Metadati SAML 2.0 IdP
Questi sono i metadati che SimpleSAMLphp ha generato e che possono essere inviati ai partner fidati per creare una federazione tra siti.
Si possono ottenere i metadati in XML dall'URL dedicata:
https://idp.na-prostem.si/simplesaml/saml2/idp/metadata.php
Metadati
Metadati SAML 2.0 in formato XML:
<?xml version="1.0"?> <md:EntityDescriptor xmlns:md="urn:oasis:names:tc:SAML:2.0:metadata" xmlns:ds="http://www.w3.org/2000/09/xmldsig#" entityID="https://idp.na-prostem.si/simplesaml/saml2/idp/metadata.php"> <md:IDPSSODescriptor protocolSupportEnumeration="urn:oasis:names:tc:SAML:2.0:protocol"> <md:KeyDescriptor use="signing"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIE6zCCA1OgAwIBAgIUDi1DmEgxrJFgj3tDcn8y2iP53tYwDQYJKoZIhvcNAQELBQAwgYQxCzAJBgNVBAYTAlNJMREwDwYDVQQIDAhTbG92ZW5pYTESMBAGA1UEBwwJTGp1YmxqYW5hMRMwEQYDVQQKDApOYS1wcm9zdGVtMRYwFAYDVQQDDA1uYS1wcm9zdGVtLnNpMSEwHwYJKoZIhvcNAQkBFhJpbmZvQG5hLXByb3N0ZW0uc2kwHhcNMjMwNDIzMDA0MTIxWhcNMzMwNDIyMDA0MTIxWjCBhDELMAkGA1UEBhMCU0kxETAPBgNVBAgMCFNsb3ZlbmlhMRIwEAYDVQQHDAlManVibGphbmExEzARBgNVBAoMCk5hLXByb3N0ZW0xFjAUBgNVBAMMDW5hLXByb3N0ZW0uc2kxITAfBgkqhkiG9w0BCQEWEmluZm9AbmEtcHJvc3RlbS5zaTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAPpcJD/K6LU1/bgH1iMwsT77FO2KBluK9BBHdnYEVssRKi8UdeFHmXQ40d6LtQwqqZttYOMKdNNMzZ4UzMTuJNZCo+dl06vxLQkDwvjaFkGuN35QCEuIaHVgmEQ8a24gGwWOLc4mtDNMV5RpGZskQSlhaOLk0cQpWmOtfLosMesCo+InUu5/njQ9eJGebAhfHTI2jHANr75AnjYUExJ90pIoJasXA6I8boRx9Gypbbn8AU+FBmXH05IMa2MI9f1rNjSiW7LCHpLppi42/hKvigodm0GmiNo1muSyOTiPaRSopMv742xcHTV7OXNK4F/ofZxi/FcbCOlUx25rqyJ3LIZw9BlhJYwcH5CzOyc04LIXlr090sfLjA5fPA7L96UOJMQU5k34tzlOUyeAFm+TN4aqzBzJE1eoWPSymxvwiOdabcJ+E/0JSl8Rz6retXqR0TTvsgEC4+2u3ZHK7hkflGxEqUHDb8XmuABSzwL25DFMnOb3tNGeb36/M7OujNH6gQIDAQABo1MwUTAdBgNVHQ4EFgQUw+gfZ0lA9slWNXmh4c5GAb61SPIwHwYDVR0jBBgwFoAUw+gfZ0lA9slWNXmh4c5GAb61SPIwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAYEAiKMdVRSYlYcYp+bQuRFSZKuDUa//l/AsTjYWLgDFtUgDE/EizHjfUs0QkXSMz2qtLYGIZhaDeqduFimrH4mSU0ElaLZOabm1x612YbVBmlTUy2CoOFcUMkUbyBx8MWwVFFIHO5ZcEY9nqOGELQhQZFk8BJsPumn3Fz8n9lTp4PFcFDjtGY8+gNiuoMAIVV9G2/3wcrBFIOH3Pn84jGRat0YtFYKXsPkXqyKIeiZi2pCw81aHVg0kOeW7NYaDUVBSvYTAf0SgBAL8DrngHp2BJ1dTPUuSnWQkZ44FVxLpCqgXvNQTidO6X7x6IFSCYs/S1gsqV6Epv684Zy+BIPJQh6Tfqq7VYNtZGUrSOb7w/K+MVDS16n0N5PjwRSzkgCpOxJlOj1Jle6nO0T3pxQ/BJ1UIPkzdzTHhqYtVABHacjbvtfOwvkUF8v1+/Kshu54T6WkNKflkridlzhqRaXSNw9O20iVSykTgkVT64fr5bMJ94nfVTLXD7tWQpIGSH8ih</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:KeyDescriptor use="encryption"> <ds:KeyInfo