SAML 2.0 identitetsudbyders metadata
Her er det metadata, som SimpleSAMLphp har genereret. Du kan sende det til dem du stoler i forbindelse med oprettelsen af en føderation.
Du kan få metadata-xml her:
https://arh.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php
Metadata
I SAML 2.0 metadata xml-format:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://arh.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDnzCCAoegAwIBAgIUcg3YOV1pkyu1KyBvDEhoIBa4uUMwDQYJKoZIhvcNAQELBQAwXzELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEkMCIGA1UEAwwbYXJoLmlkcC1wcm94eS5maW5raS51a2ltLm1rMB4XDTIwMDQwMjA5NTY1N1oXDTMwMDMzMTA5NTY1N1owXzELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEkMCIGA1UEAwwbYXJoLmlkcC1wcm94eS5maW5raS51a2ltLm1rMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnhEaT2CZhU1bXwDwdhOSd5wroGcSJX2Lq697SUzz0itrqt69r+hJGUjAos+eAwrZGyHDi445xHr5NbKjh5cD1w3W9ETfbyeVLBFVZ+TZr5u1qD46K4c8FXQuuWZ7zptG0wEms8RTLtkxgFy0PpAG50eEIXCPdS/gNOCZbaGbXvOVbdQg/Qjf8hMkdo5YmY39/GuPe26xCKQ9/v8rVCvPQTandDL1p0+IilO2q4l9IcxAMZxzVfHG1J/UxcW0BvzFiyO9l6kdvU8e/2JgbiIEQuY9TIQwwv8ZmEsWb6BvztXkEmaCK1JutSIkOTBAhEu53b7TAyg2ph3yOWHKKKf9hQIDAQABo1MwUTAdBgNVHQ4EFgQUd3kRT9w9ukaYxA+36arL6eXHK5YwHwYDVR0jBBgwFoAUd3kRT9w9ukaYxA+36arL6eXHK5YwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAXALTZSWh/OsXL5k3ZbDPCdcIXIIMibc4AnZwYd4T7yVqNANc/3dDoVthKr1K0n7vUlu7/dCTZuDdBrKVisnd9S0q83VYJagRuGoMvHUP/gC9z1Ia+uMwOKAWQhpTrGbKB0CMq6CJRvScBsv41STpJEvDv0TPhBC/4RD0wly8JH8MfSRCHsL+KmGaWVT1D8vhIIxfYg6VOYOVElmSdpMd0N/5gI36bXBm8WcGU88ianNw6cpRs8wsqu14AHQX8zq3FAP9jsVt0qmPeHE/heSItjF3VCI9OxEuHTyWD4NCOAECb9Yoms/COe3MWyXWT0iTTxo7VwphP3zqcu/zolbqKA==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDnzCCAoegAwIBAgIUcg3YOV1pkyu1KyBvDEhoIBa4uUMwDQYJKoZIhvcNAQELBQAwXzELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEkMCIGA1UEAwwbYXJoLmlkcC1wcm94eS5maW5raS51a2ltLm1rMB4XDTIwMDQwMjA5NTY1N1oXDTMwMDMzMTA5NTY1N1owXzELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEkMCIGA1UEAwwbYXJoLmlkcC1wcm94eS5maW5raS51a2ltLm1rMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnhEaT2CZhU1bXwDwdhOSd5wroGcSJX2Lq697SUzz0itrqt69r+hJGUjAos+eAwrZGyHDi445xHr5NbKjh5cD1w3W9ETfbyeVLBFVZ+TZr5u1qD46K4c8FXQuuWZ7zptG0wEms8RTLtkxgFy0PpAG50eEIXCPdS/gNOCZbaGbXvOVbdQg/Qjf8hMkdo5YmY39/GuPe26xCKQ9/v8rVCvPQTandDL1p0+IilO2q4l9IcxAMZxzVfHG1J/UxcW0BvzFiyO9l6kdvU8e/2JgbiIEQuY9TIQwwv8ZmEsWb6BvztXkEmaCK1JutSIkOTBAhEu53b7TAyg2ph3yOWHKKKf9hQIDAQABo1MwUTAdBgNVHQ4EFgQUd3kRT9w9ukaYxA+36arL6eXHK5YwHwYDVR0jBBgwFoAUd3kRT9w9ukaYxA+36arL6eXHK5YwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAXALTZSWh/OsXL5k3ZbDPCdcIXIIMibc4AnZwYd4T7yVqNANc/3dDoVthKr1K0n7vUlu7/dCTZuDdBrKVisnd9S0q83VYJagRuGoMvHUP/gC9z1Ia+uMwOKAWQhpTrGbKB0CMq6CJRvScBsv41STpJEvDv0TPhBC/4RD