SAML 2.0 IdP Metadata
SimpleSAMLphp har har genererat följande metadata. För att sätta upp en betrodd federation kan du skicka metadata till de parter du har förtroende för.
Du kan hämta metadata i XML-format på dedicerad URL:
https://simplesaml.eek.ee/saml2/idp/metadata.php
Metadata
I SAML 2.0 Metadata XML-format:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://simplesaml.eek.ee/saml2/idp/metadata.php"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol" WantAuthnRequestsSigned="true"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIHhTCCBW2gAwIBAgIQGbpCp43fdzhRgYnK8u7ciTANBgkqhkiG9w0BAQwFADBEMQswCQYDVQQGEwJOTDEZMBcGA1UEChMQR0VBTlQgVmVyZW5pZ2luZzEaMBgGA1UEAxMRR0VBTlQgT1YgUlNBIENBIDQwHhcNMjEwNzE0MDAwMDAwWhcNMjIwNzE0MjM1OTU5WjB6MQswCQYDVQQGEwJFRTERMA8GA1UECBMISGFyanVtYWExEDAOBgNVBAcTB1RhbGxpbm4xKjAoBgNVBAoMIUVlc3RpIEV0dGV2w7V0bHVza8O1cmdrb29sIE1haW5vcjEaMBgGA1UEAxMRc2ltcGxlc2FtbC5lZWsuZWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCyiCU8SLvY1pCRR2etekTng4OPXMeE3gDwDOvYr1NwOHxaU3Kn1jjXNRgONNzpNp1DSGoUrrSgltp59EPEG7mKPl7SYPZ2BAtQ0n3vO71j3lu3AcuWJZmQLiOCjkkTS4YueE8TTCMX5gv73BajgelKkEk/+kQWZ9vJGhSMt39F2BLcjaAkpWsAk7GQZ+dz1iBHG025gLruetur9XXw0E4OuiQZRj7NB02kEapIw+4fpYLyqhJ11a0BaXnGP+50fc6OXx795AIYACHpTA8BKzaBl2Dtjw+jmLQn6K+bOhZZXFGwwLPoOIdZWfBm4ptF9dnIMj1wo6WpdtN6ZbUNEKn1AgMBAAGjggM7MIIDNzAfBgNVHSMEGDAWgBRvHTVJEGwy+lmgnryK6B+VvnF6DDAdBgNVHQ4EFgQU+61CDHY8IM8V4OP/JoPtu3MDNeswDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMEkGA1UdIARCMEAwNAYLKwYBBAGyMQECAk8wJTAjBggrBgEFBQcCARYXaHR0cHM6Ly9zZWN0aWdvLmNvbS9DUFMwCAYGZ4EMAQICMD8GA1UdHwQ4MDYwNKAyoDCGLmh0dHA6Ly9HRUFOVC5jcmwuc2VjdGlnby5jb20vR0VBTlRPVlJTQUNBNC5jcmwwdQYIKwYBBQUHAQEEaTBnMDoGCCsGAQUFBzAChi5odHRwOi8vR0VBTlQuY3J0LnNlY3RpZ28uY29tL0dFQU5UT1ZSU0FDQTQuY3J0MCkGCCsGAQUFBzABhh1odHRwOi8vR0VBTlQub2NzcC5zZWN0aWdvLmNvbTAzBgNVHREELDAqghFzaW1wbGVzYW1sLmVlay5lZYIVd3d3LnNpbXBsZXNhbWwuZWVrLmVlMIIBfgYKKwYBBAHWeQIEAgSCAW4EggFqAWgAdwBGpVXrdfqRIDC1oolp9PN9ESxBdL79SbiFq/L8cP5tRwAAAXqkR/fwAAAEAwBIMEYCIQDMZbol+k8e9iTkB8AF+FU7hFuzDJ4NbywqaqWTUuA+BwIhAMMxnKlhyBD+iSQYpmyyTRv726wyP6wuRFbAQ1hH+Cp2AHUAQcjKsd8iRkoQxqE6CUKHXk4xixsD6+tLx2jwkGKWBvYAAAF6pEf3tAAABAMARjBEAiAS2JignSelQwTvZrioamENZSF4n7sF6mHrS8Hhc1b+fQIgc1Vh/xFPT54+vJAh3c6Zk3O5MT8ReEjIDkSB8V61wHwAdgApeb7wnjk5IfBWc59jpXflvld9nGAK+PlNXSZcJV3HhAAAAXqkR/eJAAAEAwBHMEUCIQD5jKAMx+vDBSzjqaopzsubPFPUW3Cv2v3hNtgOh4vVkgIgHtQD+nEkIHWA+HTLf0T+LHsk8Cy2FBAWzcAlYBHXiccwDQYJKoZIhvcNAQEMBQADggIBAGPYlzUp5fUQbSWDLaqhEkQnx6LJYxBZL80/LtfA+aCdX6kEQSXkeAFYdZrdZSH0DoOr7tvFgYlbAcMGEw3PtuVoUSZCnVbXmkmp4oe/WjQtGXw3u0Z5EWI1SygpAJkumPp4lcW0VioiTBbZ77Ih1oXORuvEjqha9XrWEeObhAQW8h4rbmJpNdXvB6FwmXXTZNMgtKr6MzlSlWXfXdh6ePuUVZxjdXmkEthqf6pCyVpDEJx9PcIk31CBYyM4fI2oVMrf6xB0zA3EIaHq99I82716J8OQz+Lt2nDUwbRJ7Grk4i5oZWH1jl6zBl4XHXHDdVLNOk43qYeeVeS/7Omw18+5aLVWBMY03A6wjqMoALPCNh5lp7yEVzbD6BEpsDJX/Fx+ATSdhfDv8Vom4OLQOT1WGTCBKuJVMn/ldiZ3m1BsOS1zJAJOLde0Y4Xv4vUquRVwm+RhzNlAzV7JlEs92os1Qu5RccufWv2FbOOcneVXprro69Gk9xpcjHcyztQl7l8zc/t9ZpsbDveGZi8AlnUBkSZyQfslLlJmSIQrdkL1bojebubqxe369qOSbXtV4cKSUVUY0z7OVSMfXG2Lcqm+jxDh1bB6EJnJppm8QtAIgMm62Ukd3vhsnlaUAlVlEvK2JCCsXaCMDWc78g1BiNMv1QQWqwXWcyXfxqsnnnk9</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIHhTCCBW2gAwIBAgIQGbpCp43fdzhRgYnK8u7ciTANBgkqhkiG9w0BAQwFADBEMQswCQYDVQQGEwJOTDEZMBcGA1UEChMQR0VBTlQgVmVyZW5pZ2luZzEaMBgGA1UEAxMRR0VBTlQgT1YgUlNBIENBIDQwHhcNMjEwNzE0MDAwMDAwWhcNMjIwNzE0MjM1OTU5WjB6MQswCQYDVQQGEwJFRTERMA8GA1UECBMISGFyanVtYWExEDAOBgNVBAcTB1RhbGxpbm4xKjAoBgNVBAoMIUVlc3RpIEV0dGV2w7V0bHVza8O1cmdrb29sIE1haW5vcjEaMBgGA1UEAxMRc2ltcGxlc2FtbC5lZWsuZWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCyiCU8SLvY1pCRR2etekTng4OPXMeE3gDwDOvYr1NwOHxaU3Kn1jjXNRgONNzpNp1DSGoUrrSgltp59EPEG7mKPl7SYPZ2BAtQ0n3vO71j3lu3AcuWJZmQLiOCjkkTS4YueE8TTCMX5gv73BajgelKkEk/+kQWZ9vJGhSMt39F2BLcjaAkpWsAk7GQZ+dz1iBHG025gLruetur9XXw0