xmlns:ds="http://www.w3.org/2000/09/xmldsig#"> <ds:X509Data> <ds:X509Certificate>MIIE6zCCA1OgAwIBAgIUDi1DmEgxrJFgj3tDcn8y2iP53tYwDQYJKoZIhvcNAQELBQAwgYQxCzAJBgNVBAYTAlNJMREwDwYDVQQIDAhTbG92ZW5pYTESMBAGA1UEBwwJTGp1YmxqYW5hMRMwEQYDVQQKDApOYS1wcm9zdGVtMRYwFAYDVQQDDA1uYS1wcm9zdGVtLnNpMSEwHwYJKoZIhvcNAQkBFhJpbmZvQG5hLXByb3N0ZW0uc2kwHhcNMjMwNDIzMDA0MTIxWhcNMzMwNDIyMDA0MTIxWjCBhDELMAkGA1UEBhMCU0kxETAPBgNVBAgMCFNsb3ZlbmlhMRIwEAYDVQQHDAlManVibGphbmExEzARBgNVBAoMCk5hLXByb3N0ZW0xFjAUBgNVBAMMDW5hLXByb3N0ZW0uc2kxITAfBgkqhkiG9w0BCQEWEmluZm9AbmEtcHJvc3RlbS5zaTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAPpcJD/K6LU1/bgH1iMwsT77FO2KBluK9BBHdnYEVssRKi8UdeFHmXQ40d6LtQwqqZttYOMKdNNMzZ4UzMTuJNZCo+dl06vxLQkDwvjaFkGuN35QCEuIaHVgmEQ8a24gGwWOLc4mtDNMV5RpGZskQSlhaOLk0cQpWmOtfLosMesCo+InUu5/njQ9eJGebAhfHTI2jHANr75AnjYUExJ90pIoJasXA6I8boRx9Gypbbn8AU+FBmXH05IMa2MI9f1rNjSiW7LCHpLppi42/hKvigodm0GmiNo1muSyOTiPaRSopMv742xcHTV7OXNK4F/ofZxi/FcbCOlUx25rqyJ3LIZw9BlhJYwcH5CzOyc04LIXlr090sfLjA5fPA7L96UOJMQU5k34tzlOUyeAFm+TN4aqzBzJE1eoWPSymxvwiOdabcJ+E/0JSl8Rz6retXqR0TTvsgEC4+2u3ZHK7hkflGxEqUHDb8XmuABSzwL25DFMnOb3tNGeb36/M7OujNH6gQIDAQABo1MwUTAdBgNVHQ4EFgQUw+gfZ0lA9slWNXmh4c5GAb61SPIwHwYDVR0jBBgwFoAUw+gfZ0lA9slWNXmh4c5GAb61SPIwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAYEAiKMdVRSYlYcYp+bQuRFSZKuDUa//l/AsTjYWLgDFtUgDE/EizHjfUs0QkXSMz2qtLYGIZhaDeqduFimrH4mSU0ElaLZOabm1x612YbVBmlTUy2CoOFcUMkUbyBx8MWwVFFIHO5ZcEY9nqOGELQhQZFk8BJsPumn3Fz8n9lTp4PFcFDjtGY8+gNiuoMAIVV9G2/3wcrBFIOH3Pn84jGRat0YtFYKXsPkXqyKIeiZi2pCw81aHVg0kOeW7NYaDUVBSvYTAf0SgBAL8DrngHp2BJ1dTPUuSnWQkZ44FVxLpCqgXvNQTidO6X7x6IFSCYs/S1gsqV6Epv684Zy+BIPJQh6Tfqq7VYNtZGUrSOb7w/K+MVDS16n0N5PjwRSzkgCpOxJlOj1Jle6nO0T3pxQ/BJ1UIPkzdzTHhqYtVABHacjbvtfOwvkUF8v1+/Kshu54T6WkNKflkridlzhqRaXSNw9O20iVSykTgkVT64fr5bMJ94nfVTLXD7tWQpIGSH8ih</ds:X509Certificate> </ds:X509Data> </ds:KeyInfo> </md:KeyDescriptor> <md:SingleLogoutService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.na-prostem.si/simplesaml/saml2/idp/SingleLogoutService.php"/> <md:NameIDFormat>urn:oasis:names:tc:SAML:2.0:nameid-format:transient</md:NameIDFormat> <md:SingleSignOnService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect" Location="https://idp.na-prostem.si/simplesaml/saml2/idp/SSOService.php"/> </md:IDPSSODescriptor> <md:ContactPerson contactType="technical"> <md:GivenName>admin</md:GivenName> <md:EmailAddress>mailto:root@na-prostem.si</md:EmailAddress> </md:ContactPerson> </md:EntityDescriptor>
In formato flat per SimpleSAMLphp - da utilizzare se dall'altra parte c'è un'entità che utilizza SimpleSAMLphp