0wly8JH8MfSRCHsL+KmGaWVT1D8vhIIxfYg6VOYOVElmSdpMd0N/5gI36bXBm8WcGU88ianNw6cpRs8wsqu14AHQX8zq3FAP9jsVt0qmPeHE/heSItjF3VCI9OxEuHTyWD4NCOAECb9Yoms/COe3MWyXWT0iTTxo7VwphP3zqcu/zolbqKA==</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://arh.idp-proxy.finki.ukim.mk/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://arh.idp-proxy.finki.ukim.mk/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>FINKI</md:GivenName> <md:SurName>FCC</md:SurName> <md:EmailAddress>fcc@finki.ukim.mk</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
I SimpleSAMLphp flat-file format - brug dette hvis du også bruger SimpleSAMLphp i den anden ende;
$metadata['https://arh.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php'] = array ( 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://arh.idp-proxy.finki.ukim.mk/saml2/idp/metadata.php', 'SingleSignOnService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://arh.idp-proxy.finki.ukim.mk/saml2/idp/SSOService.php', ), ), 'SingleLogoutService' => array ( 0 => array ( 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://arh.idp-proxy.finki.ukim.mk/saml2/idp/SingleLogoutService.php', ), ), 'certData' => 'MIIDnzCCAoegAwIBAgIUcg3YOV1pkyu1KyBvDEhoIBa4uUMwDQYJKoZIhvcNAQELBQAwXzELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEkMCIGA1UEAwwbYXJoLmlkcC1wcm94eS5maW5raS51a2ltLm1rMB4XDTIwMDQwMjA5NTY1N1oXDTMwMDMzMTA5NTY1N1owXzELMAkGA1UEBhMCTUsxCjAIBgNVBAgMASAxDzANBgNVBAcMBlNrb3BqZTENMAsGA1UECgwEVUtJTTEkMCIGA1UEAwwbYXJoLmlkcC1wcm94eS5maW5raS51a2ltLm1rMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAnhEaT2CZhU1bXwDwdhOSd5wroGcSJX2Lq697SUzz0itrqt69r+hJGUjAos+eAwrZGyHDi445xHr5NbKjh5cD1w3W9ETfbyeVLBFVZ+TZr5u1qD46K4c8FXQuuWZ7zptG0wEms8RTLtkxgFy0PpAG50eEIXCPdS/gNOCZbaGbXvOVbdQg/Qjf8hMkdo5YmY39/GuPe26xCKQ9/v8rVCvPQTandDL1p0+IilO2q4l9IcxAMZxzVfHG1J/UxcW0BvzFiyO9l6kdvU8e/2JgbiIEQuY9TIQwwv8ZmEsWb6BvztXkEmaCK1JutSIkOTBAhEu53b7TAyg2ph3yOWHKKKf9hQIDAQABo1MwUTAdBgNVHQ4EFgQUd3kRT9w9ukaYxA+36arL6eXHK5YwHwYDVR0jBBgwFoAUd3kRT9w9ukaYxA+36arL6eXHK5YwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAQEAXALTZSWh/OsXL5k3ZbDPCdcIXIIMibc4AnZwYd4T7yVqNANc/3dDoVthKr1K0n7vUlu7/dCTZuDdBrKVisnd9S0q83VYJagRuGoMvHUP/gC9z1Ia+uMwOKAWQhpTrGbKB0CMq6CJRvScBsv41STpJEvDv0TPhBC/4RD0wly8JH8MfSRCHsL+KmGaWVT1D8vhIIxfYg6VOYOVElmSdpMd0N/5gI36bXBm8WcGU88ianNw6cpRs8wsqu14AHQX8zq3FAP9jsVt0qmPeHE/heSItjF3VCI9OxEuHTyWD4NCOAECb9Yoms/COe3MWyXWT0iTTxo7VwphP3zqcu/zolbqKA==', 'NameIDFormat' => array ( 0 => 'urn:oasis:names:tc:SAML:2.0:nameid-format:persistent', ), 'contacts' => array ( 0 => array ( 'emailAddress' => 'fcc@finki.ukim.mk', 'contactType' => 'technical', 'givenName' => 'FINKI', 'surName' => 'FCC', ), ), );
Certifikater
Download X509 certifikaterne som PEM-indkodet filer.