Čeština | Dansk | Deutsch | English | Español | eesti keel | Euskara | Suomeksi | Français | עִבְרִית | Hrvatski | Magyar | Bahasa Indonesia | Italiano | 日本語 | Lëtzebuergesch | Lietuvių kalba | Latviešu | Nederlands | Nynorsk | Bokmål | Język polski | Português | Português brasileiro | Românește | русский язык | Sámegiella | Slovenščina | Srpski | Svenska | Türkçe | 简体中文 | 繁體中文

SAML 2.0 IdP metadata

Her er metadata som SimpleSAMLphp har generert for deg. Du må utveksle metadata med de partene du stoler på for å sette opp en føderasjon.

Du kan nå metadata i XML-format på en dedikert URL:

https://idp.research-work.shop/simplesaml/saml2/idp/metadata.php

Metadata

I SAML 2.0 Metadata XML Format:

<?xml version="1.0" encoding="UTF-8"?>
<md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://idp.research-work.shop/simplesaml/saml2/idp/metadata.php">
  <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol">
    <md:KeyDescriptor use="signing">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIDIzCCAgugAwIBAgIUd91/H+vznWys9J/eydgruhtMLOAwDQYJKoZIhvcNAQELBQAwITEfMB0GA1UEAwwWaWRwLnJlc2VhcmNoLXdvcmsuc2hvcDAeFw0yNjAxMTYwNjQ3MzZaFw0zNjAxMTQwNjQ3MzZaMCExHzAdBgNVBAMMFmlkcC5yZXNlYXJjaC13b3JrLnNob3AwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDE+CAzUPIl7FFGNKbAGD5Es3EIxU/Y56UVKCUi8yQwD4NVRpyPJ2gJj7yW68NyT8DO746T3mybTq4PN5cd4MZSrKE7CO9BB95IRNl+6uxyGYtjgnYCSzJLxAry37zc9Od6FFeWqYDiP/43cTXvYz/QBVQPEmBsKkGkURB1aokB+ZELVvCU1xScbk+d1yDVUZ/joNBJRzY+1+359sJHmes9WDQe9u0hqOpZJtRGfrWPGwQRiCZgpVEZ3TiqeOplrRD29+fa7PFUB2EOBlHtT/zp6jOZnGs6ZQfQ2bPi0BJ2/seNGu+zKaW8pASF6bqVa1O9y/jUX0+hY8Sth5hD12t1AgMBAAGjUzBRMB0GA1UdDgQWBBQvQ5FfnxL7d7MKjSMufmBTqrpXkDAfBgNVHSMEGDAWgBQvQ5FfnxL7d7MKjSMufmBTqrpXkDAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBVNNWEOl4vq8kHfSiKzeQiy1TPDlkpfhqgzZoblWG5/f4RDN3HasOpmlsbnRwWMwxac1D3vWsVjbLpP944+pOtoVkjOZyG0DmoMri0G4HZbntuYMvEIMi4B2Ng5pDNgy8k1YcZAHQDzOtCEfDcFHdDOSiF9T88nh+aWPZbzLJzTWQVJ2vn2A5Oa4yR/H1NKe3nBjO7xoNd63VtVxM2vdtOR3MBtA7fpyfBewixdwLT0myZ2/JubD4V4yJNeqgTbVmbSkNH0/ZF2iFPkci7ZiEGAL/VP3eOEkWWU7bPFRj21V2qgUFoZklDbMNmR9ffxsIW1R/MT20DmtkA+9aeUIFt</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:KeyDescriptor use="encryption">
      <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:X509Data>
          <ds:X509Certificate>MIIDIzCCAgugAwIBAgIUd91/H+vznWys9J/eydgruhtMLOAwDQYJKoZIhvcNAQELBQAwITEfMB0GA1UEAwwWaWRwLnJlc2VhcmNoLXdvcmsuc2hvcDAeFw0yNjAxMTYwNjQ3MzZaFw0zNjAxMTQwNjQ3MzZaMCExHzAdBgNVBAMMFmlkcC5yZXNlYXJjaC13b3JrLnNob3AwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDE+CAzUPIl7FFGNKbAGD5Es3EIxU/Y56UVKCUi8yQwD4NVRpyPJ2gJj7yW68NyT8DO746T3mybTq4PN5cd4MZSrKE7CO9BB95IRNl+6uxyGYtjgnYCSzJLxAry37zc9Od6FFeWqYDiP/43cTXvYz/QBVQPEmBsKkGkURB1aokB+ZELVvCU1xScbk+d1yDVUZ/joNBJRzY+1+359sJHmes9WDQe9u0hqOpZJtRGfrWPGwQRiCZgpVEZ3TiqeOplrRD29+fa7PFUB2EOBlHtT/zp6jOZnGs6ZQfQ2bPi0BJ2/seNGu+zKaW8pASF6bqVa1O9y/jUX0+hY8Sth5hD12t1AgMBAAGjUzBRMB0GA1UdDgQWBBQvQ5FfnxL7d7MKjSMufmBTqrpXkDAfBgNVHSMEGDAWgBQvQ5FfnxL7d7MKjSMufmBTqrpXkDAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBVNNWEOl4vq8kHfSiKzeQiy1TPDlkpfhqgzZoblWG5/f4RDN3HasOpmlsbnRwWMwxac1D3vWsVjbLpP944+pOtoVkjOZyG0DmoMri0G4HZbntuYMvEIMi4B2Ng5pDNgy8k1YcZAHQDzOtCEfDcFHdDOSiF9T88nh+aWPZbzLJzTWQVJ2vn2A5Oa4yR/H1NKe3nBjO7xoNd63VtVxM2vdtOR3MBtA7fpyfBewixdwLT0myZ2/JubD4V4yJNeqgTbVmbSkNH0/ZF2iFPkci7ZiEGAL/VP3eOEkWWU7bPFRj21V2qgUFoZklDbMNmR9ffxsIW1R/MT20DmtkA+9aeUIFt</ds:X509Certificate>
        </ds:X509Data>
      </ds:KeyInfo>
    </md:KeyDescriptor>
    <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.research-work.shop/simplesaml/saml2/idp/SingleLogoutService.php"/>
    <md:NameIDFormat>urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified</md:NameIDFormat>
    <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.research-work.shop/simplesaml/saml2/idp/SSOService.php"/>
  </md:IDPSSODescriptor>
  <md:ContactPerson contactType="technical">
    <md:GivenName>Administrator</md:GivenName>
    <md:EmailAddress>mailto:na@example.com</md:EmailAddress>
  </md:ContactPerson>
</md:EntityDescriptor>