$metadata['https://idp.na-prostem.si/simplesaml/saml2/idp/metadata.php'] = [ 'metadata-set' => 'saml20-idp-remote', 'entityid' => 'https://idp.na-prostem.si/simplesaml/saml2/idp/metadata.php', 'SingleSignOnService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://idp.na-prostem.si/simplesaml/saml2/idp/SSOService.php', ], ], 'SingleLogoutService' => [ [ 'Binding' => 'urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect', 'Location' => 'https://idp.na-prostem.si/simplesaml/saml2/idp/SingleLogoutService.php', ], ], 'certData' => 'MIIE6zCCA1OgAwIBAgIUDi1DmEgxrJFgj3tDcn8y2iP53tYwDQYJKoZIhvcNAQELBQAwgYQxCzAJBgNVBAYTAlNJMREwDwYDVQQIDAhTbG92ZW5pYTESMBAGA1UEBwwJTGp1YmxqYW5hMRMwEQYDVQQKDApOYS1wcm9zdGVtMRYwFAYDVQQDDA1uYS1wcm9zdGVtLnNpMSEwHwYJKoZIhvcNAQkBFhJpbmZvQG5hLXByb3N0ZW0uc2kwHhcNMjMwNDIzMDA0MTIxWhcNMzMwNDIyMDA0MTIxWjCBhDELMAkGA1UEBhMCU0kxETAPBgNVBAgMCFNsb3ZlbmlhMRIwEAYDVQQHDAlManVibGphbmExEzARBgNVBAoMCk5hLXByb3N0ZW0xFjAUBgNVBAMMDW5hLXByb3N0ZW0uc2kxITAfBgkqhkiG9w0BCQEWEmluZm9AbmEtcHJvc3RlbS5zaTCCAaIwDQYJKoZIhvcNAQEBBQADggGPADCCAYoCggGBAPpcJD/K6LU1/bgH1iMwsT77FO2KBluK9BBHdnYEVssRKi8UdeFHmXQ40d6LtQwqqZttYOMKdNNMzZ4UzMTuJNZCo+dl06vxLQkDwvjaFkGuN35QCEuIaHVgmEQ8a24gGwWOLc4mtDNMV5RpGZskQSlhaOLk0cQpWmOtfLosMesCo+InUu5/njQ9eJGebAhfHTI2jHANr75AnjYUExJ90pIoJasXA6I8boRx9Gypbbn8AU+FBmXH05IMa2MI9f1rNjSiW7LCHpLppi42/hKvigodm0GmiNo1muSyOTiPaRSopMv742xcHTV7OXNK4F/ofZxi/FcbCOlUx25rqyJ3LIZw9BlhJYwcH5CzOyc04LIXlr090sfLjA5fPA7L96UOJMQU5k34tzlOUyeAFm+TN4aqzBzJE1eoWPSymxvwiOdabcJ+E/0JSl8Rz6retXqR0TTvsgEC4+2u3ZHK7hkflGxEqUHDb8XmuABSzwL25DFMnOb3tNGeb36/M7OujNH6gQIDAQABo1MwUTAdBgNVHQ4EFgQUw+gfZ0lA9slWNXmh4c5GAb61SPIwHwYDVR0jBBgwFoAUw+gfZ0lA9slWNXmh4c5GAb61SPIwDwYDVR0TAQH/BAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAYEAiKMdVRSYlYcYp+bQuRFSZKuDUa//l/AsTjYWLgDFtUgDE/EizHjfUs0QkXSMz2qtLYGIZhaDeqduFimrH4mSU0ElaLZOabm1x612YbVBmlTUy2CoOFcUMkUbyBx8MWwVFFIHO5ZcEY9nqOGELQhQZFk8BJsPumn3Fz8n9lTp4PFcFDjtGY8+gNiuoMAIVV9G2/3wcrBFIOH3Pn84jGRat0YtFYKXsPkXqyKIeiZi2pCw81aHVg0kOeW7NYaDUVBSvYTAf0SgBAL8DrngHp2BJ1dTPUuSnWQkZ44FVxLpCqgXvNQTidO6X7x6IFSCYs/S1gsqV6Epv684Zy+BIPJQh6Tfqq7VYNtZGUrSOb7w/K+MVDS16n0N5PjwRSzkgCpOxJlOj1Jle6nO0T3pxQ/BJ1UIPkzdzTHhqYtVABHacjbvtfOwvkUF8v1+/Kshu54T6WkNKflkridlzhqRaXSNw9O20iVSykTgkVT64fr5bMJ94nfVTLXD7tWQpIGSH8ih', 'NameIDFormat' => 'urn:oasis:names:tc:SAML:2.0:nameid-format:transient', 'contacts' => [ [ 'emailAddress' => 'root@na-prostem.si', 'contactType' => 'technical', 'givenName' => 'admin', ], ], ];
Certificati
Scarica i certificati X509 come file PEM-encoded