SAML 2.0 IdP Metapodatki
Tu so metapodatki, ki jih je generiral SimpleSAMLphp. Dokument lahko pošljete zaupanja vrednim partnerjem, s katerimi boste ustvarili federacijo.
XML metapodatki se nahajajo na tem naslovu:
https://idp.ucv.ro/simplesaml/saml2/idp/metadata.php
Metapodatki
V SAML 2.0 Metapodatkovni XML format:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://idp.ucv.ro/simplesaml/saml2/idp/metadata.php"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDAjCCAmugAwIBAgIJAJ3dMqHUVgjrMA0GCSqGSIb3DQEBBQUAMIGZMRMwEQYDVQQDDApzcC4xd2ViLnJvMQswCQYDVQQGEwJSTzENMAsGA1UECAwERG9sajEQMA4GA1UEBwwHQ3JhaW92YTEeMBwGA1UECgwVVW5pdmVyc2l0eSBvZiBDcmFpb3ZhMRowGAYDVQQLDBFDZW50cnVsIGRlIENhbGN1bDEYMBYGCSqGSIb3DQEJARYJaXRAdWN2LnJvMB4XDTE2MDEyMjExMDQ1N1oXDTE3MDEyMTExMDQ1N1owgZkxEzARBgNVBAMMCnNwLjF3ZWIucm8xCzAJBgNVBAYTAlJPMQ0wCwYDVQQIDAREb2xqMRAwDgYDVQQHDAdDcmFpb3ZhMR4wHAYDVQQKDBVVbml2ZXJzaXR5IG9mIENyYWlvdmExGjAYBgNVBAsMEUNlbnRydWwgZGUgQ2FsY3VsMRgwFgYJKoZIhvcNAQkBFglpdEB1Y3Yucm8wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALRHXqI9LxEzGda8wI1BeqU6ModyolgsaWVltpubbOxyeEaHmguxmj4wirAxjLjHgpeYXLvfdvGjLn08u+/SujsotIY6VVSooc/dMScM3QQuuzbEXtexsEclE4ZaaMyQaFM390J5viUX9YU2twutqCabUq+N/boe5/jfe/NCXGxVAgMBAAGjUDBOMB0GA1UdDgQWBBT2z+zuEWAt+u+hhq/7tI7QwddMsTAfBgNVHSMEGDAWgBT2z+zuEWAt+u+hhq/7tI7QwddMsTAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4GBAAoU4HfxRConvNmOl/cvu23wp+jvpgh2W7iV0zB915RJk+ieQRR9xxvCp242hxmrwonjDyYJgeEKuL9qq3xZYWIP2xLNKS4TYZDbiPeWILZ6p4pLyJQQ6oNMYSemvZs9+9KSKtUbwErgd27wvFNL9pUz95yZ+UfM+RFqSZ0rJnCC</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIDAjCCAmugAwIBAgIJAJ3dMqHUVgjrMA0GCSqGSIb3DQEBBQUAMIGZMRMwEQYDVQQDDApzcC4xd2ViLnJvMQswCQYDVQQGEwJSTzENMAsGA1UECAwERG9sajEQMA4GA1UEBwwHQ3JhaW92YTEeMBwGA1UECgwVVW5pdmVyc2l0eSBvZiBDcmFpb3ZhMRowGAYDVQQLDBFDZW50cnVsIGRlIENhbGN1bDEYMBYGCSqGSIb3DQEJARYJaXRAdWN2LnJvMB4XDTE2MDEyMjExMDQ1N1oXDTE3MDEyMTExMDQ1N1owgZkxEzARBgNVBAMMCnNwLjF3ZWIucm8xCzAJBgNVBAYTAlJPMQ0wCwYDVQQIDAREb2xqMRAwDgYDVQQHDAdDcmFpb3ZhMR4wHAYDVQQKDBVVbml2ZXJzaXR5IG9mIENyYWlvdmExGjAYBgNVBAsMEUNlbnRydWwgZGUgQ2FsY3VsMRgwFgYJKoZIhvcNAQkBFglpdEB1Y3Yucm8wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALRHXqI9LxEzGda8wI1BeqU6ModyolgsaWVltpubbOxyeEaHmguxmj4wirAxjLjHgpeYXLvfdvGjLn08u+/SujsotIY6VVSooc/dMScM3QQuuzbEXtexsEclE4ZaaMyQaFM390J5viUX9YU2twutqCabUq+N/boe5/jfe/NCXGxVAgMBAAGjUDBOMB0GA1UdDgQWBBT2z+zuEWAt+u+hhq/7tI7QwddMsTAfBgNVHSMEGDAWgBT2z+zuEWAt+u+hhq/7tI7QwddMsTAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4GBAAoU4HfxRConvNmOl/cvu23wp+jvpgh2W7iV0zB915RJk+ieQRR9xxvCp242hxmrwonjDyYJgeEKuL9qq3xZYWIP2xLNKS4TYZDbiPeWILZ6p4pLyJQQ6oNMYSemvZs9+9KSKtUbwErgd27wvFNL9pUz95yZ+UfM+RFqSZ0rJnCC</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.ucv.ro/simplesaml/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.ucv.ro/simplesaml/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>Administrator</md:GivenName> <md:EmailAddress>mailto:it@ucv.ro</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
V SimpleSAMLphp "flat file" formatu - ta format uporabite, če uporabljate SimpleSAMLphp entiteto na drugi strani:
$metadata['https://idp.ucv.ro/simplesaml/saml2/idp/metadata.php'] = [ 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://idp.ucv.ro/simplesaml/saml2/idp/metadata.php', 'SingleSignOnService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://idp.ucv.ro/simplesaml/saml2/idp/SSOService.php', ], ], 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://idp.ucv.ro/simplesaml/saml2/idp/SingleLogoutService.php', ], ], 'certData' => 'MIIDAjCCAmugAwIBAgIJAJ3dMqHUVgjrMA0GCSqGSIb3DQEBBQUAMIGZMRMwEQYDVQQDDApzcC4xd2ViLnJvMQswCQYDVQQGEwJSTzENMAsGA1UECAwERG9sajEQMA4GA1UEBwwHQ3JhaW92YTEeMBwGA1UECgwVVW5pdmVyc2l0eSBvZiBDcmFpb3ZhMRowGAYDVQQLDBFDZW50cnVsIGRlIENhbGN1bDEYMBYGCSqGSIb3DQEJARYJaXRAdWN2LnJvMB4XDTE2MDEyMjExMDQ1N1oXDTE3MDEyMTExMDQ1N1owgZkxEzARBgNVBAMMCnNwLjF3ZWIucm8xCzAJBgNVBAYTAlJPMQ0wCwYDVQQIDAREb2xqMRAwDgYDVQQHDAdDcmFpb3ZhMR4wHAYDVQQKDBVVbml2ZXJzaXR5IG9mIENyYWlvdmExGjAYBgNVBAsMEUNlbnRydWwgZGUgQ2FsY3VsMRgwFgYJKoZIhvcNAQkBFglpdEB1Y3Yucm8wgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALRHXqI9LxEzGda8wI1BeqU6ModyolgsaWVltpubbOxyeEaHmguxmj4wirAxjLjHgpeYXLvfdvGjLn08u+/SujsotIY6VVSooc/dMScM3QQuuzbEXtexsEclE4ZaaMyQaFM390J5viUX9YU2twutqCabUq+N/boe5/jfe/NCXGxVAgMBAAGjUDBOMB0GA1UdDgQWBBT2z+zuEWAt+u+hhq/7tI7QwddMsTAfBgNVHSMEGDAWgBT2z+zuEWAt+u+hhq/7tI7QwddMsTAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUAA4GBAAoU4HfxRConvNmOl/cvu23wp+jvpgh2W7iV0zB915RJk+ieQRR9xxvCp242hxmrwonjDyYJgeEKuL9qq3xZYWIP2xLNKS4TYZDbiPeWILZ6p4pLyJQQ6oNMYSemvZs9+9KSKtUbwErgd27wvFNL9pUz95yZ+UfM+RFqSZ0rJnCC', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'contacts' => [ [ 'emailAddress' => 'it@ucv.ro', 'contactType' => 'technical', 'givenName' => 'Administrator', ], ], ];
Digitalna potrdila
Prenesi X509 digitalno potrdilo v PEM datoteki.