SAML 2.0 IdP metadata
Her er metadata som SimpleSAMLphp har generert for deg. Du må utveksle metadata med de partene du stoler på for å sette opp en føderasjon.
Du kan nå metadata i XML-format på en dedikert URL:
https://testidp.piemmeidea.it/jtsaml/saml2/idp/metadata.php
Metadata
I SAML 2.0 Metadata XML Format:
<?xml version="1.0"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://testidp.piemmeidea.it/jtsaml/saml2/idp/metadata.php">
<md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
<md:KeyDescriptor use="signing">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIFzTCCA7WgAwIBAgIJAOkWTiAhPoOlMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNVBAYTAklUMREwDwYDVQQIDAhQaWFjZW56YTELMAkGA1UEBwwCUEMxGzAZBgNVBAoMEkpvaW50IFRlY2hub2xvZ2llczERMA8GA1UECwwIVEVTVCBJRFAxHjAcBgNVBAMMFXRlc3RpZHAucGllbW1laWRlYS5pdDAeFw0yMTA2MDMxMzUzNDJaFw0zMTA2MDExMzUzNDJaMH0xCzAJBgNVBAYTAklUMREwDwYDVQQIDAhQaWFjZW56YTELMAkGA1UEBwwCUEMxGzAZBgNVBAoMEkpvaW50IFRlY2hub2xvZ2llczERMA8GA1UECwwIVEVTVCBJRFAxHjAcBgNVBAMMFXRlc3RpZHAucGllbW1laWRlYS5pdDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANFJavquxDM8NHOhaYOgz5C2Y3c4mVdA80FOPrJEpQviERNmOePGpmt5kT44AJ3SLB0Hb7e74BtEShA28HqqqDmM4wofy8+w6LwEGH1og8IzMA9SCq8DoBt7hcsX9e1zzK8TOU3v+bcAlhJL/SSjez8leoogdHXd0+OB9Hz8xuoWoFrK+4XSgv+AJk9tBt298CNtYh1o5EUGWYn4esw1GIbOtjsY2hnVW7/bdPURolJZAyfyij0wzsq0Vs65ZqvgEK+yglvt14RFfFe5x+bMYSj8x42nYXC2NjvBUsowinUAIamJRLgbaDywmJRie3FPp4Zg6E4u2dtJDnrYAZqlP3y14jZrvI+Cx9uzLcC4iGakEiAxMOTp5A8dILb2W/180YKZ6PG/odtb1p8symGqTmRNW9gOiaoEfvcazzwJ7LuG5YoNhC1xNM55mMHlAP6jNzfaydlCTC49YwvSqc4eqbXXo10X4bdOli8hH1sXMOdagOO1esJWzIwnhaH1IZDgTuFrN+gikvMoMUW0/esbej72cRvgWKIBwcLGYJuLF869ZbwDCyGe38m1giOtWSHfsHAC9kzgyo+YuMoNuwTkQkYnf1d14kNBuuRPc2cfKjTHAb/gdx4XFkykJ2Ger7ksFxpIujmQSAIeLrQTYTpad1slXttmUPYH/ZtEsHQAYqiHAgMBAAGjUDBOMB0GA1UdDgQWBBTpRjUIClMpTFY/ZS0XfPlL4emtejAfBgNVHSMEGDAWgBTpRjUIClMpTFY/ZS0XfPlL4emtejAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4ICAQAI0pZu1v5uHZ2CCtw5j07msVNmLOKM9juv1QMsgk+n7EwFUp5C8CgM7jhJSlO6QPJQcbLqqNOCQie0xQAAeUDZrGsCrH92AwMC6ANkTkJ0oAlXlDIpFdI00F/5qtugtIshekELrEY16GSfULRf9MB27tHSGG2x0BIVMsLamOhD31IdQnMjr48rvpUA+AOMdof48LgG1U+Fn5jlY6DgKYplFGxo2cN3lVFzQZCsXAzr5tJxcBVZpxhj7cL7luLTDowuwCSI/P03ATedNrreDbFBN6fG5HQbS0Hh3JJ9Tzn0QcrYuTP774CoatkwqebOI+2zwSx0wFkVCeAQ0UZ4/EQ07hzgUUa8yMVFqyabx+P/frGcGv70dY6cNUdQib+D6ie5hNLIEWrSpiCAAh5Thf7tETVH88Pts7QfAssClmPqBOrmCqzv/KLJC5uCSSDKlnH/n1dvHw27ZWKB4kEEJeFWbUFzO1LLl6GhzfASxBT3knasGvaFQERn5duAhrkH86NNKAz3IJoJAi2gjHTS4Dy18CinvBK/xDqNDuTYAqLDIffEOXWn2ooqvhtFnMUKU9T/Na/wGqQ+RaZ24QAfn7QnxJtZht37TkM79TkZwHbFis0UDPe6DViI9J4s+/5WmOimtbYN68xaZxqezG6Eg6aBCDq5V3aJ+H51ORstMzSEjg==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:KeyDescriptor use="encryption">
<ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
<ds:X509Data>
<ds:X509Certificate>MIIFzTCCA7WgAwIBAgIJAOkWTiAhPoOlMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNVBAYTAklUMREwDwYDVQQIDAhQaWFjZW56YTELMAkGA1UEBwwCUEMxGzAZBgNVBAoMEkpvaW50IFRlY2hub2xvZ2llczERMA8GA1UECwwIVEVTVCBJRFAxHjAcBgNVBAMMFXRlc3RpZHAucGllbW1laWRlYS5pdDAeFw0yMTA2MDMxMzUzNDJaFw0zMTA2MDExMzUzNDJaMH0xCzAJBgNVBAYTAklUMREwDwYDVQQIDAhQaWFjZW56YTELMAkGA1UEBwwCUEMxGzAZBgNVBAoMEkpvaW50IFRlY2hub2xvZ2llczERMA8GA1UECwwIVEVTVCBJRFAxHjAcBgNVBAMMFXRlc3RpZHAucGllbW1laWRlYS5pdDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANFJavquxDM8NHOhaYOgz5C2Y3c4mVdA80FOPrJEpQviERNmOePGpmt5kT44AJ3SLB0Hb7e74BtEShA28HqqqDmM4wofy8+w6LwEGH1og8IzMA9SCq8DoBt7hcsX9e1zzK8TOU3v+bcAlhJL/SSjez8leoogdHXd0+OB9Hz8xuoWoFrK+4XSgv+AJk9tBt298CNtYh1o5EUGWYn4esw1GIbOtjsY2hnVW7/bdPURolJZAyfyij0wzsq0Vs65ZqvgEK+yglvt14RFfFe5x+bMYSj8x42nYXC2NjvBUsowinUAIamJRLgbaDywmJRie3FPp4Zg6E4u2dtJDnrYAZqlP3y14jZrvI+Cx9uzLcC4iGakEiAxMOTp5A8dILb2W/180YKZ6PG/odtb1p8symGqTmRNW9gOiaoEfvcazzwJ7LuG5YoNhC1xNM55mMHlAP6jNzfaydlCTC49YwvSqc4eqbXXo10X4bdOli8hH1sXMOdagOO1esJWzIwnhaH1IZDgTuFrN+gikvMoMUW0/esbej72cRvgWKIBwcLGYJuLF869ZbwDCyGe38m1giOtWSHfsHAC9kzgyo+YuMoNuwTkQkYnf1d14kNBuuRPc2cfKjTHAb/gdx4XFkykJ2Ger7ksFxpIujmQSAIeLrQTYTpad1slXttmUPYH/ZtEsHQAYqiHAgMBAAGjUDBOMB0GA1UdDgQWBBTpRjUIClMpTFY/ZS0XfPlL4emtejAfBgNVHSMEGDAWgBTpRjUIClMpTFY/ZS0XfPlL4emtejAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4ICAQAI0pZu1v5uHZ2CCtw5j07msVNmLOKM9juv1QMsgk+n7EwFUp5C8CgM7jhJSlO6QPJQcbLqqNOCQie0xQAAeUDZrGsCrH92AwMC6ANkTkJ0oAlXlDIpFdI00F/5qtugtIshekELrEY16GSfULRf9MB27tHSGG2x0BIVMsLamOhD31IdQnMjr48rvpUA+AOMdof48LgG1U+Fn5jlY6DgKYplFGxo2cN3lVFzQZCsXAzr5tJxcBVZpxhj7cL7luLTDowuwCSI/P03ATedNrreDbFBN6fG5HQbS0Hh3JJ9Tzn0QcrYuTP774CoatkwqebOI+2zwSx0wFkVCeAQ0UZ4/EQ07hzgUUa8yMVFqyabx+P/frGcGv70dY6cNUdQib+D6ie5hNLIEWrSpiCAAh5Thf7tETVH88Pts7QfAssClmPqBOrmCqzv/KLJC5uCSSDKlnH/n1dvHw27ZWKB4kEEJeFWbUFzO1LLl6GhzfASxBT3knasGvaFQERn5duAhrkH86NNKAz3IJoJAi2gjHTS4Dy18CinvBK/xDqNDuTYAqLDIffEOXWn2ooqvhtFnMUKU9T/Na/wGqQ+RaZ24QAfn7QnxJtZht37TkM79TkZwHbFis0UDPe6DViI9J4s+/5WmOimtbYN68xaZxqezG6Eg6aBCDq5V3aJ+H51ORstMzSEjg==</ds:X509Certificate>
</ds:X509Data>
</ds:KeyInfo>
</md:KeyDescriptor>
<md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://testidp.piemmeidea.it/jtsaml/saml2/idp/SingleLogoutService.php"/>
<md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat>
<md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://testidp.piemmeidea.it/jtsaml/saml2/idp/SSOService.php"/>
</md:IDPSSODescriptor>
</md:EntityDescriptor>
I SimpleSAMLphp format - bruk denne dersom du benytter SimpleSAMLphp i den andre enden:
$metadata['https://testidp.piemmeidea.it/jtsaml/saml2/idp/metadata.php'] = [
'metadata-set' => 'saml20-idp-remote',
'entityid' => 'https://testidp.piemmeidea.it/jtsaml/saml2/idp/metadata.php',
'SingleSignOnService' => [
[
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://testidp.piemmeidea.it/jtsaml/saml2/idp/SSOService.php',
],
],
'SingleLogoutService' => [
[
'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
'Location' => 'https://testidp.piemmeidea.it/jtsaml/saml2/idp/SingleLogoutService.php',
],
],
'certData' => 'MIIFzTCCA7WgAwIBAgIJAOkWTiAhPoOlMA0GCSqGSIb3DQEBCwUAMH0xCzAJBgNVBAYTAklUMREwDwYDVQQIDAhQaWFjZW56YTELMAkGA1UEBwwCUEMxGzAZBgNVBAoMEkpvaW50IFRlY2hub2xvZ2llczERMA8GA1UECwwIVEVTVCBJRFAxHjAcBgNVBAMMFXRlc3RpZHAucGllbW1laWRlYS5pdDAeFw0yMTA2MDMxMzUzNDJaFw0zMTA2MDExMzUzNDJaMH0xCzAJBgNVBAYTAklUMREwDwYDVQQIDAhQaWFjZW56YTELMAkGA1UEBwwCUEMxGzAZBgNVBAoMEkpvaW50IFRlY2hub2xvZ2llczERMA8GA1UECwwIVEVTVCBJRFAxHjAcBgNVBAMMFXRlc3RpZHAucGllbW1laWRlYS5pdDCCAiIwDQYJKoZIhvcNAQEBBQADggIPADCCAgoCggIBANFJavquxDM8NHOhaYOgz5C2Y3c4mVdA80FOPrJEpQviERNmOePGpmt5kT44AJ3SLB0Hb7e74BtEShA28HqqqDmM4wofy8+w6LwEGH1og8IzMA9SCq8DoBt7hcsX9e1zzK8TOU3v+bcAlhJL/SSjez8leoogdHXd0+OB9Hz8xuoWoFrK+4XSgv+AJk9tBt298CNtYh1o5EUGWYn4esw1GIbOtjsY2hnVW7/bdPURolJZAyfyij0wzsq0Vs65ZqvgEK+yglvt14RFfFe5x+bMYSj8x42nYXC2NjvBUsowinUAIamJRLgbaDywmJRie3FPp4Zg6E4u2dtJDnrYAZqlP3y14jZrvI+Cx9uzLcC4iGakEiAxMOTp5A8dILb2W/180YKZ6PG/odtb1p8symGqTmRNW9gOiaoEfvcazzwJ7LuG5YoNhC1xNM55mMHlAP6jNzfaydlCTC49YwvSqc4eqbXXo10X4bdOli8hH1sXMOdagOO1esJWzIwnhaH1IZDgTuFrN+gikvMoMUW0/esbej72cRvgWKIBwcLGYJuLF869ZbwDCyGe38m1giOtWSHfsHAC9kzgyo+YuMoNuwTkQkYnf1d14kNBuuRPc2cfKjTHAb/gdx4XFkykJ2Ger7ksFxpIujmQSAIeLrQTYTpad1slXttmUPYH/ZtEsHQAYqiHAgMBAAGjUDBOMB0GA1UdDgQWBBTpRjUIClMpTFY/ZS0XfPlL4emtejAfBgNVHSMEGDAWgBTpRjUIClMpTFY/ZS0XfPlL4emtejAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBCwUAA4ICAQAI0pZu1v5uHZ2CCtw5j07msVNmLOKM9juv1QMsgk+n7EwFUp5C8CgM7jhJSlO6QPJQcbLqqNOCQie0xQAAeUDZrGsCrH92AwMC6ANkTkJ0oAlXlDIpFdI00F/5qtugtIshekELrEY16GSfULRf9MB27tHSGG2x0BIVMsLamOhD31IdQnMjr48rvpUA+AOMdof48LgG1U+Fn5jlY6DgKYplFGxo2cN3lVFzQZCsXAzr5tJxcBVZpxhj7cL7luLTDowuwCSI/P03ATedNrreDbFBN6fG5HQbS0Hh3JJ9Tzn0QcrYuTP774CoatkwqebOI+2zwSx0wFkVCeAQ0UZ4/EQ07hzgUUa8yMVFqyabx+P/frGcGv70dY6cNUdQib+D6ie5hNLIEWrSpiCAAh5Thf7tETVH88Pts7QfAssClmPqBOrmCqzv/KLJC5uCSSDKlnH/n1dvHw27ZWKB4kEEJeFWbUFzO1LLl6GhzfASxBT3knasGvaFQERn5duAhrkH86NNKAz3IJoJAi2gjHTS4Dy18CinvBK/xDqNDuTYAqLDIffEOXWn2ooqvhtFnMUKU9T/Na/wGqQ+RaZ24QAfn7QnxJtZht37TkM79TkZwHbFis0UDPe6DViI9J4s+/5WmOimtbYN68xaZxqezG6Eg6aBCDq5V3aJ+H51ORstMzSEjg==',
'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient',
];
Sertifikater
Last ned X509-sertifikatene som PEM-filer.