
<md:ContactPerson contactType="technical">
<md:GivenName>Administrator</md:GivenName>
<md:EmailAddress>mailto:a.ronca@indire.it</md:EmailAddress>
</md:ContactPerson>
</md:EntityDescriptor>
I SimpleSAMLphp format - bruk denne dersom du benytter SimpleSAMLphp i den andre enden:
$metadata['https://personale.idp.indire.it/saml2/idp/metadata.php'] = array (
'metadata-set' => 'saml20-idp-remote',
'entityid' => 'https://personale.idp.indire.it/saml2/idp/metadata.php',
'SingleSignOnService' =>
array (
0 =>
array (
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://personale.idp.indire.it/saml2/idp/SSOService.php',
),
),
'SingleLogoutService' =>
array (
0 =>
array (
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://personale.idp.indire.it/saml2/idp/SingleLogoutService.php',
),
),
'certData' => 'MIID3zCCAsegAwIBAgIJANd8FzRLfm5bMA0GCSqGSIb3DQEBCwUAMIGFMQswCQYDVQQGEwJJVDELMAkGA1UECAwCRkkxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEMMAoGA1UECwwDQ0VEMRYwFAYDVQQDDA1pZHAuaW5kaXJlLml0MSAwHgYJKoZIhvcNAQkBFhFhLnJvbmNhQGluZGlyZS5pdDAeFw0xNTA0MDExMTA0MzJaFw0yNTAzMzExMTA0MzJaMIGFMQswCQYDVQQGEwJJVDELMAkGA1UECAwCRkkxEDAOBgNVBAcMB0ZpcmVuemUxDzANBgNVBAoMBklORElSRTEMMAoGA1UECwwDQ0VEMRYwFAYDVQQDDA1pZHAuaW5kaXJlLml0MSAwHgYJKoZIhvcNAQkBFhFhLnJvbmNhQGluZGlyZS5pdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAJ0t/1yvnWbcCNCn8d4CaZ1HegH2lbaXf2c1JmAuMnPiXoXZaElX+qX7pJq5KQ8JsswlRGqij5vgFMcgP6/ckBL7hMn57lUlmpXOq9pRTlf0qcOr7XQU7iS1miOi48PXrONu4CFltoxn6TsKJDkOzgGkjc1s2HVchaJ5KqDAprsCd+D9CmH3SC8l7F+3yc3m3yb943CnhrmWzmkL3ItFYareMxQa/Gf4ZdnlFuD7JyzUUHqGLq3xxS1F6raq+Gz678WFEqgnFuTGZVFY8UnM7JMUe4xlsm9a0aoiivZ/fU+mstJV3RFN1ERGy0KIrOBtEsnV1KJcWWsJdDzK4iz1OnMCAwEAAaNQME4wHQYDVR0OBBYEFGrLiW7wOoCFfd1dyETheDKVhfOLMB8GA1UdIwQYMBaAFGrLiW7wOoCFfd1dyETheDKVhfOLMAwGA1UdEwQFMAMBAf8wDQYJKoZIhvcNAQELBQADggEBADIO1kI9DCEC5pr7vG1gCAiwY1QuLUIvrKowTNd6dlGtFmVrQgxTnw9E50PdG1y4TzL6BMYlX3M/EtFfD9RtzzzJuJLJVzTI4+/4We9ZhNrvL+eOSb2BhkVEtaD0hPY0tWdFy8Z/iaOF4Bk5RiATKaJw0P9MCXY7srnocDyPk8EwRJTWNXUTFjjsFJYTPZIT4hszC5V1wN99xXTFs6cpHUfPHd1B5B53pKNgPQ6lw+ZDcfiSy4VsyFBSliwHeckhxJQEKRwSLK5JqdhaPGaUSNBS3vsZO7WAVVG/nth/crLUp8fDXcmNr9/DJBrJOfEG6+1/AQZqWR5SDJq+Tenw01w=',
'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient',
'contacts' =>
array (
0 =>
array (
'emailAddress' => 'a.ronca@indire.it',
'contactType' => 'technical',
'givenName' => 'Administrator',
),
),
);
Sertifikater
Last ned X509-sertifikatene som PEM-filer.