E4OuiQZRj7NB02kEapIw+4fpYLyqhJ11a0BaXnGP+50fc6OXx795AIYACHpTA8BKzaBl2Dtjw+jmLQn6K+bOhZZXFGwwLPoOIdZWfBm4ptF9dnIMj1wo6WpdtN6ZbUNEKn1AgMBAAGjggM7MIIDNzAfBgNVHSMEGDAWgBRvHTVJEGwy+lmgnryK6B+VvnF6DDAdBgNVHQ4EFgQU+61CDHY8IM8V4OP/JoPtu3MDNeswDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMEkGA1UdIARCMEAwNAYLKwYBBAGyMQECAk8wJTAjBggrBgEFBQcCARYXaHR0cHM6Ly9zZWN0aWdvLmNvbS9DUFMwCAYGZ4EMAQICMD8GA1UdHwQ4MDYwNKAyoDCGLmh0dHA6Ly9HRUFOVC5jcmwuc2VjdGlnby5jb20vR0VBTlRPVlJTQUNBNC5jcmwwdQYIKwYBBQUHAQEEaTBnMDoGCCsGAQUFBzAChi5odHRwOi8vR0VBTlQuY3J0LnNlY3RpZ28uY29tL0dFQU5UT1ZSU0FDQTQuY3J0MCkGCCsGAQUFBzABhh1odHRwOi8vR0VBTlQub2NzcC5zZWN0aWdvLmNvbTAzBgNVHREELDAqghFzaW1wbGVzYW1sLmVlay5lZYIVd3d3LnNpbXBsZXNhbWwuZWVrLmVlMIIBfgYKKwYBBAHWeQIEAgSCAW4EggFqAWgAdwBGpVXrdfqRIDC1oolp9PN9ESxBdL79SbiFq/L8cP5tRwAAAXqkR/fwAAAEAwBIMEYCIQDMZbol+k8e9iTkB8AF+FU7hFuzDJ4NbywqaqWTUuA+BwIhAMMxnKlhyBD+iSQYpmyyTRv726wyP6wuRFbAQ1hH+Cp2AHUAQcjKsd8iRkoQxqE6CUKHXk4xixsD6+tLx2jwkGKWBvYAAAF6pEf3tAAABAMARjBEAiAS2JignSelQwTvZrioamENZSF4n7sF6mHrS8Hhc1b+fQIgc1Vh/xFPT54+vJAh3c6Zk3O5MT8ReEjIDkSB8V61wHwAdgApeb7wnjk5IfBWc59jpXflvld9nGAK+PlNXSZcJV3HhAAAAXqkR/eJAAAEAwBHMEUCIQD5jKAMx+vDBSzjqaopzsubPFPUW3Cv2v3hNtgOh4vVkgIgHtQD+nEkIHWA+HTLf0T+LHsk8Cy2FBAWzcAlYBHXiccwDQYJKoZIhvcNAQEMBQADggIBAGPYlzUp5fUQbSWDLaqhEkQnx6LJYxBZL80/LtfA+aCdX6kEQSXkeAFYdZrdZSH0DoOr7tvFgYlbAcMGEw3PtuVoUSZCnVbXmkmp4oe/WjQtGXw3u0Z5EWI1SygpAJkumPp4lcW0VioiTBbZ77Ih1oXORuvEjqha9XrWEeObhAQW8h4rbmJpNdXvB6FwmXXTZNMgtKr6MzlSlWXfXdh6ePuUVZxjdXmkEthqf6pCyVpDEJx9PcIk31CBYyM4fI2oVMrf6xB0zA3EIaHq99I82716J8OQz+Lt2nDUwbRJ7Grk4i5oZWH1jl6zBl4XHXHDdVLNOk43qYeeVeS/7Omw18+5aLVWBMY03A6wjqMoALPCNh5lp7yEVzbD6BEpsDJX/Fx+ATSdhfDv8Vom4OLQOT1WGTCBKuJVMn/ldiZ3m1BsOS1zJAJOLde0Y4Xv4vUquRVwm+RhzNlAzV7JlEs92os1Qu5RccufWv2FbOOcneVXprro69Gk9xpcjHcyztQl7l8zc/t9ZpsbDveGZi8AlnUBkSZyQfslLlJmSIQrdkL1bojebubqxe369qOSbXtV4cKSUVUY0z7OVSMfXG2Lcqm+jxDh1bB6EJnJppm8QtAIgMm62Ukd3vhsnlaUAlVlEvK2JCCsXaCMDWc78g1BiNMv1QQWqwXWcyXfxqsnnnk9</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://simplesaml.eek.ee/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://simplesaml.eek.ee/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>Indrek</md:GivenName> <md:SurName>Tobre</md:SurName> <md:EmailAddress>mailto:noreply@eek.ee</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
I filformatet för simpleSAML, använd detta detta format om SimpleSAMLphp används i mottagende sida:
$metadata['https://simplesaml.eek.ee/saml2/idp/metadata.php'] = [ 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://simplesaml.eek.ee/saml2/idp/metadata.php', 'SingleSignOnService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://simplesaml.eek.ee/saml2/idp/SSOService.php', ], ], 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://simplesaml.eek.ee/saml2/idp/SingleLogoutService.php', ], ], 'certData' => 'MIIHhTCCBW2gAwIBAgIQGbpCp43fdzhRgYnK8u7ciTANBgkqhkiG9w0BAQwFADBEMQswCQYDVQQGEwJOTDEZMBcGA1UEChMQR0VBTlQgVmVyZW5pZ2luZzEaMBgGA1UEAxMRR0VBTlQgT1YgUlNBIENBIDQwHhcNMjEwNzE0MDAwMDAwWhcNMjIwNzE0MjM1OTU5WjB6MQswCQYDVQQGEwJFRTERMA8GA1UECBMISGFyanVtYWExEDAOBgNVBAcTB1RhbGxpbm4xKjAoBgNVBAoMIUVlc3RpIEV0dGV2w7V0bHVza8O1cmdrb29sIE1haW5vcjEaMBgGA1UEAxMRc2ltcGxlc2FtbC5lZWsuZWUwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCyiCU8SLvY1pCRR2etekTng4OPXMeE3gDwDOvYr1NwOHxaU3Kn1jjXNRgONNzpNp1DSGoUrrSgltp59EPEG7mKPl7SYPZ2BAtQ0n3vO71j3lu3AcuWJZmQLiOCjkkTS4YueE8TTCMX5gv73BajgelKkEk/+kQWZ9vJGhSMt39F2BLcjaAkpWsAk7GQZ+dz1iBHG025gLruetur9XXw0E4OuiQZRj7NB02kEapIw+4fpYLyqhJ11a0BaXnGP+50fc6OXx795AIYACHpTA8BKzaBl2Dtjw+jmLQn6K+bOhZZXFGwwLPoOIdZWfBm4ptF9dnIMj1wo6WpdtN6ZbUNEKn1AgMBAAGjggM7MIIDNzAfBgNVHSMEGDAWgBRvHTVJEGwy+lmgnryK6B+VvnF6DDAdBgNVHQ4EFgQU+61CDHY8IM8V4OP/JoPtu3MDNeswDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwHQYDVR0lBBYwFAYIKwYBBQUHAwEGCCsGAQUFBwMCMEkGA1UdIARCMEAwNAYLKwYBBAGyMQECAk8wJTAjBggrBgEFBQcCARYXaHR0cHM6Ly9zZWN0aWdvLmNvbS9DUFMwCAYGZ4EMAQICMD8GA1UdHwQ4MDYwNKAyoDCGLmh0dHA6Ly9HRUFOVC5jcmwuc2VjdGlnby5jb20vR0VBTlRPVlJTQUNBNC5jcmwwdQYIKwYBBQUHAQEEaTBnMDoGCCsGAQUFBzAChi5odHRwOi8vR0VBTlQuY3J0LnNlY3RpZ28uY29tL0dFQU5UT1ZSU0FDQTQuY3J0MCkGCCsGAQUFBzABhh1odHRwOi8vR0VBTlQub2NzcC5zZWN0aWdvLmNvbTAzBgNVHREELDAqghFzaW1wbGVzYW1sLmVlay5lZYIVd3d3LnNpbXBsZXNhbWwuZWVrLmVlMIIBfgYKKwYBBAHWeQIEAgSCAW4EggFqAWgAdwBGpVXrdfqRIDC1oolp9PN9ESxBdL79SbiFq/L8cP5tRwAAAXqkR/fwAAAEAwBIMEYCIQDMZbol+k8e9iTkB8AF+FU7hFuzDJ4NbywqaqWTUuA+BwIhAMMxnKlhyBD+iSQYpmyyTRv726wyP6wuRFbAQ1hH+Cp2AHUAQcjKsd8iRkoQxqE6CUKHXk4xixsD6+tLx2jwkGKWBvYAAAF6pEf3tAAABAMARjBEAiAS2JignSelQwTvZrioamENZSF4n7sF6mHrS8Hhc1b+fQIgc1Vh/xFPT54+vJAh3c6Zk3O5MT8ReEjIDkSB8V61wHwAdgApeb7wnjk5IfBWc59jpXflvld9nGAK+PlNXSZcJV3HhAAAAXqkR/eJAAAEAwBHMEUCIQD5jKAMx+vDBSzjqaopzsubPFPUW3Cv2v3hNtgOh4vVkgIgHtQD+nEkIHWA+HTLf0T+LHsk8Cy2FBAWzcAlYBHXiccwDQYJKoZIhvcNAQEMBQADggIBAGPYlzUp5fUQbSWDLaqhEkQnx6LJYxBZL80/LtfA+aCdX6kEQSXkeAFYdZrdZSH0DoOr7tvFgYlbAcMGEw3PtuVoUSZCnVbXmkmp4oe/WjQtGXw3u0Z5EWI1SygpAJkumPp4lcW0VioiTBbZ77Ih1oXORuvEjqha9XrWEeObhAQW8h4rbmJpNdXvB6FwmXXTZNMgtKr6MzlSlWXfXdh6ePuUVZxjdXmkEthqf6pCyVpDEJx9PcIk31CBYyM4fI2oVMrf6xB0zA3EIaHq99I82716J8OQz+Lt2nDUwbRJ7Grk4i5oZWH1jl6zBl4XHXHDdVLNOk43qYeeVeS/7Omw18+5aLVWBMY03A6wjqMoALPCNh5lp7yEVzbD6BEpsDJX/Fx+ATSdhfDv8Vom4OLQOT1WGTCBKuJVMn/ldiZ3m1BsOS1zJAJOLde0Y4Xv4vUquRVwm+RhzNlAzV7JlEs92os1Qu5RccufWv2FbOOcneVXprro69Gk9xpcjHcyztQl7l8zc/t9ZpsbDveGZi8AlnUBkSZyQfslLlJmSIQrdkL1bojebubqxe369qOSbXtV4cKSUVUY0z7OVSMfXG2Lcqm+jxDh1bB6EJnJppm8QtAIgMm62Ukd3vhsnlaUAlVlEvK2JCCsXaCMDWc78g1BiNMv1QQWqwXWcyXfxqsnnnk9', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'redirect.sign' => true, 'contacts' => [ [ 'emailAddress' => 'noreply@eek.ee', 'contactType' => 'technical', 'givenName' => 'Indrek', 'surName' => 'Tobre', ], ], ];
Certifikat
Hämta X509-certifikaten som PEM-kodade filer.