I SimpleSAMLphp format - bruk denne dersom du benytter SimpleSAMLphp i den andre enden:

$metadata['https://idp.research-work.shop/simplesaml/saml2/idp/metadata.php'] = [
    'metadata-set' => 'saml20-idp-remote',
    'entityid' => 'https://idp.research-work.shop/simplesaml/saml2/idp/metadata.php',
    'SingleSignOnService' => [
        [
            'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
            'Location' => 'https://idp.research-work.shop/simplesaml/saml2/idp/SSOService.php',
        ],
    ],
    'SingleLogoutService' => [
        [
            'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect',
            'Location' => 'https://idp.research-work.shop/simplesaml/saml2/idp/SingleLogoutService.php',
        ],
    ],
    'certData' => 'MIIDIzCCAgugAwIBAgIUd91/H+vznWys9J/eydgruhtMLOAwDQYJKoZIhvcNAQELBQAwITEfMB0GA1UEAwwWaWRwLnJlc2VhcmNoLXdvcmsuc2hvcDAeFw0yNjAxMTYwNjQ3MzZaFw0zNjAxMTQwNjQ3MzZaMCExHzAdBgNVBAMMFmlkcC5yZXNlYXJjaC13b3JrLnNob3AwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDE+CAzUPIl7FFGNKbAGD5Es3EIxU/Y56UVKCUi8yQwD4NVRpyPJ2gJj7yW68NyT8DO746T3mybTq4PN5cd4MZSrKE7CO9BB95IRNl+6uxyGYtjgnYCSzJLxAry37zc9Od6FFeWqYDiP/43cTXvYz/QBVQPEmBsKkGkURB1aokB+ZELVvCU1xScbk+d1yDVUZ/joNBJRzY+1+359sJHmes9WDQe9u0hqOpZJtRGfrWPGwQRiCZgpVEZ3TiqeOplrRD29+fa7PFUB2EOBlHtT/zp6jOZnGs6ZQfQ2bPi0BJ2/seNGu+zKaW8pASF6bqVa1O9y/jUX0+hY8Sth5hD12t1AgMBAAGjUzBRMB0GA1UdDgQWBBQvQ5FfnxL7d7MKjSMufmBTqrpXkDAfBgNVHSMEGDAWgBQvQ5FfnxL7d7MKjSMufmBTqrpXkDAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBCwUAA4IBAQBVNNWEOl4vq8kHfSiKzeQiy1TPDlkpfhqgzZoblWG5/f4RDN3HasOpmlsbnRwWMwxac1D3vWsVjbLpP944+pOtoVkjOZyG0DmoMri0G4HZbntuYMvEIMi4B2Ng5pDNgy8k1YcZAHQDzOtCEfDcFHdDOSiF9T88nh+aWPZbzLJzTWQVJ2vn2A5Oa4yR/H1NKe3nBjO7xoNd63VtVxM2vdtOR3MBtA7fpyfBewixdwLT0myZ2/JubD4V4yJNeqgTbVmbSkNH0/ZF2iFPkci7ZiEGAL/VP3eOEkWWU7bPFRj21V2qgUFoZklDbMNmR9ffxsIW1R/MT20DmtkA+9aeUIFt',
    'NameIDFormat' => [
        'urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified',
    ],
    'contacts' => [
        [
            'emailAddress' => 'na@example.com',
            'contactType' => 'technical',
            'givenName' => 'Administrator',
        ],
    ],
];

Sertifikater

Last ned X509-sertifikatene som PEM-filer.